Add support for the Dockerfile USER directive so that the container's
CMD/ENTRYPOINT runs as the configured user instead of root.
Changes:
- inject.rs: Add user field to Config struct, write /slim/user at
build time
- build.rs: Pass config.user through to inject()
- slim-init.sh: Read /slim/user and drop privileges via su before
executing the command. Numeric uids are resolved to usernames via
/etc/passwd (BusyBox su does not accept numeric args). When dropping
privileges, run as a child (not exec) so PID 1 stays root and can
poweroff after the command exits.
- test.sh: Add test_user verifying build-time CMD and --cmd override
both run as the configured user
Closes#7
slim now works with any Containerfile by injecting distro-agnostic scripts
at build time:
- /slim/init: mounts special filesystems, configures networking (static
QEMU slirp), sets up cgroup2, timezone, and rootless container prereqs.
Parses slim.cmd=<base64> from the kernel cmdline for runtime overrides,
otherwise execs /slim/exec.
- /slim/exec: generated from the image's CMD/ENTRYPOINT (via podman image
inspect), overridable via --cmd at build and run time.
Changes:
- New src/inject.rs: inspect image config, infer command, generate
/slim/exec script, inject /slim/ into mounted rootfs
- New src/scripts/slim-init.sh: the universal init script (include_str!)
- build.rs: rename --init to --cmd, inject scripts before packing,
drop Meta::save, restructure to ensure unmount always runs
- qemu.rs: hardcode init=/slim/init, add --cmd (base64 on cmdline),
drop Meta::load, add -no-reboot
- Remove src/meta.rs and meta.toml (no longer needed)
- Cargo.toml: add serde_json + base64, remove unused walkdir + cpio + toml
- Example Containerfiles simplified to plain FROM + CMD
- New example/test.sh for manual verification
- README updated for new workflow