There's also openat on linux. My point is that the general, practiced approach is not capability based.