Expand description
Re-exports§
pub use v0::AdvanceRetentionRequest;pub use v0::AdvanceRetentionResponse;pub use v0::ApiError;pub use v0::AttributesProjection;pub use v0::Checkpoint;pub use v0::CheckpointOwnerSummary;pub use v0::CommitRequest;pub use v0::CommitResponse;pub use v0::CreateCheckpointRequest;pub use v0::CreateNamespaceRequest;pub use v0::CreateSnapshotRequest;pub use v0::DeleteDirectoryBehavior;pub use v0::DeleteNamespaceResponse;pub use v0::DeletedObjectCounts;pub use v0::DestinationBehavior;pub use v0::ErrorDetails;pub use v0::ExtendSnapshotRequest;pub use v0::FileBytes;pub use v0::FileRevision;pub use v0::FilesystemOperation;pub use v0::FlushWalOutcome;pub use v0::FlushWalResponse;pub use v0::ForkNamespaceRequest;pub use v0::GcRequest;pub use v0::GcResponse;pub use v0::GrepMatch;pub use v0::GrepRequest;pub use v0::GrepResponse;pub use v0::ListCheckpointsResponse;pub use v0::ListFileRevisionsResponse;pub use v0::ListInodeChildrenResponse;pub use v0::ListPathEntriesResponse;pub use v0::ListSnapshotsResponse;pub use v0::ListTrashResponse;pub use v0::MaintenanceStepRequest;pub use v0::MaintenanceStepResponse;pub use v0::MetadataMaintenanceRequest;pub use v0::MetadataMaintenanceResponse;pub use v0::Namespace;pub use v0::NamespaceDiagnostics;pub use v0::PathEntry;pub use v0::PathEntryKind;pub use v0::ReleaseCheckpointResponse;pub use v0::ReleaseSnapshotResponse;pub use v0::ReleasedCheckpointCounts;pub use v0::ReorganizeStepOutcome;pub use v0::RetainedCandidates;pub use v0::RetainedReason;pub use v0::SnapshotSummary;pub use v0::TrashEntry;pub use v0::WalFlushStepOutcome;
Modules§
- env
- Environment variables used by more than one LoonFS process.
- options
- Per-operation options shared by the embedded runtime and HTTP client.
- public_
inode_ id - Converts inode IDs between internal numbers and public API strings.
- v0
- The v0 HTTP protocol shapes.
- wire
- Durable wire formats grouped by their owning format family.
Structs§
- Absolute
Path - Canonical absolute path plus its parsed components.
- ActorId
- A validated actor identifier supplied by the application.
- Actor
IdValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Actor
Ref - Identifies the user, service, or system responsible for a commit.
- Attribute
Key - Validated name of one inode attribute.
- Attribute
KeyValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Attribute
Revision No - Revision number for an inode’s attributes.
- Attribute
Value - One validated attribute value.
- Attribute
Value Validation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Attributes
- A validated attribute map for one inode.
- Capability
Document - A deployment’s self-description (API spec, “Capability discovery”).
- Change
Seq - Sequence number assigned to a namespace commit.
- Checkpoint
Id - Durable checkpoint identifier.
- Checksum
- An algorithm and its canonical lowercase-hex checksum value.
- Commit
Id - Client-supplied idempotency key for one logical commit.
- Commit
IdValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Content
Id - Durable identity of one immutable content object.
- Content
Ref - Pointer to one immutable content object.
- Content
Store Id - Durable id for an immutable content store.
- Crc32c
- Incremental CRC-32C (Castagnoli) checksum.
- Crc64
Nvme - CRC-64/NVME over a payload delivered in pieces.
- Directory
Page Cursor - Cursor for one directory listing position.
- Display
Name - User-facing spelling of one path component.
- Effective
Limit - A validated page size selected from a caller request and a policy.
- File
Revisions Page Cursor - Cursor for one file revision listing position.
- Generated
IdValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Grep
Manifest Object Id - Durable object id for one stored grep manifest.
