bubblewrap
bubblewrap copied to clipboard
--bind non-world-x path with --unshare-user
resolve_symlinks_in_ops appears to be called after setting up the new UID namespace, when it no longer has privileges to access the bind source. So even running bwrap as root, I can't bind mount a non-world-x path.