Apply a commit
Applies one commit: an ordered, non-empty list of path operations that commit together as one logical commit, under one commit id that makes retries idempotent. Request preconditions check the pre-state after receipt resolution and before operations; a failed precondition names its position in details.precondition_index. A single-operation call is the one-element case. The first operation that fails aborts the whole request, and a request carrying more than one operation names that operation’s position in details.operation_index.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”Namespace id
Header Parameters
Section titled “Header Parameters ”Stable opaque actor id containing 1 to 256 visible ASCII characters.
Example
usr_8f3cStable opaque actor ID supplied by the application. Keep this value unchanged when retrying a commit; it is attribution, not authentication.
Request Body required
Section titled “Request Body required ”A request to commit one or more filesystem operations atomically in order.
Unknown fields are rejected.
object
Caller-supplied idempotency key for the whole request.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The proofs for new external content references in this request.
Proof that a specific content_ref may be used in a later commit.
object
Content authorized by this token.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
The opaque server-signed token that clients must not parse.
The caller annotation that forms part of the commit identity.
The non-empty ordered operations to commit atomically.
Create one directory.
object
Whether to create missing ancestor directories while requiring the final component to be new.
Absolute destination path, rejected when invalid or already bound.
Example
/docs/report.txtCreate a directory under an existing parent inode.
object
New directory name.
Example
report.txtParent directory.
Example
ino_123Create or replace one file from uploaded or inline content. Requires exactly one of content_ref and inline_content.
object
Whether an existing file may receive a new revision instead of causing a conflict.
Uploaded content covered by a token; mutually exclusive with inline_content.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
With replace behavior, the request requires the path to contain this inode.
Example
ino_123With replace behavior and an inode precondition, the request requires this content revision.
Complete file bytes as base64; mutually exclusive with content_ref.
Absolute destination path; missing ancestors are created automatically.
Example
/docs/report.txtCreate a file with an unused name under an existing parent inode. Requires exactly one of content_ref and inline_content.
object
Uploaded content covered by a token; mutually exclusive with inline_content.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
New file name.
Example
report.txtComplete file bytes as base64; mutually exclusive with content_ref.
Parent directory.
Example
ino_123Append a revision to a file inode if its current revision matches. Requires exactly one of content_ref and inline_content.
object
Uploaded content covered by a token; mutually exclusive with inline_content.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
Current revision required for the write.
Complete file bytes as base64; mutually exclusive with content_ref.
File to update.
Example
ino_123Delete one path.
object
Whether a non-empty directory may be tombstoned recursively.
The inode that the path must still resolve to before deletion.
Example
ino_123Absolute path that must resolve to a visible inode.
Example
/docs/report.txtDelete an inode if its current binding matches.
object
Whether a non-empty directory may be tombstoned recursively.
Binding version required for the delete.
Inode to delete.
Example
ino_123Move one path to another path.
object
Whether an existing destination file may be replaced.
Absolute destination whose parent must be visible and writable.
Example
/docs/report.txtWith replace behavior, the destination inode required by the request.
Example
ino_123With replace behavior and an inode precondition, the required content revision.
Absolute source path that must resolve to a visible inode.
Example
/docs/report.txtMove an inode if its current binding matches.
object
Whether an existing destination file may be replaced.
New name.
Example
report.txtDestination directory.
Example
ino_123Binding version required for the move.
With replace behavior, the destination inode required by the request.
Example
ino_123With replace behavior and an inode precondition, the required content revision.
Inode to move.
Example
ino_123Copy one file path to another path.
object
Whether an existing destination file may be replaced.
Absolute destination whose parent must be visible and writable.
Example
/docs/report.txtWith replace behavior, the destination inode required by the request.
Example
ino_123With replace behavior and an inode precondition, the required content revision.
Absolute source path that must resolve to a visible file.
Example
/docs/report.txtRestore the deletion identified by inode_id and deletion_seq.
object
Observed deletion sequence, which prevents cancelling a newer tombstone sequence.
The restore destination. Omit it to use the recorded binding.
Example
/docs/report.txtDeleted inode to make reachable again.
Example
ino_123Restore an older revision as the current revision for a path.
object
Absolute path that must resolve to a visible file.
Example
/docs/report.txtExisting historical revision whose content will be copied into a new current revision.
Write and remove attributes on the inode one path resolves to.
object
With an inode precondition, the attribute revision that must still be current.
The inode that the path must still resolve to before the update.
Example
ino_123Absolute path that must resolve to a visible file or directory.
Example
/docs/report.txtThe attribute keys to remove, including duplicates that validation must reject.
The attributes to write, replacing values for matching keys and leaving other keys unchanged.
object
A validated inode attribute value of at most 4,096 UTF-8 bytes.
Empty strings and control characters are valid, and only an explicit remove operation deletes an attribute.
Example
platformReplace the access row of the inode one path resolves to. The root path is a valid target.
object
Whether the directory stops inheritance from its ancestors.
With an inode precondition, the access revision that must still be current.
The inode that the path must still resolve to before the update.
Example
ino_123The inode’s complete direct grants after this update.
object
A set of rights. Encoded as distinct names in read, history, write, create, remove, share, manage, admin order. Decoding accepts any order and rejects repeated names.
Absolute path that must resolve to a visible file or directory.
Example
/docs/report.txtOrdered admission conditions evaluated before any operations.
Requires the pre-state head sequence to equal expected_head_seq.
object
Sequence observed when the caller read its inputs.
Requires a visible inode with the content revision the caller read.
object
Content revision observed by the caller.
Inode whose state the caller read.
Example
ino_123Requires the path to retain the binding the caller read.
object
Detects moves away and back.
