Augment NOPRIV libcap mode with the sticky NO_NEW_PRIVS prctl bit.

Since I last visited securebits no privs mode, a new prctl bit
has been added (it isn't a securebit, but a parallel implementation
of something similar). So, layer that bit on top of NOPRIV mode.

Signed-off-by: Andrew G. Morgan <morgan@kernel.org>
5 files changed