> eg if you create a new user ns and new netns can you say use ping or other root-requiring network ops?
Yes - but only with nics owned by your new network namespace. Which means nics which you create (which won't be hooked into the parent ns), or nics which a privileged task in the parent netns passed into your ns.