OK, this was nasty ...
capability is a module again, but IT DOES NOT NEED TO BE LOADED any more.
capabilities are now default whether or not CONFIG_SECURITY is enabled
or not. It should always have been like that. dummy is only still used
as fall-back for non-implemented operations from security modules.
The capability module can be loaded as secondary module (and stacked
on top of selinux) or a primary module. As primary module, it won't
change anything, though, except hurting performance a bit. Thus not
loading (nor compiling in) is better.
capability boot parameter is not needed any more and has been removed.