Inode required at the path.
Example
ino_123Absolute path to check, including the root.
Example
/docs/report.txtRequires a visible inode with the attribute revision the caller read.
object
Attribute revision observed by the caller.
Inode whose state the caller read.
Example
ino_123Requires a visible inode with the access revision the caller read.
object
Access revision observed by the caller.
Inode whose state the caller read.
Example
ino_123Requires no visible entry at the full path.
object
Absolute path to check, including the root.
Example
/docs/report.txtResponses
Section titled “ Responses ”Commit applied
One committed logical commit: its identity and the events it applied.
object
The idempotency key for the commit.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The commit time in Unix milliseconds; committed_seq defines commit order.
Actor responsible for the commit, as supplied by the application.
Example
usr_8f3cSequence number where the commit became visible.
The semantic filesystem operations the commit applied, in request order.
A directory was created.
object
Opaque identifier for the binding created by this event.
User-facing spelling of the new entry.
Example
report.txtNewly allocated namespace-scoped inode identity.
Example
ino_123Directory the new entry was bound under.
Example
ino_123A file and its first revision were created.
object
Opaque identifier for the binding created by this event.
Content of the first revision.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
User-facing spelling of the new entry.
Example
report.txtNewly allocated namespace-scoped inode identity.
Example
ino_123Directory the new entry was bound under.
Example
ino_123First revision number.
A file received a new current revision from a put or revision restore.
object
Immutable content published by the revision.
object
Mandatory checksum over the complete object.
object
Algorithm that produced value.
The canonical lowercase hexadecimal checksum without a prefix.
Immutable identity of the content; with the owner, it determines the object key.
Example
con_9f2a6c0e4b7d4a90b13f0d8c5e6a2b41Content strategy used by the referenced content.
Namespace that originally wrote the bytes.
Example
demoComplete byte length of the referenced content.
File inode whose history advanced.
Example
ino_123New monotonic position in that file’s revision history.
An inode moved to a new parent directory or name.
object
Opaque identifier for the binding created by this event.
Spelling of the new binding.
Example
report.txtDirectory holding the new binding.
Example
ino_123Inode whose binding changed.
Example
ino_123Spelling of the removed binding.
Example
report.txtDirectory that held the removed binding.
Example
ino_123A file or directory subtree was deleted.
object
Directory binding removed by the deletion.
object
Name shown to users.
Example
report.txtName used to look up the entry.
Example
report.txtParent directory containing the entry.
Example
ino_123Inode at the root of the deleted subtree.
Example
ino_123A deleted inode was recovered and re-bound.
object
Opaque identifier for the binding created by this event.
Spelling of the recovered binding.
Example
report.txtRecovered inode.
Example
ino_123Directory the recovered entry was bound under.
Example
ino_123An inode’s attributes changed.
object
The inode’s complete attribute map after the update, including an empty map when all attributes were cleared.
object
A validated inode attribute value of at most 4,096 UTF-8 bytes.
Empty strings and control characters are valid, and only an explicit remove operation deletes an attribute.
Example
platformNew attribute revision for that inode.
Inode whose attributes advanced.
Example
ino_123An inode’s access row was replaced. grants is the complete direct grant map after the update.
object
Revision published by the update.
Whether the directory stops inheritance from its ancestors.
The inode’s complete direct grants after this update.
object
A set of rights. Encoded as distinct names in read, history, write, create, remove, share, manage, admin order. Decoding accepts any order and rejects repeated names.
Inode whose access state advanced.
Example
ino_123The optional caller annotation for the commit.
Namespace that changed.
Example
demoInvalid commit
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
Unauthorized
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
Namespace or path not found
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
Operation conflict
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
Namespace deleted
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
JSON body exceeds the 2 MiB limit
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
Inline content is disabled
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.
The server cannot complete the request now. Inspect code to determine whether the cause is a deadline, shutdown, load, writer-session admission, required maintenance, or invalid storage credentials. A mutation may still complete after a deadline or lost acknowledgment, so determine its outcome before retrying.
HTTP error body used by LoonFS APIs.
object
The stable machine-readable error code as a string.
The optional machine-readable context for the error code.
object
The Unix-millisecond time when the current writer acquired its epoch, when available.
Epoch that currently owns the namespace.
The writer ID recorded for the current epoch, when available.
Access revision that is actually current for the inode.
Attribute revision that is actually current for the inode.
Current binding token; absent for the root, which has no binding.
Deletion sequence actually active for the inode.
The actual namespace head sequence.
The path actually contained this inode.
Example
ino_123Revision that is actually current; absent when the inode has none.
Change-feed cursor the request asked to resume after.
Idempotency key of the commit the error concerns.
Example
c_f3a9c2d4b6e8417a90c5d2f8e1b7a6c0The fingerprint of the mutation that landed under commit_id, present with committed_seq.
The sequence where this commit ID already landed, when recorded by a durable receipt.
Access revision the request expected to be current.
Attribute revision the request expected to be current.
Opaque binding token supplied by the request.
Deletion sequence the undelete expected to be active.
The head sequence required by the request.
The request expected the path to contain this inode.
Example
ino_123Revision the request expected to be current.
Epoch the failing writer session held when it was displaced.
Inode the failed precondition or operation targeted.
Example
ino_123Maximum writer sessions admitted by the node.
The deleted namespace that caused the operation to fail.
Example
demoThe index of the failed operation in the request.
Zero-based position of the failed request precondition.
Oldest sequence still promised for incremental replay.
The capability feature key for a not_supported error.
Human-readable error message.
The invalid JSON Pointer, parameter name, CLI flag, or CLI argument.
The request correlation ID also sent in the x-request-id response header.