关于Linux capabilities的技术问询:特权操作划分与多能力授权
Great questions about Linux capabilities—let’s break them down clearly:
Linux capabilities were built to split the monolithic root privilege into smaller, more manageable permissions, and they cover most common privileged operations you’ll encounter. However, they don’t cover every single privileged action.
The big caveat here is CAP_SYS_ADMIN, often called the "catch-all" capability. It encompasses hundreds of operations that haven’t been split into more specific, granular capabilities yet—things like certain filesystem tweaks, kernel parameter adjustments, and niche system management tasks. Additionally, very new kernel features or extremely niche operations might not have a dedicated capability defined yet, so you’d still need full root access (or CAP_SYS_ADMIN) to perform them.
Absolutely—this is a common pattern, especially with the broad CAP_SYS_ADMIN acting as a superset for many granular capabilities. Here are some concrete examples:
- Binding to privileged ports (port numbers < 1024): The standard, least-privilege way is with
CAP_NET_BIND_SERVICE, but a process withCAP_SYS_ADMIN(or running as root, which has all capabilities) can also do this. - Modifying system time:
CAP_SYS_TIMEis the dedicated capability for adjusting the system clock, butCAP_SYS_ADMINalso grants this permission. - Mounting/unmounting filesystems:
CAP_SYS_MOUNTis the specific capability for this task, butCAP_SYS_ADMINincludes this permission too. - Loading kernel modules:
CAP_SYS_MODULEis the intended, restricted way to load modules, butCAP_SYS_ADMINwill also allow this operation.
This design balances granularity (for processes that only need one specific privilege) and convenience (for full system admin tools that need broad access).
内容的提问来源于stack exchange,提问作者dippynark

