[
     {
          "Id": "9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70",
          "Created": "2026-08-10T03:00:54.017559035+03:00",
          "Path": "/usr/bin/tini",
          "Args": [
               "--",
               "/bin/sh",
               "-c",
               "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' >&2; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' >&2; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' >&2; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' >&2; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' >&2; exit 10; }\n\"$@\"",
               "sh",
               "codex",
               "exec",
               "--sandbox",
               "danger-full-access",
               "--skip-git-repo-check",
               "-C",
               "/sandbox/workspaces/agent-a33d295a0f6813f26-5e47d8cf1563",
               "-m",
               "gpt-5.6-sol",
               "-c",
               "model_reasoning_effort=low",
               "Fresh independent final security/correctness review for TODO #178. The user's exact request: Apply /tmp/todo178-final.patch in your isolated Overdeck worktree, then review the full applied diff and relevant call sites. Do not rely on prior reviews. Focus P0/P1/P2 only: whole-version atomic runtime under SIGKILL/restart and final activation sequencing; canonical/symlink paths and source TOCTOU; lock ownership; hostile startup/PATH/Git/env; passwd-home; fully-bound durable started receipts before SSH/K3s; no-envelope/retries; inner exits/pod ordering. Do not commit/deploy/install/live mutate. Report exact concrete failure sequences or explicitly clean. Context: the patch is already applied in this exact worktree from the patch's exact git-blob preimages. Review /tmp/todo178-final.patch as the authoritative full diff, inspect the resulting changed files in this worktree, and trace only relevant call sites essential to validate the named invariants. Treat all boundary inputs as hostile and fail closed when a guard cannot be confirmed. Enumerate sibling branches explicitly. For every candidate: state exact trigger/state sequence, re-read and try to refute it once, then report only survivors. Severity scope is P0/P1/P2 (critical/high/medium) only; omit lower-value findings. Do not mutate any files or run deploy/install/live operations. Output a numbered severity-ordered list with Title, absolute Location, Severity, Trigger/failure sequence, and specific Fix. End with Headline naming ship blockers and Residual/unverified. If no exploitable P0/P1/P2 survives, say explicitly clean and list only the top assumptions a deeper review should test."
          ],
          "State": {
               "OciVersion": "1.2.1",
               "Status": "exited",
               "Running": false,
               "Paused": false,
               "Restarting": false,
               "OOMKilled": false,
               "Dead": false,
               "Pid": 0,
               "ExitCode": 0,
               "Error": "",
               "StartedAt": "2026-08-10T03:00:54.175550346+03:00",
               "FinishedAt": "2026-08-10T03:03:29.859944725+03:00",
               "CheckpointedAt": "0001-01-01T00:00:00Z",
               "RestoredAt": "0001-01-01T00:00:00Z"
          },
          "Image": "b1f0e605dca88041db84124d554a87c90f1e67b0afd39a1e6eb5fdd69b2333ef",
          "ImageDigest": "sha256:a04c8666e3eb0dfed42cd16d577c383649555d1d05f214546c06d9377ef7a456",
          "ImageName": "localhost/overdeck-agent-sandbox:d1c7f17660b1",
          "Rootfs": "",
          "Pod": "",
          "ResolvConfPath": "/run/user/1000/containers/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/resolv.conf",
          "HostnamePath": "/run/user/1000/containers/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/hostname",
          "HostsPath": "/run/user/1000/containers/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/hosts",
          "StaticDir": "/home/user/.local/share/containers/storage/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata",
          "OCIConfigPath": "/home/user/.local/share/containers/storage/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/config.json",
          "OCIRuntime": "crun",
          "ConmonPidFile": "/run/user/1000/containers/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/conmon.pid",
          "PidFile": "/run/user/1000/containers/overlay-containers/9b5b76783b807426f4c11eabd163c6c4e985fc1ba2335dcce5f495f71016bd70/userdata/pidfile",
          "Name": "overdeck-sandbox-agent-a33d295a0f6813f26-5e47d8cf1563",
