Sorry, testcase in #8 is invalid, bc lxc-usernsexec doesn't create a new pid namespace, so mount is denied because we do not own our pidns->userns.
Sorry, testcase in #8 is invalid, bc lxc-usernsexec doesn't create a new pid namespace, so mount is denied because we do not own our pidns->userns.