Can/should we prospectively drop various kernel capabilities related to firmware access?