          "RestartCount": 0,
          "Driver": "overlay",
          "MountLabel": "",
          "ProcessLabel": "",
          "AppArmorProfile": "",
          "EffectiveCaps": null,
          "BoundingCaps": null,
          "ExecIDs": [],
          "GraphDriver": {
               "Name": "overlay",
               "Data": {
                    "LowerDir": "/home/user/.local/share/containers/storage/overlay/d49a100797e83202ba1ecfc6175b67d1fe8e5fe75f54da3ee4262308a916622b/diff:/home/user/.local/share/containers/storage/overlay/d43056af101e2d4cdc651cfdf040d6f107c81620d77808f41223f6f9991ce581/diff:/home/user/.local/share/containers/storage/overlay/c438e503bc1c229234bb171b4b77992a7423bd688d9f96fee535288d2c85060f/diff:/home/user/.local/share/containers/storage/overlay/48792945e4e1b9f4c26265b925061931e57a2748839cbbd458091e793b01c483/diff:/home/user/.local/share/containers/storage/overlay/4219c648e7a6ce168560334375bcf7ebe4d60674c7e0ed1d2133bf7c0a2403ce/diff:/home/user/.local/share/containers/storage/overlay/a7dd58a7a982534dd1c90283ee4304eabae7b47cdaae59a8260c9dfab477d11d/diff:/home/user/.local/share/containers/storage/overlay/2ca4754021bf0d5cfbb2854036b912ad2e5707084c80bd8d188e438201b8e52e/diff:/home/user/.local/share/containers/storage/overlay/ca1f4233d2b0487eac3cf4495286478f0c62d9aa65a38723143748143eabb908/diff:/home/user/.local/share/containers/storage/overlay/e715b54c9641f9e832d1a136ae3cf414ffa2ada20630de35a799e6198d6110f4/diff:/home/user/.local/share/containers/storage/overlay/4e167893ba2f7243ffacc715fa832ddbb596f0a83fa1e1dcfcc7480a05dd6b72/diff:/home/user/.local/share/containers/storage/overlay/cd7010618e91c57771c4e70c076ca7ebed5051f2dadd9cf3594c39535026152a/diff:/home/user/.local/share/containers/storage/overlay/7249826692473065bd49c116884f426135dc4b7a6375219adc1527c5eb880e3b/diff:/home/user/.local/share/containers/storage/overlay/f000331b42681cdec47aebef7ef03be564c1f7d756aae241cec523a997b8ada3/diff:/home/user/.local/share/containers/storage/overlay/45fc035401d0739c04295700f1a0956d14007b33830e7df90d24e6e2ed6e6925/diff:/home/user/.local/share/containers/storage/overlay/33abc4ad76e2099a56041549ac0643312ed831660ea7f28e07f05bc228e12f78/diff",
                    "UpperDir": "/home/user/.local/share/containers/storage/overlay/eea805ebf34086e5bdf0e6812bed93ea7bb0aef8af66c03d02e304d86b616014/diff",
                    "WorkDir": "/home/user/.local/share/containers/storage/overlay/eea805ebf34086e5bdf0e6812bed93ea7bb0aef8af66c03d02e304d86b616014/work"
               }
          },
          "Mounts": [
               {
                    "Type": "bind",
                    "Source": "/home/user/sandbox",
                    "Destination": "/sandbox",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key",
                    "Destination": "/sandbox-secrets/e2e_key",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts",
                    "Destination": "/sandbox-secrets/e2e_known_hosts",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/cdx-offload/git-common/overdeck-73dd7c243420",
                    "Destination": "/home/user/cdx-offload/git-common/overdeck-73dd7c243420",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26",
                    "Destination": "/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/state/overdeck-sandbox/creds/1786320043668380439-3739229-30751/codex/auth.json",
                    "Destination": "/sandbox-secrets/codex/auth.json",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               }
          ],
          "Dependencies": [],
          "NetworkSettings": {
               "EndpointID": "",
               "Gateway": "",
               "IPAddress": "",
               "IPPrefixLen": 0,
               "IPv6Gateway": "",
               "GlobalIPv6Address": "",
               "GlobalIPv6PrefixLen": 0,
               "MacAddress": "",
               "Bridge": "",
               "SandboxID": "",
               "HairpinMode": false,
               "LinkLocalIPv6Address": "",
               "LinkLocalIPv6PrefixLen": 0,
               "Ports": {},
               "SandboxKey": "",
               "Networks": {
                    "pasta": {
                         "EndpointID": "",
                         "Gateway": "",
                         "IPAddress": "",
                         "IPPrefixLen": 0,
                         "IPv6Gateway": "",
                         "GlobalIPv6Address": "",
                         "GlobalIPv6PrefixLen": 0,
                         "MacAddress": "",
