Repository navigation
omnifs v0.2.0-dev.0
Pre-release
Pre-release
Added
- omnifs is now distributed on npm as
@0xff-ai/omnifs. Install withnpm install -g @0xff-ai/omnifs; the CLI binary ships in one of four platform-specific optional-dependency packages (darwin-arm64,darwin-x64,linux-arm64,linux-x64). The Docker image is pulled onomnifs up, not at install time. - Full
omnifs init <provider>/omnifs up/omnifs downmount lifecycle.omnifs initwalks through provider auth (device-code or PKCE loopback OAuth), writes a per-mount config under~/.omnifs/config/mounts/, and stores credentials in the OS keychain (macOS Keychain, Linux libsecret, Windows DPAPI) with a mode-600 file fallback at~/.omnifs/data/credentials.json.omnifs uppulls the matching runtime image, materialises credentials into a private session directory bind-mounted read-only into the container, then removes the session on stop or failure. omnifs authsubcommands:login,logout,status,refresh,scopes,import. OAuth refresh happens automatically with a one-shot 401 retry coordinated by a singleflight plus a cross-process file lock so concurrent CLI invocations do not race on the same refresh token.omnifs setupguided first-run walkthrough: detects OS and Docker, helps pick providers, runsinitfor each, and brings the container up.omnifs doctorruns ten ordered probes to diagnose why a mount is not working (Docker availability, FUSE timeout, missing credentials, etc.).omnifs resetclears configs and credentials after an explicit confirmation prompt.omnifs mounts ls/omnifs mounts rmfor listing and removing configured mounts.omnifs statusreadiness card showing runtime state, configured mounts, and auth state.omnifs versionandomnifs completionscommands.omnifs devcontributor sandbox: walks up from cwd to find the workspaceCargo.toml, capturesgh auth token, downloads the Chinook SQLite fixture into.secrets/db/test.db, builds anomnifs:<short-sha>-devimage, and starts a container with all built-in providers mounted. Replaces the oldjust dev/docker compose upworkflow.- Three supported OAuth flows in the new
omnifs-authcrate: PKCE loopback (browser-redirect), PKCE manual code (paste-back), and device code (visit URL, type short code). GitHub uses device code with no default write scopes; Linear uses PKCE loopback with thereadscope. - Host-managed provider credentials: providers never see tokens; the host attaches them to outgoing HTTP requests after callouts cross the WASM boundary. Provider auth needs are declared in
omnifs.provider.json(OAuth endpoints, scopes, injection header, allowed domains); adding a new service does not require patching the host. omnifs-credscrate for the keychain + file + in-memory credential store, withCredentialKey::storage_key()(provider:scheme:account) as the public wire form. Stale file-fallback entries are cleaned up after successful keyring writes; durability and permissions are hardened.- Database provider (
omnifs-provider-db) mounted at/db, projecting a read-only SQLite database as a filesystem. Exposesmeta/{version.txt,path.txt,info.json}andtables/{name}/{schema.sql,schema.json,indexes.json,count.txt,sample.json}. SQLite runs inside the WASM sandbox viarusqlitewith the bundled feature; the host preopens the database file's parent directory through Wasmtime's WASI context with read-only permissions so no bytes cross the WIT boundary. v1 is SQLite-only and read-only. - Docker provider (
omnifs-provider-docker) mounted at/docker, projecting the local Docker daemon over the Unix socket. Exposes/system/{info,version,df}.json,/system/ping,/containers/_listing.json, facets{by-name,by-id,_running,_stopped}each binding to a per-container subtree (inspect.json,summary.json,summary.txt,state), and/compose/{project}/services/{service}/containers/{name}grouping by Compose labels. Container state files are marked volatile so reads bypass the kernel page cache and always reach the provider. Bounded-window/eventspolling translates container actions into cache-invalidation prefixes. - Unix-socket HTTP transport in the host. Providers use
HttpEndpoint::Unixandbuild_url(path, query); the host detectsunix:URLs, decodes the hex-encoded socket path, builds a per-socketreqwest::ClientviaClientBuilder::unix_socket, and rewrites the URL for that client. Unix sockets are gated by a newunix-socketsallowlist onCapabilityGrants. - Linear provider (
omnifs-provider-linear) mounted at/linear, projecting a Linear workspace. Teams appear at/linear/teams/{KEY}, issues at/linear/teams/{KEY}/issues/{_open,_all}/{IDENT}/. Each issue surface hastitle,state,priority,assignee, anddescription.mdas files. Issue listings preload child files so acatafterlsskips a follow-up round trip. Uses Linear's GraphQL API with hand-written query strings and serde response structs (Linear's endpoint rejects full introspection queries as too complex, ruling out code generation). - arXiv provider now also exposes a recent-submissions surface per category:
/categories/{cat}/recent,/categories/{cat}/recent/_fetched,/categories/{cat}/recent/pages/{n}, and/categories/{cat}/submissions/{YYYYMMDD}directories discovered from fetched pages. Direct paper lookup at/papers/{id}is unchanged. - Projected file attributes: providers now declare
Size(Exact,NonZero, orUnknown),Bytes(inline or deferred),ReadMode, andStability(Immutable,Mutable, orVolatile) through theProjectionAPI. The host uses these facts to setst_size, FUSE direct-I/O flags, cache behavior, ranged-read handling, and post-read size promotion. The old 256 MiB placeholder is removed. Volatile files returnentry_timeout = 0,attr_timeout = 0, andFOPEN_DIRECT_IO; ranged files open a provider handle for snapshot-consistent reads. - Sandboxed archive extraction via a host-owned
omnifs-tool-archiveWasm component.BlobExecutorstreamsfetch-blobresponses into a staged temp file and commits metadata before the body is visible;ArchiveExecutorkeys extracted trees by(cache-key, format, strip-prefix)and coalesces concurrent extractions throughTreeMaterializer. The extractor runs path sanitization, depth/length/entry-count/per-file/total-byte limits inside the sandbox and publishes completed trees via atomic directory rename so tree refs never observe partial output. EffectiveConfigtype representing a mount after provider metadata has been merged in.ProviderCatalog::load_mount()returns one; credential targeting, session materialisation, and runtime construction all consume it. The previousInstanceConfig-plus-late-apply_metadatapattern is removed.- Provider runtime capabilities now come back from
initas(State, ProviderInfo, RequestedCapabilities)instead of a separate WIT export. Initialisation runs exactly once inProviderRuntime::new. Capability entries can be markeddynamic: truewhen the concrete grant depends on mount config (Docker's socket path is the motivating case). omnifs-mount-schemacrate is split into typed modules with a checked-in JSON schema atcrates/omnifs-mount-schema/schema/omnifs.provider.schema.json(regenerate withjust regen-schema).- Per-crate README files for all published crates.
