Commit 1a296762b3d0 made libcasper pass PD_NOWAITPID to pdfork(2).
Kernels predating the flag (15.1 and earlier, since the flag first
ships in 15.2) reject it with EINVAL, which makes cap_init() and every
service fork fail when a newer world runs on an older kernel, for
example in a poudriere jail.
Add casper_pdfork(), which retries without the flag on EINVAL, and use
it at both pdfork(2) call sites. The retry is safe because the kernel
validates pdfork flags before creating a child. On such kernels the
zombie must still be reaped with waitpid(2), as before the flag was
introduced.
The fallback is compiled out once __FreeBSD_version reaches 1700000,
so it disappears from main when stable/16 branches while remaining in
the stable/15 and stable/16 branches that need it.
MFC after: 3 days