                         "NetworkID": "pasta",
                         "DriverOpts": null,
                         "IPAMConfig": null,
                         "Links": null
                    }
               }
          },
          "Namespace": "",
          "IsInfra": false,
          "IsService": false,
          "KubeExitCodePropagation": "invalid",
          "lockNumber": 2,
          "Config": {
               "Hostname": "sandbox-agent-a33d295a0f6813f26-5e47d8cf1563",
               "Domainname": "",
               "User": "agent",
               "AttachStdin": false,
               "AttachStdout": false,
               "AttachStderr": false,
               "Tty": false,
               "OpenStdin": true,
               "StdinOnce": false,
               "Env": [
                    "LANG=C.UTF-8",
                    "PNPM_HOME=/sandbox/home/.local/share/pnpm",
                    "DISABLE_AUTOUPDATER=1",
                    "container=podman",
                    "COREPACK_ENABLE_DOWNLOAD_PROMPT=0",
                    "SANDBOX_TOOLGAP_FILE=/sandbox/toolgap/gaps.jsonl",
                    "SANDBOX_ID=agent-a33d295a0f6813f26-5e47d8cf1563",
                    "SANDBOX_E2E_TARGET=user@host.containers.internal",
                    "PLAYWRIGHT_BROWSERS_PATH=/ms-playwright",
                    "DEBIAN_FRONTEND=noninteractive",
                    "BASH_ENV=/etc/overdeck-sandbox/toolgap.bash",
                    "SANDBOX_E2E_PORT=2222",
                    "PATH=/usr/local/node/bin:/sandbox/home/.local/share/pnpm:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
                    "PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1",
                    "PNPM_STORE_DIR=/sandbox/store/pnpm",
                    "HOME=/sandbox/home",
                    "SANDBOX_IMAGE=localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "HOSTNAME=sandbox-agent-a33d295a0f6813f26-5e47d8cf1563"
               ],
               "Cmd": [
                    "/bin/sh",
                    "-c",
                    "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' \u003e\u00262; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' \u003e\u00262; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' \u003e\u00262; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' \u003e\u00262; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' \u003e\u00262; exit 10; }\n\"$@\"",
                    "sh",
                    "codex",
                    "exec",
                    "--sandbox",
                    "danger-full-access",
                    "--skip-git-repo-check",
                    "-C",
                    "/sandbox/workspaces/agent-a33d295a0f6813f26-5e47d8cf1563",
                    "-m",
                    "gpt-5.6-sol",
                    "-c",
                    "model_reasoning_effort=low",
                    "Fresh independent final security/correctness review for TODO #178. The user's exact request: Apply /tmp/todo178-final.patch in your isolated Overdeck worktree, then review the full applied diff and relevant call sites. Do not rely on prior reviews. Focus P0/P1/P2 only: whole-version atomic runtime under SIGKILL/restart and final activation sequencing; canonical/symlink paths and source TOCTOU; lock ownership; hostile startup/PATH/Git/env; passwd-home; fully-bound durable started receipts before SSH/K3s; no-envelope/retries; inner exits/pod ordering. Do not commit/deploy/install/live mutate. Report exact concrete failure sequences or explicitly clean. Context: the patch is already applied in this exact worktree from the patch's exact git-blob preimages. Review /tmp/todo178-final.patch as the authoritative full diff, inspect the resulting changed files in this worktree, and trace only relevant call sites essential to validate the named invariants. Treat all boundary inputs as hostile and fail closed when a guard cannot be confirmed. Enumerate sibling branches explicitly. For every candidate: state exact trigger/state sequence, re-read and try to refute it once, then report only survivors. Severity scope is P0/P1/P2 (critical/high/medium) only; omit lower-value findings. Do not mutate any files or run deploy/install/live operations. Output a numbered severity-ordered list with Title, absolute Location, Severity, Trigger/failure sequence, and specific Fix. End with Headline naming ship blockers and Residual/unverified. If no exploitable P0/P1/P2 survives, say explicitly clean and list only the top assumptions a deeper review should test."
