@2ffa8eb4 Make systemd set prctl PR_SET_NO_NEW_PRIVS in pid 1. 😈
@2b562a3e We actually have an option for that in /etc/systemd/system.conf. But I am not aware of any general purpose distro setting that. And ideally we'd turn off the suid/fcaps logic already in kernel, i.e. compile the whole thing out.