kcode-k1-rust-podman 0.2.4

Synchronous Podman-backed Cargo check and binary build helper.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# kcode-k1-rust-podman 0.2.4

`RustPodman::new(program, image)` accepts nonempty Podman executable and image values. `RustPodmanPaths::new(workspace, cargo_home, target, local_registry, cargo_config)` records caller-owned paths. Operations reject symlink leaves, require four distinct nonoverlapping directory roots and an ordinary config file, and preserve complete command diagnostics.

`format` runs `cargo fmt --all` in the supplied workspace with networking disabled. It is an explicit caller-requested operation, leaves formatting changes in the caller-owned workspace, and does not create a lockfile. Formatting is not part of `check`.

`check` runs one network-enabled container with the workspace, Cargo home and target writable and the K1 registry and Cargo configuration read-only. It regenerates the root lockfile to select the newest dependencies allowed by the manifest, fetches that exact closure, then runs ordinary locked `cargo build` and `cargo test` using Cargo's default targets and features. It does not impose formatting, Clippy, warnings-denied, all-target, all-feature, or separate documentation-test gates. It requires an ordinary root `Cargo.lock` after success. Caller-owned Cargo and target directories remain reusable across calls.

`compile_workspace_all_targets` is the one-time Loom bootstrap-import operation. In one network-enabled container it regenerates the workspace lockfile and runs `cargo test --workspace --all-targets --no-run --locked`. It compiles the complete workspace and all supported test targets without executing tests or doing a redundant build or fetch pass. It requires an ordinary root `Cargo.lock` after success. The ordinary `check` operation is unchanged.

`build_binary` accepts a 1–250 character lowercase ASCII kebab-case binary target name, requires the root lockfile, and performs a separate network-enabled locked release build because it returns a named executable. It copies the result through a unique mode-0700 sibling stage directory and atomically renames it over an absent or ordinary nonsymlink output.

Every container uses a read-only root, rootless keep-id mapping, dropped capabilities, no-new-privileges and a private temporary directory. Only the supplied workspace, Cargo cache, target, local registry, Cargo configuration and optional output stage are mounted; K1 state, credentials, host controls and the Podman socket are not mounted. Host Cargo and rustc are never run.

`CommandDiagnostics` contains complete exit status, stdout and stderr. `RustPodmanError` separates invalid input, filesystem, spawn, failed-command and successful-command follow-up failures. Calls are synchronous and own no authorization, cache policy, retry, timeout, lock, shared mutable state, background work or output truncation.