Make --enable-expensive-hardening work with sandbox
We should encourage people to build, sometimes, with more expensive hardening options than we'd like by default. I'm thinking in particular of turning on AddressSanitizer where available.
This should also force memory pool optimizations off, if they're not already off by default. (see #11476 (moved))
The above is merged; see discussion below for the remaining parts of this ticket.