When / is mounted as shared, unshare(CLONE_NEWNS) doesn't prevent the bind mount to be system wide. Worse: it isn't unmounted at exit. Thus this patch wich remount / with --make-rslave. See #739593 for more details. ===================================================================