feat(rootfs): cache-aware rootfs preparation with persist hook

Add ecr::rootfs with the full rootfs lifecycle behind the library:

- RootfsCache::prepare resolves an image reference, downloads through
  the tarball cache (with the OCI :latest digest freshness check) and
  extracts into a scratch directory tracked by PreparedRootfs.
- PreparedRootfs::persist packs the current rootfs back into its cache
  entry (compressed to match the entry's extension, symlinks and
  permissions preserved) and marks it with a .provisioned sidecar.
- RootfsCache::prepare_provisioned composes both into the hot-cell
  flow: provision once, and every later call sharing the cache skips
  the download and the provisioning step.

extract: an "oci-" cache entry without a layers.manifest is a
persisted provisioned rootfs; extract it as a plain archive.

The CLI now drives prepare and drops its inline cache/orchestration
code and the dirs/tempfile dependencies.  The binfmt check moves ahead
of the download so foreign-arch runs fail before pulling an image.
This commit is contained in:
2026-09-21 00:06:20 +02:00
parent 4f669fb5ec
commit b6ddd85525
6 changed files with 653 additions and 158 deletions
Generated
-2
View File
@@ -328,9 +328,7 @@ version = "0.1.0"
dependencies = [
"anyhow",
"clap",
"dirs",
"ecr",
"tempfile",
]
[[package]]