[PATCH 2/2] docs: threat-model: don't limit root capabilities to CAP_SYS_ADMIN

From: Jonathan Corbet

Date: Wed May 13 2026 - 16:58:53 EST


The threat-model document says that only users with CAP_SYS_ADMIN can carry
out a number of admin-level tasks, but there are numerous capabilities that
can confer that sort of power. Generalize the text slightly to make it
clear that CAP_SYS_ADMIN is not the only all-powerful capability.

Signed-off-by: Jonathan Corbet <corbet@xxxxxxx>
---
Documentation/process/threat-model.rst | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/Documentation/process/threat-model.rst b/Documentation/process/threat-model.rst
index 91da52f7114fd..f177b8d3c1caf 100644
--- a/Documentation/process/threat-model.rst
+++ b/Documentation/process/threat-model.rst
@@ -62,7 +62,8 @@ on common processors featuring privilege levels and memory management units:

* **Capability-based protection**:

- * users not having the ``CAP_SYS_ADMIN`` capability may not alter the
+ * users not having elevated capabilities (including but not limited to
+ CAP_SYS_ADMIN) may not alter the
kernel's configuration, memory nor state, change other users' view of the
file system layout, grant any user capabilities they do not have, nor
affect the system's availability (shutdown, reboot, panic, hang, or making
--
2.53.0