Begin upload
Starts an upload session for content that may later be attached to a file. Service-proxied uploads send bytes through the server; direct-put uploads return object-store presigned credentials.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”Namespace id
Request Body required
Section titled “Request Body required ”Request for starting an upload session.
object
Optional for direct_multipart; selects the part geometry. Absent
takes the server’s default. direct_multipart claims its content at
completion, so nothing about the payload is declared here.
object
Byte length of every part except the last, or None for the
server’s default.
The value bounds the object: a provider accepts at most 10,000
parts, so this session can carry at most part_size_bytes × 10_000
bytes. A client that knows its payload is very large asks for a
larger part size; one that does not know its length at all takes the
default and keeps asking for part URLs until its stream ends.
Responses
Section titled “ Responses ”Upload session started
Response for starting an upload session.
object
Presigned write details for DirectPut, or None for ServiceProxied.
object
Short-lived URL plus required headers for one object-store write.
object
Expiration timestamp in Unix milliseconds.
Headers that are covered by the signature and must be sent.
object
HTTP method the client must use.
Full presigned URL.
Immutable object identity the server minted, plus the byte length and checksum covered by the signed request. Completion and the later commit both name exactly this reference.
object
Immutable identity of the referenced object.
Content strategy used by the referenced object.
Complete byte length of the referenced content.
Mandatory checksum over the complete object, used to verify the stored bytes against this reference without downloading them.
object
Algorithm that produced value.
Lowercase hex of the raw checksum bytes.
The algorithm is its own field, so the value carries no prefix. Provider APIs that report base64 are converted at the adapter.
SHA-256 over the complete payload, lowercase hex, when a trusted party computed it.
Present means the LoonFS write path hashed the whole stream itself, or a provider validated a signed whole-object SHA-256 on the write. There are no client-claimed digests: absent means nobody trustworthy hashed these bytes, never “the client did not tell us”.
Transport selected after applying server capability and request validation.
Namespace authorized to consume the eventual staged content.
Durable session identity used by subsequent append and completion calls.
Invalid upload request
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Unauthorized
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Namespace not found
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Namespace deleted
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Requested upload mode is unsupported
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.