pub fn ckdev_binary(built: impl AsRef<Path>) -> PathBufExpand description
Publish a built executable under a content-addressed ckdev-* name.
Already-dev-named paths pass through. Unix copies live under /tmp, never
$TMPDIR, to avoid per-user temporary-directory execution assessment delays.
A child writes a private staging copy, then an atomic rename publishes it.
This avoids hard-link execution failures and writable descriptors inherited
by concurrently spawned children. Published files are read-only, verified
against their digest on reuse, and pruned after three days.
Use checked_output to report failed child exits, including signal names.