kcode-k1-rust-podman 0.2.0

Synchronous Podman-backed Cargo check and binary build helper.
Documentation
1
2
3
4
5
6
7
8
9
10
11
# kcode-k1-rust-podman 0.2.0

`RustPodman::new(program, image)` accepts nonempty Podman executable and image values. `RustPodmanPaths::new(workspace, cargo_home, target, local_registry, cargo_config)` records caller-owned paths. Operations reject symlink leaves, require four distinct nonoverlapping directory roots and an ordinary config file, and preserve complete command diagnostics.

`check` runs one network-enabled container with the workspace, Cargo home and target writable and the K1 registry and Cargo configuration read-only. It generates the root lockfile, fetches locked crates.io and K1 dependencies, then runs formatting, locked builds, warnings-denied Clippy, tests and documentation tests. It requires an ordinary root `Cargo.lock` after success. Caller-owned Cargo and target directories remain reusable across calls.

`build_binary` requires the root lockfile and performs a separate network-enabled locked release build because it returns a named executable. It copies the result through a unique mode-0700 sibling stage directory and atomically renames it over an absent or ordinary nonsymlink output.

Every container uses a read-only root, rootless keep-id mapping, dropped capabilities, no-new-privileges and a private temporary directory. Only the supplied workspace, Cargo cache, target, local registry, Cargo configuration and optional output stage are mounted; K1 state, credentials, host controls and the Podman socket are not mounted. Host Cargo and rustc are never run.

`CommandDiagnostics` contains complete exit status, stdout and stderr. `RustPodmanError` separates invalid input, filesystem, spawn, failed-command and successful-command follow-up failures. Calls are synchronous and own no authorization, cache policy, retry, timeout, lock, shared mutable state, background work or output truncation.