Right. `CAP_SYS_ADMIN` is for all intents and purposes equivalent to root.

No, not since namespacing came around.