Changed
- arXiv provider route model is restructured around recent submissions. The calendar/date-query,
new,updated,by-author,/authors, and/searchsurfaces are removed. Category traversal now goes through/categories/{category}/recentand/categories/{category}/submissions/{YYYYMMDD}; direct paper lookup at/papers/{paper}is unchanged. The only live category listing query shape issearch_query=cat:{category}sorted bysubmittedDatedescending. - Provider protocol vocabulary is reorganized into three orthogonal channels:
callout(intermediate host work the provider suspends on),return(the completed operation answer), andeffect(host-side mutation committed at the return boundary).provider-responseis renamed toprovider-stepwith armssuspended(callouts)andreturned(provider-return). A return cannot carry callouts; an error return cannot carry effects. - Dead git callouts (
git-list-tree,git-read-blob,git-head-ref,git-list-cached-repos) and the unusedreconcileinterface are removed from the WIT. - The
sidecar::materializemethod is folded intolookup-childandlist-childrenvia#[subtree]dispatch from the SDK. - Host runtime module
crates/host/src/runtime/mod.rsis split into focused modules:instance.rs(Wasmtime mechanics),callouts.rs(dispatch and tracing),effects.rs(terminal mutations andProjectionAccumulator),log_redaction.rs,wit_conversions.rs,op.rs(theOpenum andValidator), andhttp_stack.rs(shared HTTP transport).RuntimeErrorconstruction errors split intoRuntimeBuildError. - Browse cache re-skin enums collapse into their WIT counterparts;
cache::SCHEMA_VERSIONbumps to 5, invalidating existing L2 records. - CLI flows are redesigned around mount configs, provider metadata, credential materialisation, and container lifecycle commands. Verbose output is off by default;
-venables INFO logs and-vvadds DEBUG. Common errors surface aTry:block with a concrete next step. - Provider manifests (
omnifs.provider.json) describe auth schemes, token injection policy, capability grants, and config schema. All built-in providers (arxiv,db,dns,docker,github,linear,test) carry anomnifs.provider.jsonand drop vestigial[package.metadata.component]Cargo sections. - Docker Compose development entrypoints (
compose.yaml,just dev) are replaced by the supportedomnifs dev,omnifs shell,omnifs logs, andomnifs downworkflow. - Wasm providers are baked into the runtime image at
/root/.omnifs/providers/withOMNIFS_PROVIDERS_DIRset so the daemon finds them without an entrypoint flag.
Fixed
- Large file content (PR diffs, arXiv papers over the 512 KiB
MAX_EAGER_RESPONSE_BYTEScap) no longer returns EIO. The GitHub and arXiv providers route oversized reads throughfetch-blobso bytes stay host-side; the SDK gainsFileContent::BlobandFileContent::BlobWithAttrsvariants for blob-backed file content. cd /github/<owner>followed bylsno longer re-fetches the listing. The SDK'sprojection_exact_lookupwas marking dirents non-exhaustive even when the handler returnedPageStatus::Exhaustive; a newlisting-exhaustiveflag onproj-entrypropagates the exhaustive bit into the host's projection accumulator.lookup_childinto a bind site now dispatches correctly whenparent_pathequals the bind template exactly (not just when it is a strict ancestor). Previously the lookup fell through to the no-handler branch and returnedNotFound.projection_exact_lookupwas packing the looked-up target's children intolookup-entry.siblingsinstead of the target's actual siblings. The host was caching the listing under the wrong key. The SDK now populatessiblingswith the target's siblings computed from the parent's static children, with the exhaustive bit derived fromStaticChildren::parent_has_dynamic_children.- Synchronous FUSE invalidation is removed from the provider callout path, eliminating hangs when reading GitHub projected files such as issue bodies.
- DNS and other unknown-size full-read files now return complete content through
cat,head, and similar tools instead of appearing empty because the kernel saw a zero or one byte sentinel before provider content was materialised. - Credential persistence no longer leaves stale file-fallback entries after keyring writes; file-store durability and permissions are hardened.
- Host credential-store setup now logs when keyring access falls back to the file store.
sdk-macrosdev-dependency onomnifs-sdkno longer carries a redundant version specifier, fixing workspace version resolution.