Capabilities checks for sysfs mount do include those on netns, but only if CONFIG_NET_NS is enabled. Sorry, should've caught that earlier... The following changes since commit c99c2171fc61476afac0dfb59fb2c447a01fb1e0: afs: Use fs_context to pass parameters over automount (2019-02-28 03:29:39 -0500) are available in the git repository at: git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs.git work.mount for you to fetch changes up to ab81dabda1d4edc1728173be6c6a279455f220e3: fix sysfs_init_fs_context() in !CONFIG_NET_NS case (2019-03-16 09:45:42 -0400) ---------------------------------------------------------------- Al Viro (1): fix sysfs_init_fs_context() in !CONFIG_NET_NS case fs/sysfs/mount.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-)