<i>sigh</i><p>Linux has had user namespaces for a while, and user namespaces solve this problem.<p>Yes, they have their share of bugs (I've found quite a few of them), but they're <i>far</i> better than doing containerization with funny cgroup games and crossed fingers (i.e. what Docker does now).