trying much, and got error on start container...
features: keyctl=1,nesting=1
unprivileged: 1
pct set xxx --mp0 /lib/modules/$(uname -r),mp=/lib/modules/$(uname -r),ro=1
explicitly configured lxc.apparmor.profile overrides the following settings: features:fuse, features:nesting
run_buffer: 314 Script exited with status 20
lxc_init: 798 Failed to run lxc.hook.pre-start for container "100120"
__lxc_start: 1945 Failed to initialize container "100120"
sid 0 hostid 100000 range 65536
INFO lsm - lsm/lsm.c:lsm_init:40 - Initialized LSM security driver AppArmor
INFO conf - conf.c:run_script_argv:331 - Executing script "/usr/share/lxc/hooks/lxc-pve-prestart-hook" for container "100120", config section "lxc"
DEBUG conf - conf.c:run_buffer:303 - Script exec /usr/share/lxc/hooks/lxc-pve-prestart-hook 100120 lxc pre-start produced output: symlink encountered at: //lib
ERROR conf - conf.c:run_buffer:314 - Script exited with status 20
ERROR start - start.c:lxc_init:798 - Failed to run lxc.hook.pre-start for container "100120"
ERROR start - start.c:__lxc_start:1945 - Failed to initialize container "100120"
INFO conf - conf.c:run_script_argv:331 - Executing script "/usr/share/lxc/hooks/lxc-pve-poststop-hook" for container "100120", config section "lxc"
startup for container '100120' failed