Last I knew, LXC doesn't try to isolate containers against deliberate breakout attempts the way OpenVZ does. It's more intended to run a lot of basically cooperating application instances with separate IP addresses, configurations, etc. Docker is about the same way and apparently this OpenVZ...