allow fsverity_init self:capability sys_admin;