capabilities: require CAP_SETFCAP to map uid 0