I did further tests with a Bionic container on a Xenial host. There, I also needed to add "capability fsetid".
I did further tests with a Bionic container on a Xenial host. There, I also needed to add "capability fsetid".