security: filesystem capabilities refactor kernel code