Capsicum: practical capabilities in UNIX