New system calls are all well and good, but are useless without something to call them.
IronPenguin features are utilized through a few new administrative tools:
capceiling is used to run a program with a lowered capability ceiling and to see the current ceiling.
fscap is used to set or view the forced and allowed capabilities set on a file.