Adds a standalone rule to the very top of 60-persistent-storage.rules.
To not expose dom0 processes like blkid for attacks from VM (e.g. by placing malicious filesystem header in private.img).