Although vm is strong isolation, but capabilities might be still need for some other cases...
Although vm is strong isolation, but capabilities might be still need for some other cases...