- Grep
Page Cursor - Cursor for one content-search (grep) snapshot.
- Index
Segment Id - Durable id for one derived-index segment file.
- InodeId
- Numeric identity of a file or directory within a namespace.
- Manifest
No - Monotonic manifest counter for one namespace.
- Manifest
Object Id - Durable object id for one namespace manifest candidate.
- Metadata
Compaction Id - Durable id for one streaming metadata compaction job.
- Metadata
Segment Id - Durable id for one metadata segment.
- NameKey
- Name-policy-derived directory entry key.
- Name
KeyValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Namespace
Id - Durable id for one namespace.
- Namespace
IdValidation Error - Describes why supplied text does not satisfy this identifier’s validation contract.
- Page
- Typed result envelope for internal runtime/core page methods.
- Page
Request - Typed request envelope for internal runtime/core page methods.
- Pagination
Policy - Fixed pagination contract for endpoints with potentially unbounded results.
- Path
Component - One path segment as stored, preserving display spelling.
- Public
Ordinal Range Error - Returned when an ordinal exceeds
MAX_PUBLIC_INTEGER. - PutRetry
Attempt - Details of the retried PUT being compared with an existing receipt.
- PutRetry
Receipt - Receipt data needed to verify a PUT that reused a commit ID.
- Revision
No - Revision number for a file’s content.
- RunNo
- Monotonic run counter allocated by the manifest that names the run.
- Secret
String - A secret string such as an access key, token, or signing secret.
- Semantic
Fingerprint Error - Error returned when the canonical fingerprint input cannot be encoded.
- Sha256
- SHA-256 over a payload delivered in pieces.
- Trash
Page Cursor - Cursor for one trash listing position.
- Upload
Id - Durable id for one upload session.
- WalSegment
Id - Durable id for one WAL segment.
- Writer
Epoch - Counter used to reject writes from an older writer.
Enums§
- Actor
Kind - The type of actor responsible for a commit.
- Attributes
Error - Describes which attribute-map limit an input broke.
- Capability
Document Error - Violation of the capability document rules.
- Checksum
Algorithm - Supported checksum algorithms.
- Checksum
Validation Error - Describes why a checksum is not in its canonical wire form.
- Content
Evidence - Available proof that a payload matches a committed content reference.
- Content
RefKind - Kind of content reference.
- Content
RefValidation Error - Describes why a content reference cannot be part of a durable commit.
- Error
Code - Stable machine-readable error reason.
- Error
Kind - Broad error category for caller or operator action.
- Inode
Kind - Filesystem item kind.
- Limit
Error - Invalid caller-supplied page size.
- Namespace
Cursor Error - Why a namespace-bound cursor cannot resume the enumeration replaying it.
- Page
Cursor Error - Invalid opaque page cursor.
- Path
Error - Describes why caller-supplied path or display-name text is not admissible.
- PutRetry
Error Classification - Classification of an error encountered while verifying a retried PUT.
- Streaming
Checksum - Incremental checksum for streamed reads and writes.
Constants§
- DEFAULT_
MAX_ PAGE_ LIMIT - Contract maximum accepted page size.
- DEFAULT_
PAGE_ LIMIT - Contract page size for endpoints that omit a caller-supplied limit.
- FEATURE_
ADMIN_ GREP_ INDEX - Gates grep-index administration: enabling a namespace’s grep root, disabling it, collecting its garbage, and reading its lifecycle.
- FEATURE_
ATTRIBUTES - Gates inode attributes: writing them, and projecting them onto reads. Attributes are part of the core plane, not a composed extension, so a deployment that serves the core profile serves them.
- FEATURE_
DOWNLOADS_ DIRECT_ GET - Gates download grants that are authorized with short-lived presigned URLs. A deployment that offers any direct transfer advertises this one, because letting a client write an object too large to proxy back means being able to hand it back.
- FEATURE_
INODES_ LIST_ CHILDREN - Gates listing a directory’s children by parent inode ID. Part of the core plane and implemented by the runtime, so current deployments advertise it; the key exists so inode-driven sync clients can gate on deployments built before the route.
