pub fn apply(prog: &Prog<'_>) -> Result<()>Expand description
Sets no_new_privs and installs prog for the calling thread. It
cannot be removed and is inherited across fork and execve.
Only calls prctl, so it is async-signal-safe and may run between
fork and exec (for example from CommandExt::pre_exec).