Harden namespace directory ownership and lifecycle cleanup - #36
Open
raphaelfeitoza wants to merge 5 commits into
Open
raphaelfeitoza wants to merge 5 commits into
raphaelfeitoza wants to merge 5 commits into
Conversation
raphaelfeitoza
added this pull request to stack #37
October 1, 2026 14:49
raphaelfeitoza
marked this pull request as ready for review
October 1, 2026 18:29
raphaelfeitoza
force-pushed
the
fix/namespace-directory-ownership-89265
branch
from
October 1, 2026 19:54
744ca2f to
09e4e6a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stack
Depends on #31 (
fix/namespace-path-traversal-89265). Review this PR against that branch, notmain; merge #31 first.This extracts directory-ownership and lifecycle hardening from #31; its minimal namespace-string traversal fix remains independently reviewable.
Summary
jobstable.Review and threat model
Independent correctness, security and read-only cross-file reviews found no remaining high/critical issue on final commit
744ca2f75f5cce3141b6400c62ee49fbc4cd1dbbwithin the trusted single-process/process-crash model. A Linux CI replica-reset regression on the preceding commit was fixed by744ca2f75fand the same cluster test passed in the full rerun.This is not a general atomic-filesystem or multi-writer security guarantee. Privileged external filesystem replacement is out of scope. Failed/incomplete resets and quarantined directories may require operator inspection; see
docs/ADMIN_API.md. Sudden power-loss durability on Windows and device-level macOSF_FULLFSYNCare not claimed. Synchronous short filesystem operations under identity coordination avoid cancellation races but can block a Tokio worker on slow filesystems. Logical reopen tests do not substitute for actual SIGKILL/power-loss tests.Validation
cargo fmt --all -- --check,cargo check -p libsql-server --tests --offline,git diff --check: passed.744ca2f75fpassed: both Run Tests jobs, Run Checks, unused-dependency/features check, Windows checks. The first run found a replica-onlyjobstable regression, fixed in this commit; the next run hit aDatabaseBusyfailure in an unchanged concurrent-connection test, passed on retry; a subsequent full rerun passed.libsql_open_v3/sqlite3_*symbols; Linux CI supplies runtime validation.