[klibc] run-init: add drop_capabilities support

Building on the work in ff0a614bd724f6c4c6a5014a9955dc1bc028f336,
this moves the capability code down into the run-init library, so that
run-init can use it as well, via the new "-d" flag.

Signed-off-by: Kees Cook <kees@outflux.net>
Signed-off-by: H. Peter Anvin <hpa@linux.intel.com>
7 files changed