e.g. on desktop systems, you might want to allow regular users to mount files as disks, which can be accomplished by changing `/dev/mdctl` permissions.
However currently in that case any user would be able to delete any other user's ramdisks.
This patch changes that.
bikeshedding: `PRIV_VFS_ADMIN` vs new `PRIV_` or something else?