Is cloning to satisfy the compiler bad practice?
It is a legitimate first draft. Get it working with clones, measure, then remove the ones that matter. Fighting lifetimes on a prototype costs days and usually ends with the same structure you would have reached by refactoring later.
unwrap is fine in examples but what do real programs do?
Propagate with ? and define one error type per crate boundary. thiserror for libraries, anyhow for applications is the common split: libraries need callers to match on variants, applications mostly need context and a good message.
What is the most common way people get this wrong?
Doing it once and never verifying. The setup is the visible part, so it gets attention, and the check that would catch a silent failure never gets written.