https://github.com/rootless-containers/rootlesskit/blob/master/pkg/child/child.go has extra exec for `mount(8)` binary. `mount(2)` syscall could be called directly.