@quad @lanodan
uh.. I thought we're talking about
https://github.com/containers/bubblewrap
and the README there says bwrap's explicit purpose is to *not* use unprivileged userNS...
if I'm running as a privileged user I'd just use unshare directly...