cgroup: allow a cgroup subsystem to reject a fork