kcode-k1-rust-podman 0.1.0

Synchronous Podman-backed Cargo fetch, check, and binary build helper.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# kcode-k1-rust-podman 0.1.0

This concrete synchronous leaf lets K1 Rust coding fetch, check, and build a binary in Podman. It owns no cache policy, access decision, publication, retry, timeout, cancellation, or background work.

`RustPodman::new(program, image)` accepts opaque nonempty executable and image values. `RustPodmanPaths::new(workspace, cargo_home, target, local_registry, cargo_config)` records caller-owned paths. Operations reject symlink leaves, require four distinct nonoverlapping directory roots and an ordinary config file, and preserve complete command diagnostics.

`fetch` runs one network-enabled container with workspace and cargo home writable, registry and config read-only, and no target mount. It runs `mkdir -p /tmp/home && cargo generate-lockfile && cargo fetch --locked` and then requires an ordinary root `Cargo.lock`.

`check` first requires that lock, disables networking, mounts workspace and registry read-only and cargo home and target writable, then runs fail-fast fmt, offline locked build, warnings-denied Clippy, tests, and doc tests for the workspace and all features/targets as applicable.

`build_binary` accepts a 1-36 character lowercase kebab name. With networking disabled it performs a locked offline release build, passing the name only through `K1_BINARY`, and copies the result to a unique mode-0700 sibling stage directory. It accepts only an ordinary staged binary and atomically renames it over an absent or ordinary nonsymlink output.

Every container uses `podman run --rm --read-only --userns=keep-id --cap-drop=ALL --security-opt=no-new-privileges --workdir=/workspace --env=HOME=/tmp/home --env=CARGO_HOME=/cargo-home --env=CARGO_TARGET_DIR=/target --tmpfs=/tmp:rw,nosuid,nodev`. Only supplied operation paths are mounted. Host Cargo and rustc are never run.

`CommandDiagnostics` contains the complete exit status, stdout, and stderr. `RustPodmanError` separates invalid input, filesystem, spawn, failed-command, and successful-command follow-up failures. Calls are synchronous and have no retry, timeout, lock, shared mutable state, or output truncation.