I am trying to build the `docker' package on a foreign distro. Specifically, Debian sid. This results in the following test failures: -------------------------------------- === Failed === FAIL: daemon/graphdriver/quota TestBlockDev/testBlockDevQuotaDisabled (0.03s) --- FAIL: TestBlockDev/testBlockDevQuotaDisabled (0.03s) projectquota_test.go:83: assertion failed: error is not nil: exit status 1: mount failed: mount: /tmp/guix-build-docker-19.03.7.drv-0/xfs-mountPoint-325789281: mount failed: Operation not permitted. === FAIL: daemon/graphdriver/quota TestBlockDev/testBlockDevQuotaEnabled (0.02s) --- FAIL: TestBlockDev/testBlockDevQuotaEnabled (0.02s) projectquota_test.go:83: assertion failed: error is not nil: exit status 1: mount failed: mount: /tmp/guix-build-docker-19.03.7.drv-0/xfs-mountPoint-054602316: mount failed: Operation not permitted. === FAIL: daemon/graphdriver/quota TestBlockDev/testSmallerThanQuota (0.01s) --- FAIL: TestBlockDev/testSmallerThanQuota (0.01s) projectquota_test.go:83: assertion failed: error is not nil: exit status 1: mount failed: mount: /tmp/guix-build-docker-19.03.7.drv-0/xfs-mountPoint-879061307: mount failed: Operation not permitted. === FAIL: daemon/graphdriver/quota TestBlockDev/testBiggerThanQuota (0.01s) --- FAIL: TestBlockDev/testBiggerThanQuota (0.01s) projectquota_test.go:83: assertion failed: error is not nil: exit status 1: mount failed: mount: /tmp/guix-build-docker-19.03.7.drv-0/xfs-mountPoint-487602526: mount failed: Operation not permitted. === FAIL: daemon/graphdriver/quota TestBlockDev/testRetrieveQuota (0.01s) --- FAIL: TestBlockDev/testRetrieveQuota (0.01s) projectquota_test.go:83: assertion failed: error is not nil: exit status 1: mount failed: mount: /tmp/guix-build-docker-19.03.7.drv-0/xfs-mountPoint-717635877: mount failed: Operation not permitted. === FAIL: daemon/graphdriver/quota TestBlockDev (0.38s) projectquota_test.go:50: meta-data=/tmp/guix-build-docker-19.03.7.drv-0/xfs-image973358730 isize=256 agcount=4, agsize=4096 blks = sectsz=512 attr=2, projid32bit=1 = crc=0 finobt=0, sparse=0, rmapbt=0 = reflink=0 data = bsize=4096 blocks=16384, imaxpct=25 = sunit=0 swidth=0 blks naming =version 2 bsize=4096 ascii-ci=0, ftype=1 log =internal log bsize=4096 blocks=853, version=2 = sectsz=512 sunit=0 blks, lazy-count=1 realtime =none extsz=4096 blocks=0, rtextents=0 -------------------------------------- This suggests that there's an issue with permissions. I recalled that Debian ships a custom kernel patch that disables unprivileged namespaces by default. However, after setting kernel.unprivileged_userns_clone = 1 the problem persisted. I am attaching the full build log.