[PATCH] isolation: keep CAP_SYS_PTRACE when required