# kcode-k1-rust-podman 0.2.1
`RustPodman::new(program, image)` accepts nonempty Podman executable and image values. `RustPodmanPaths::new(workspace, cargo_home, target, local_registry, cargo_config)` records caller-owned paths. Operations reject symlink leaves, require four distinct nonoverlapping directory roots and an ordinary config file, and preserve complete command diagnostics.
`format` runs `cargo fmt --all` in the supplied workspace with networking disabled. It uses the same containment and mounts as checks, leaves formatting changes in the caller-owned workspace, and does not create a lockfile.
`check` runs one network-enabled container with the workspace, Cargo home and target writable and the K1 registry and Cargo configuration read-only. It generates the root lockfile, fetches locked crates.io and K1 dependencies, then runs formatting verification, locked builds, warnings-denied Clippy, tests and documentation tests. It requires an ordinary root `Cargo.lock` after success. Caller-owned Cargo and target directories remain reusable across calls.
`build_binary` requires the root lockfile and performs a separate network-enabled locked release build because it returns a named executable. It copies the result through a unique mode-0700 sibling stage directory and atomically renames it over an absent or ordinary nonsymlink output.
Every container uses a read-only root, rootless keep-id mapping, dropped capabilities, no-new-privileges and a private temporary directory. Only the supplied workspace, Cargo cache, target, local registry, Cargo configuration and optional output stage are mounted; K1 state, credentials, host controls and the Podman socket are not mounted. Host Cargo and rustc are never run.
`CommandDiagnostics` contains complete exit status, stdout and stderr. `RustPodmanError` separates invalid input, filesystem, spawn, failed-command and successful-command follow-up failures. Calls are synchronous and own no authorization, cache policy, retry, timeout, lock, shared mutable state, background work or output truncation.