rrnewton
## Summary `hermit run --verify` does not honor the normal run container's `--tmp` or environment configuration. ## Reproduction Run a program that must be mounted through a user-provided tmp directory: ```sh mkdir -p /tmp/hermit-verify-repro cp /bin/true /tmp/hermit-verify-repro/guest hermit run --tmp=/tmp/hermit-verify-repro --verify -- /tmp/guest ``` The first verify run reports that `/tmp/guest` does not exist. A non-verify run with the same `--tmp` succeeds. Environment overrides are also bypassed by the verify execution path. ## Cause `RunOpts::run_verify` always creates a fresh `TempDir` instead of calling `self.tmpfs()` (there is already a TODO noting this), and `run_verify_in_container` builds its command without the `base_env` / `merge_from_env_settings` handling used by `run_in_container`. ## Impact Tests and workloads using `--verify` cannot rely on explicit tmp contents or `--env` behavior matching ordinary `hermit run`. This was found while porting Detcore lit fixtures to Cargo.