seph
b. `Drop privileges, make the fork() syscall, (and not call any execve or similar syscall in the child, not using any
subprocess API calls like system or spawn here), and make the child enter the mnt namespace of the container
by referring to the fd of the mnt namespace of the container's pid (edited)My gut says that's going to be fragile. What if theres no
/proc? But I don't know how bullet proof it needs to be