Hi Al and Christian, The commit 12f147ddd6de ("do_change_type(): refuse to operate on unmounted/not ours mounts") introduced an ABI backward compatibility break. CRIU depends on the previous behavior, and users are now reporting criu restore failures following the kernel update. This change has been propagated to stable kernels. Is this check strictly required? Would it be possible to check only if the current process has CAP_SYS_ADMIN within the mount user namespace? Thanks, Andrei