Rootfs and layers
Apply layers in order and honour whiteouts while building the rootfs.
Rootfs and layers
Apply layers in order and honour whiteouts while building the rootfs. Preserve earlier capabilities and use the fixture only to make observation deterministic.
Contract
The harness receives a JSON process description and returns a syscall, mount, and limit plan. Real privileged execution stays outside the runner, but the plan must match Linux.
{
"op": "merge-layers",
"layers": [
{ "a": "1", "x": "old" },
{ ".wh.x": "", "b": "2" }
]
}
produces exactly:
{ "files": { "a": "1", "b": "2" } }
Emit compact JSON with a final newline. Invalid input leaves stdout empty, writes error to stderr, and exits non-zero.
Design and limits
Separate policy, mutable state, and system effects. Make resource ownership, cleanup order, and pre/post-operation invariants explicit. Do not replace the central mechanism with a simulation: the fixture controls inputs and time while your code implements isolation, memory, or synchronisation as appropriate.
Test empty boundaries, mid-operation failures, and idempotent cleanup. Sort output only at the presentation boundary.
Acceptance
- The example produces the exact output.
- Resources are not leaked and work is not duplicated.
- Failure leaves the system coherent.