- FEATURE_
NAMESPACES_ CREATE - Gates namespace creation.
- FEATURE_
NAMESPACES_ DELETE - Gates namespace deletion.
- FEATURE_
NAMESPACES_ FORK - Gates namespace forking.
- FEATURE_
QUERY_ GREP - Gates grep-index content search: the serving half of the capability; the namespace’s verified active grep root is the data half.
- FEATURE_
SNAPSHOTS - Gates read-snapshot lifecycle operations.
- FEATURE_
UPLOADS_ DIRECT_ MULTIPART - Starting presigned
direct_multipartupload sessions. Independent ofFEATURE_UPLOADS_DIRECT_PUT: a provider may sign whole-object writes without having an S3-style multipart API at all. - FEATURE_
UPLOADS_ DIRECT_ PUT - Gates direct upload sessions that are authorized with short-lived presigned URLs.
- FIRST_
ALLOCATABLE_ INODE_ ID - First inode id available after the root inode.
- LIMIT_
COMMIT_ MAX_ CONTENT_ TOKENS - Advisory limit: the most content tokens one commit may carry.
- LIMIT_
COMMIT_ MAX_ EXTERNAL_ CONTENT_ REFS - Advisory limit: the most distinct external content refs one commit’s operations may name.
- LIMIT_
COMMIT_ MAX_ MESSAGE_ BYTES - Advisory limit: the largest accepted commit
message, in bytes. - LIMIT_
COMMIT_ MAX_ OPERATIONS - Advisory limit: the most path operations one commit may carry; a longer
list answers
invalid_requestbefore planning. - LIMIT_
DOWNLOAD_ MAX_ CONCURRENT - Advisory limit: how many service-proxied content reads the deployment
materializes at once; requests past the cap answer
server_busy. - LIMIT_
DOWNLOAD_ MAX_ CONTENT_ BYTES - Advisory limit: the largest file content a service-proxied read will buffer and return in one response.
- LIMIT_
GC_ MIN_ GRACE_ WINDOW_ MS - Advisory limit: the smallest accepted
grace_window_mson agcrequest; smaller values answerinvalid_request. Derived from the publication budgets, not tuned. - LIMIT_
PAGINATION_ DEFAULT - Advisory capability key for the default page size applied when callers omit
limit. - LIMIT_
PAGINATION_ MAX - Advisory capability key for the largest page size accepted by a deployment.
- LIMIT_
QUERY_ GREP_ DEFAULT - Advisory limit: matches per grep page when the request omits
limit. - LIMIT_
QUERY_ GREP_ MAX - Advisory limit: the largest accepted grep page limit. Distinct from the pagination keys — a grep item costs a verified file read, not a row.
- LIMIT_
QUERY_ GREP_ SCAN_ BUDGET_ FILES - Advisory limit: files a plan-less
allow_scangrep will scan before refusing withquery_unindexable. - LIMIT_
QUERY_ GREP_ TAIL_ BUDGET_ FILES - Advisory limit: unindexed-tail revisions one grep scans exhaustively
before failing with
index_lagging. - LIMIT_
SNAPSHOT_ MAX_ LIFETIME_ MS - Advisory limit: the largest snapshot expiry measured from record creation.
- LIMIT_
SNAPSHOT_ MAX_ LIVE_ PER_ NAMESPACE - Advisory limit: the most live snapshots one namespace may hold.
- LIMIT_
SNAPSHOT_ MAX_ TTL_ MS - Advisory limit: the largest snapshot TTL one request may ask for.
- LIMIT_
UPLOAD_ COMPLETION_ MAX_ BODY_ BYTES - Advisory limit: the largest JSON body accepted when completing an upload. It is large enough for the maximum number of multipart entries.