               ],
               "Image": "localhost/overdeck-agent-sandbox:d1c7f17660b1",
               "Volumes": null,
               "WorkingDir": "/sandbox/workspaces/agent-a33d295a0f6813f26-5e47d8cf1563",
               "Entrypoint": [
                    "/usr/bin/tini",
                    "--"
               ],
               "OnBuild": null,
               "Labels": {
                    "io.buildah.version": "1.43.2"
               },
               "Annotations": {
                    "io.container.manager": "libpod",
                    "io.podman.annotations.cid-file": "/home/user/.local/share/overdeck-sandbox/runs/agent-a33d295a0f6813f26-5e47d8cf1563/cid",
                    "io.podman.annotations.pids-limit": "512",
                    "io.podman.annotations.userns": "keep-id",
                    "org.opencontainers.image.stopSignal": "15",
                    "org.systemd.property.KillSignal": "15",
                    "org.systemd.property.TimeoutStopUSec": "uint64 10000000"
               },
               "StopSignal": "SIGTERM",
               "HealthcheckOnFailureAction": "none",
               "HealthLogDestination": "local",
               "HealthcheckMaxLogCount": 5,
               "HealthcheckMaxLogSize": 500,
               "CreateCommand": [
                    "podman",
                    "run",
                    "--replace",
                    "--interactive",
                    "--cidfile",
                    "/home/user/.local/share/overdeck-sandbox/runs/agent-a33d295a0f6813f26-5e47d8cf1563/cid",
                    "--name",
                    "overdeck-sandbox-agent-a33d295a0f6813f26-5e47d8cf1563",
                    "--hostname",
                    "sandbox-agent-a33d295a0f6813f26-5e47d8cf1563",
                    "--userns=keep-id",
                    "--cap-drop=ALL",
                    "--security-opt=no-new-privileges",
                    "--pids-limit",
                    "512",
                    "--memory",
                    "12g",
                    "--memory-swap",
                    "12g",
                    "--cpus",
                    "4",
                    "--cpu-shares",
                    "256",
                    "--volume",
                    "/home/user/sandbox:/sandbox:rw",
                    "--volume",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key:/sandbox-secrets/e2e_key:ro",
                    "--volume",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts:/sandbox-secrets/e2e_known_hosts:ro",
                    "--volume",
                    "/home/user/cdx-offload/git-common/overdeck-73dd7c243420:/home/user/cdx-offload/git-common/overdeck-73dd7c243420:rw",
                    "--volume",
                    "/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26:/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26:rw",
                    "--volume",
                    "/home/user/.local/state/overdeck-sandbox/creds/1786320043668380439-3739229-30751/codex/auth.json:/sandbox-secrets/codex/auth.json:ro",
                    "--workdir",
                    "/sandbox/workspaces/agent-a33d295a0f6813f26-5e47d8cf1563",
                    "--env",
                    "SANDBOX_ID=agent-a33d295a0f6813f26-5e47d8cf1563",
                    "--env",
                    "SANDBOX_IMAGE=localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "--env",
                    "SANDBOX_E2E_TARGET=user@host.containers.internal",
                    "--env",
                    "SANDBOX_E2E_PORT=2222",
                    "localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "/bin/sh",
                    "-c",
                    "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' \u003e\u00262; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' \u003e\u00262; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' \u003e\u00262; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' \u003e\u00262; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' \u003e\u00262; exit 10; }\n\"$@\"",
