The daemon config for defaulting to no-new-privileges for containers was added in d7fda019bb7e24f42f8ae1ddecb3fd52df3c48bf, but somehow we managed to omit the flag itself, but also documented the flag. This just adds the actual flag. Signed-off-by: Brian Goff <cpuguy83@gmail.com> Upstream-commit: ba332a60b24f40007e7ef234c0f44ae5a5ff9d49 Component: engine