- LIMIT_
UPLOAD_ DIRECT_ PUT_ MAX_ CONTENT_ BYTES - Advisory limit: the largest object this deployment’s provider accepts in
one presigned
direct_putrequest. - LIMIT_
UPLOAD_ MAX_ CONCURRENT - Advisory limit: how many service-proxied upload bodies the deployment
buffers at once; requests past the cap answer
server_busy. - LIMIT_
UPLOAD_ MAX_ CONTENT_ BYTES - Advisory limit: the largest request body accepted for service-proxied upload content requests. This is the proxy’s cap, not the provider’s.
- MAX_
ATTRIBUTES_ TOTAL_ BYTES - Maximum total size of one attribute map in logical UTF-8 bytes. The total counts every key’s bytes plus every value’s bytes. It excludes encoder framing, so the limit does not move when the map is written as JSON instead of CBOR.
- MAX_
ATTRIBUTE_ ENTRIES - Maximum number of entries in one attribute map.
- MAX_
ATTRIBUTE_ KEY_ BYTES - Maximum attribute key length in UTF-8 bytes.
- MAX_
ATTRIBUTE_ VALUE_ BYTES - Maximum length of one attribute value in UTF-8 bytes.
- MAX_
DISPLAY_ NAME_ BYTES - Maximum stored display-name length in UTF-8 bytes: the 255-byte component cap of mainstream filesystems (ext4, APFS, NTFS components) and drives. Names are stored as given, so the cap applies to the bytes as given.
- MAX_
ID_ BYTES - Maximum validated namespace and commit id length in UTF-8 bytes.
- MAX_
NAME_ KEY_ BYTES - Maximum name-key length in UTF-8 bytes. Keys are derived from display
names capped at
crate::path::MAX_DISPLAY_NAME_BYTES; case folding expands at most threefold in bytes, so 768 admits every key derivable from a valid name while bounding row keys, filter keys, and cursors. - MAX_
PATH_ BYTES - Largest canonical absolute path, in UTF-8 bytes. Bounded so every real filesystem, archive format, and sync client can materialize any stored tree; per-component limits alone allowed paths no target could hold.
- MAX_
PATH_ DEPTH - Deepest directory nesting one path may express.
- MAX_
PUBLIC_ INTEGER - Maximum value for an ordinal exposed through the API.
- PAGE_
CURSOR_ FORMAT_ VERSION - Format version written into every encoded cursor.
- PROFILE_
ADMIN_ V0 - The optional maintenance plane.
- PROFILE_
CORE_ V0 - The mandatory data plane.
- PROFILE_
QUERY_ V0 - The optional derived-index query plane.
- PROTOCOL_
VERSION - The protocol generation this build speaks.
- RESERVED_
ATTRIBUTE_ KEY_ PREFIX - Key prefix reserved for system-owned attributes.
- ROOT_
INODE_ ID - Inode 1 is always the root directory of a namespace.
Traits§
- Namespace
Cursor - A cursor that resumes an enumeration of one namespace’s own keyspace.
- Page
Cursor - One paginated endpoint’s cursor.
Functions§
- decode_
cursor - Decodes a cursor issued by
encode_cursorfor the same endpoint. - decode_
namespace_ cursor - Decodes a cursor issued for
expected_namespace_id’s own keyspace. - encode_
cursor - Encodes a cursor as the opaque string clients round-trip.
- generated_
id - Generates a project-standard opaque durable identifier.
- manifest_
object_ id_ manifest_ no - Returns the manifest number in an object id’s 20-digit position.
- name_
key_ for_ display_ name - Derives the canonical lookup key for a display name.
- next_
public_ ordinal - Returns the next ordinal, or
Noneif the value is already at the limit. - put_
retry_ fingerprint - Computes the fingerprint for a retried single-file PUT using the content reference from the original commit.
- reconcile_
put_ commit_ id_ reuse - Checks whether a PUT rejected for commit-ID reuse is an exact retry of an earlier successful PUT.
- semantic_
commit_ fingerprint - Computes the semantic fingerprint used to validate a reused commit ID.
- sha256_
digest - Computes the durable
sha256:digest spelling used by envelope payloads and local compare tokens. - wal_
segment_ id_ start_ seq - Start seq encoded in a WAL segment id’s 20-digit position.