btw., just in case it was not obvious, i'll repeat my older assessment
of your patch: the general picture approach looks good to me and the
code is upstream-worthy.
( suggestion: if you want more people to test it then you might want to
do some add-on "put all users into separate groups" patch and .config
option - which could be tried without people having to know anything
about container setup. )
Ingo
-