                    "sh",
                    "codex",
                    "exec",
                    "--sandbox",
                    "danger-full-access",
                    "--skip-git-repo-check",
                    "-C",
                    "/sandbox/workspaces/agent-a33d295a0f6813f26-5e47d8cf1563",
                    "-m",
                    "gpt-5.6-sol",
                    "-c",
                    "model_reasoning_effort=low",
                    "Fresh independent final security/correctness review for TODO #178. The user's exact request: Apply /tmp/todo178-final.patch in your isolated Overdeck worktree, then review the full applied diff and relevant call sites. Do not rely on prior reviews. Focus P0/P1/P2 only: whole-version atomic runtime under SIGKILL/restart and final activation sequencing; canonical/symlink paths and source TOCTOU; lock ownership; hostile startup/PATH/Git/env; passwd-home; fully-bound durable started receipts before SSH/K3s; no-envelope/retries; inner exits/pod ordering. Do not commit/deploy/install/live mutate. Report exact concrete failure sequences or explicitly clean. Context: the patch is already applied in this exact worktree from the patch's exact git-blob preimages. Review /tmp/todo178-final.patch as the authoritative full diff, inspect the resulting changed files in this worktree, and trace only relevant call sites essential to validate the named invariants. Treat all boundary inputs as hostile and fail closed when a guard cannot be confirmed. Enumerate sibling branches explicitly. For every candidate: state exact trigger/state sequence, re-read and try to refute it once, then report only survivors. Severity scope is P0/P1/P2 (critical/high/medium) only; omit lower-value findings. Do not mutate any files or run deploy/install/live operations. Output a numbered severity-ordered list with Title, absolute Location, Severity, Trigger/failure sequence, and specific Fix. End with Headline naming ship blockers and Residual/unverified. If no exploitable P0/P1/P2 survives, say explicitly clean and list only the top assumptions a deeper review should test."
               ],
               "Umask": "0022",
               "Timeout": 0,
               "StopTimeout": 10,
               "Passwd": true,
               "sdNotifyMode": "container"
          },
          "HostConfig": {
               "Binds": [
                    "/home/user/sandbox:/sandbox:rw,rprivate,rbind",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key:/sandbox-secrets/e2e_key:ro,rprivate,rbind",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts:/sandbox-secrets/e2e_known_hosts:ro,rprivate,rbind",
                    "/home/user/cdx-offload/git-common/overdeck-73dd7c243420:/home/user/cdx-offload/git-common/overdeck-73dd7c243420:rw,rprivate,rbind",
                    "/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26:/home/user/cdx-offload/git-common/overdeck-73dd7c243420/worktrees/agent-a33d295a0f6813f26:rw,rprivate,rbind",
                    "/home/user/.local/state/overdeck-sandbox/creds/1786320043668380439-3739229-30751/codex/auth.json:/sandbox-secrets/codex/auth.json:ro,rprivate,rbind"
               ],
               "CgroupManager": "systemd",
               "CgroupMode": "private",
               "ContainerIDFile": "/home/user/.local/share/overdeck-sandbox/runs/agent-a33d295a0f6813f26-5e47d8cf1563/cid",
               "LogConfig": {
                    "Type": "journald",
                    "Config": null,
                    "Path": "",
                    "Tag": "",
                    "Size": "-1B"
               },
               "NetworkMode": "pasta",
               "PortBindings": {},
               "RestartPolicy": {
                    "Name": "no",
                    "MaximumRetryCount": 0
               },
               "AutoRemove": false,
               "AutoRemoveImage": false,
