lsetxattr() call failingtouch test then that file is unlabeled_ttouchcontainer_file_tlsetxattr() working inside a rootful containerchconlabel=nested: Allows SELinux modifications within the container. Containers are allowed to modify SELinux labels on files and processes, as long as SELinux policy allows. Without nested, containers view SELinux as disabled, even when it is enabled on the host. Containers are prevented from setting any labels.
setfattr --name security.selinux -v system_u:object_r:xdm_exec_t:s0:c1022,c102 /usr/sbin/gdm
setfattr: /usr/sbin/gdm: Operation not supportedlsetxattr()lsetxattr()touch test—security-opt label=disabletouchcontainer_file_tchcon