Does anyone have any advice on what to do with this? I followed Sam's helpful hint about Tracker's CI images working to [1], copied the things that looked like they might be relevant from there into my own gitlab-ci file [2], at first got some errors that I knew basically how to deal with, but now I am stuck at a bunch of error messages that look to me like gibberish but end with "operation not permitted" [3]. I have little knowledge of this problem space so I don't even know where to start to debug this. Is this the same privileges problem as "bwrap: Creating new namespace failed" described earlier in the thread, or is it something different?
Also, has anyone successfully gotten a CI job that uses lsan or asan to work in the unprivileged setup? (See my previous question about CAP_SYS_PTRACE.)