feat(rootfs): cache-aware rootfs preparation with persist hook

Add ecr::rootfs with the full rootfs lifecycle behind the library:

- RootfsCache::prepare resolves an image reference, downloads through
  the tarball cache (with the OCI :latest digest freshness check) and
  extracts into a scratch directory tracked by PreparedRootfs.
- PreparedRootfs::persist packs the current rootfs back into its cache
  entry (compressed to match the entry's extension, symlinks and
  permissions preserved) and marks it with a .provisioned sidecar.
- RootfsCache::prepare_provisioned composes both into the hot-cell
  flow: provision once, and every later call sharing the cache skips
  the download and the provisioning step.

extract: an "oci-" cache entry without a layers.manifest is a
persisted provisioned rootfs; extract it as a plain archive.

The CLI now drives prepare and drops its inline cache/orchestration
code and the dirs/tempfile dependencies.  The binfmt check moves ahead
of the download so foreign-arch runs fail before pulling an image.
This commit is contained in:
2026-09-21 00:06:20 +02:00
parent 4f669fb5ec
commit b6ddd85525
6 changed files with 653 additions and 158 deletions
-5
View File
@@ -21,8 +21,3 @@ clap = { version = "4", features = ["derive", "env"] }
# Error handling
anyhow = "1"
# Interim: used by the CLI's inline cache/extraction orchestration until it
# moves behind the library's rootfs API
dirs = "6"
tempfile = "3"