It was reported[1] to the Linux Containers list that it would be possible to use user namespaces to circumvent MNT_LOCKED and allow unprivileged users to access the directory structure underneath of mounts. A PoC was also produced and is public. Resources: [1] https://groups.google.com/forum/#!topic/linux.kernel/HnegnbXk0Vs [2] http://www.spinics.net/lists/linux-containers/msg30786.html
Didn't think this got made.. tooling bug. *** This bug has been marked as a duplicate of bug 1226751 ***