This change has no functional difference, but this order might discourage mistakes in the future.
One could argue that entering capability mode as early as possible is preferred. However, a future developer may assume the`cap_enter()` indicates where the sandbox has been entered and is ready for potentially unsafe operations, so I feel it makes sense to have fd rights limited before that point.