To avoid symlink problems these implementations switch
between the host's and container's namespace to open the
corresponding file handles, then copy the data.
With unprivileged containers we also enter the container's
user-namespace with pct-push and switch to the container's
root user before opening the destination for writing in
order to create new files with the mapped root user.