systemd: drop all capabilities by default