Explicitly remove process traceability instead of implicitly relying on setgid for that
This incorporates the review comments from !1 (closed) which I can't edit myself. (But thanks for picking it up again after we all forgot about it in Phabricator!)