               "Annotations": {
                    "io.container.manager": "libpod",
                    "io.podman.annotations.cid-file": "/home/user/.local/share/overdeck-sandbox/runs/agent-a33d295a0f6813f26-5e47d8cf1563/cid",
                    "io.podman.annotations.pids-limit": "512",
                    "io.podman.annotations.userns": "keep-id",
                    "org.opencontainers.image.stopSignal": "15",
                    "org.systemd.property.KillSignal": "15",
                    "org.systemd.property.TimeoutStopUSec": "uint64 10000000"
               },
               "VolumeDriver": "",
               "VolumesFrom": null,
               "CapAdd": [],
               "CapDrop": [
                    "CAP_CHOWN",
                    "CAP_DAC_OVERRIDE",
                    "CAP_FOWNER",
                    "CAP_FSETID",
                    "CAP_KILL",
                    "CAP_NET_BIND_SERVICE",
                    "CAP_SETFCAP",
                    "CAP_SETGID",
                    "CAP_SETPCAP",
                    "CAP_SETUID",
                    "CAP_SYS_CHROOT"
               ],
               "Dns": [],
               "DnsOptions": [],
               "DnsSearch": [],
               "ExtraHosts": [],
               "HostsFile": "",
               "GroupAdd": [],
               "IpcMode": "shareable",
               "Cgroup": "",
               "Cgroups": "default",
               "Links": null,
               "OomScoreAdj": 0,
               "PidMode": "private",
               "Privileged": false,
               "PublishAllPorts": false,
               "ReadonlyRootfs": false,
               "SecurityOpt": [
                    "no-new-privileges"
               ],
               "Tmpfs": {},
               "UTSMode": "private",
               "UsernsMode": "private",
               "IDMappings": {
                    "UidMap": [
                         "0:1:1000",
                         "1000:0:1",
                         "1001:1001:64536"
                    ],
                    "GidMap": [
                         "0:1:1000",
                         "1000:0:1",
                         "1001:1001:64536"
                    ]
               },
               "ShmSize": 65536000,
               "Runtime": "oci",
               "ConsoleSize": [
                    0,
                    0
               ],
               "Isolation": "",
               "CpuShares": 256,
               "Memory": 12884901888,
               "NanoCpus": 4000000000,
               "CgroupParent": "user.slice",
               "BlkioWeight": 0,
               "BlkioWeightDevice": null,
               "BlkioDeviceReadBps": null,
               "BlkioDeviceWriteBps": null,
               "BlkioDeviceReadIOps": null,
               "BlkioDeviceWriteIOps": null,
               "CpuPeriod": 100000,
               "CpuQuota": 400000,
               "CpuRealtimePeriod": 0,
               "CpuRealtimeRuntime": 0,
               "CpusetCpus": "",
               "CpusetMems": "",
               "Devices": [],
               "DiskQuota": 0,
               "KernelMemory": 0,
               "MemoryReservation": 0,
               "MemorySwap": 12884901888,
               "MemorySwappiness": -1,
               "OomKillDisable": false,
               "PidsLimit": 512,
               "Ulimits": [
                    {
                         "Name": "RLIMIT_NOFILE",
                         "Soft": 524288,
                         "Hard": 524288
                    },
                    {
                         "Name": "RLIMIT_NPROC",
                         "Soft": 127162,
                         "Hard": 127162
                    }
               ],
               "CpuCount": 0,
               "CpuPercent": 0,
               "IOMaximumIOps": 0,
               "IOMaximumBandwidth": 0,
               "CgroupConf": null
          },
          "UseImageHosts": false,
          "UseImageHostname": false
     }
]
