rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in runc in github.com/opencontainers/runc
/sys/fs/cgroup