perf: add mitigations=off kernel param for kiosk FPS
Single-purpose offline kiosk doesn't need Spectre/Meltdown/SRBDS
mitigations. These add syscall overhead that may contribute to
the 33ms frame times (vs 16ms target).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>