# kcode-k1-rust-podman 0.1.0
This concrete synchronous leaf lets K1 Rust coding fetch, check, and build a binary in Podman. It owns no cache policy, access decision, publication, retry, timeout, cancellation, or background work.
`RustPodman::new(program, image)` accepts opaque nonempty executable and image values. `RustPodmanPaths::new(workspace, cargo_home, target, local_registry, cargo_config)` records caller-owned paths. Operations reject symlink leaves, require four distinct nonoverlapping directory roots and an ordinary config file, and preserve complete command diagnostics.
`fetch` runs one network-enabled container with workspace and cargo home writable, registry and config read-only, and no target mount. It runs `mkdir -p /tmp/home && cargo generate-lockfile && cargo fetch --locked` and then requires an ordinary root `Cargo.lock`.
`check` first requires that lock, disables networking, mounts workspace and registry read-only and cargo home and target writable, then runs fail-fast fmt, offline locked build, warnings-denied Clippy, tests, and doc tests for the workspace and all features/targets as applicable.
`build_binary` accepts a 1-36 character lowercase kebab name. With networking disabled it performs a locked offline release build, passing the name only through `K1_BINARY`, and copies the result to a unique mode-0700 sibling stage directory. It accepts only an ordinary staged binary and atomically renames it over an absent or ordinary nonsymlink output.
Every container uses `podman run --rm --read-only --userns=keep-id --cap-drop=ALL --security-opt=no-new-privileges --workdir=/workspace --env=HOME=/tmp/home --env=CARGO_HOME=/cargo-home --env=CARGO_TARGET_DIR=/target --tmpfs=/tmp:rw,nosuid,nodev`. Only supplied operation paths are mounted. Host Cargo and rustc are never run.
`CommandDiagnostics` contains the complete exit status, stdout, and stderr. `RustPodmanError` separates invalid input, filesystem, spawn, failed-command, and successful-command follow-up failures. Calls are synchronous and have no retry, timeout, lock, shared mutable state, or output truncation.