Maybe. Remember it is new code. In principle it should be no worse than constraining a user; there are still risks of kernel compromise (one just the other day). I would check if you use any kernel modules that are not in the main tree though. Also I don't believe it is a full root, ie it can only do operations that have been whitelisted (eg creating other namespaces), otherwise you could just use mknod and overwrite the host harddrive. So your code you want to run as root may not work. You can do stuff like open low numbered ports though if you open a network namespace, so long as the host sets up bridging for it.