It seems like Information Assurance in the form of MAC (hello SELinux) is a cleaner option than capabilities where possible. I know that Fedora / RHEL taught libvirtd about SELinux and called it sVirt[1]. This seems like the best possible way forward over simple capabilities.