fix(fuse): fail closed on incomplete or invalid namespace listings - #375
Merged
beinan merged 1 commit intoJul 28, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #369. Requiring a namespace prefix fixed the empty-root startup request, but the mount could still report success with a partial, out-of-scope, or POSIX-unrepresentable listing.
This change makes startup listing fail closed end to end:
Correctness model
The control protocol remains schema v2 and intentionally does not add pagination in this follow-up. Because there is no continuation token on the wire, crossing any server-side listing limit is an explicit failure rather than an apparently successful truncated mount.
The coordinator uses one absolute deadline across all worker attempts. A silent worker cannot reset or consume the complete request budget: with a 25-second listing budget and two workers, the first can use up to 24 seconds while one second remains for failover. When the remaining budget is smaller, attempts share it evenly.
All listing paths are validated as one transaction before populate_from_listing runs, so a single invalid entry cannot leave a partially built mount.
Tests
The full worker crate cannot compile on this macOS host because its existing splice, sendfile, CPU-affinity, and io_uring paths are Linux-only. The new worker regression tests are included for Linux CI. Java changes are Javadoc-only; Java CI will run the Maven suite.