Add PackFS v0: statically linked in-process VFS implementing concept.md

Implements the core design: a mount table published as an atomically-
swapped snapshot; mem/dir/pack/overlay backends; copy-on-write overlay
with copy-up and whiteout deletion; a checksummed append journal;
compaction with exact-duplicate elimination; single-writer/wait-free-
reader concurrency with a structural/content write split; openat2/
Landlock path containment for dir mounts; and load-time pack integrity
validation. Zero required third-party dependencies.

Sanitizer testing (ASan/UBSan) caught and led to fixing a genuine
heap-use-after-free in the snapshot-reclamation path: the textbook
"load pointer, then increment its refcount" pattern left a gap a
concurrent writer could free through. Closed with a small reclaim_gate
rwlock, documented in internal.h and CLAUDE.md since it's a pattern
every refcounted structure in the codebase now follows.

zip/tar import/export backends, recommended in concept.md Section 11,
will not be built — a permanent project decision recorded in CLAUDE.md
since concept.md itself is frozen and cannot be edited to reflect it.

Includes a runnable demo (examples/demo.c, `make demo`) exercising the
library end to end and proving cross-run persistence through the pack
file, plus open-source scaffolding: MIT license, README, CONTRIBUTING,
and a CI workflow running the test suite under ASan/UBSan/TSan.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UqJpkdJ6Njnt1pw3CbghzB
This commit is contained in:
2026-09-14 05:44:08 +00:00
co-authored by Claude Sonnet 5
commit 72e3c900f2
23 changed files with 4010 additions and 0 deletions
+304
View File
@@ -0,0 +1,304 @@
/*
* pack.c — on-disk pack format (Section 9), load-time integrity
* validation (Section 7), and compaction's writer (Section 4.1, 4.3,
* 5.3, 9.1, 9.2).
*
* On-disk layout (a concrete realization of the illustrative sketch in
* Section 9, extended with the checksum field Section 7 requires):
*
* PackHeader (fixed size, 8-byte aligned)
* blobs (index_offset - sizeof(PackHeader) bytes)
* PackIndexEntry[index_count] at index_offset, sorted by name (9.1)
* strings (each name NUL-terminated) at strings_offset
*/
#include <errno.h>
#include <fcntl.h>
#include <stdlib.h>
#include <string.h>
#include <sys/mman.h>
#include <sys/stat.h>
#include <unistd.h>
#include "internal.h"
#define PACK_VERSION 1
typedef struct PackHeader {
char magic[4];
uint32_t version;
uint64_t index_offset;
uint64_t index_count;
uint64_t strings_offset;
uint64_t strings_len;
uint64_t checksum; /* FNV-1a64 over [index_offset, strings_offset+strings_len) */
} PackHeader;
static uint64_t align8(uint64_t n) { return (n + 7u) & ~(uint64_t)7u; }
/* ---- loading + validation (Section 7) ---- */
void pack_close(Pack *p) {
if (!p) return;
if (p->map && p->map != MAP_FAILED) munmap(p->map, p->map_len);
if (p->fd >= 0) close(p->fd);
free(p->path);
free(p);
}
int pack_load(const char *path, Pack **out, int *err) {
int fd = open(path, O_RDONLY | O_CLOEXEC);
if (fd < 0) { if (err) *err = VFS_ERR_NOENT; return -1; }
struct stat st;
if (fstat(fd, &st) < 0) { close(fd); if (err) *err = VFS_ERR_IO; return -1; }
size_t len = (size_t)st.st_size;
if (len < sizeof(PackHeader)) { close(fd); if (err) *err = VFS_ERR_CORRUPT; return -1; }
void *map = mmap(NULL, len, PROT_READ, MAP_PRIVATE, fd, 0);
if (map == MAP_FAILED) { close(fd); if (err) *err = VFS_ERR_IO; return -1; }
const PackHeader *hdr = (const PackHeader *)map;
if (memcmp(hdr->magic, "PKFS", 4) != 0 || hdr->version != PACK_VERSION) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
/* Bounds-check every offset before trusting it (Section 7): the
* index and strings regions must lie within the file and must not
* overlap the header. */
if (hdr->index_offset < sizeof(PackHeader) ||
hdr->index_offset > len ||
hdr->index_count > (len - hdr->index_offset) / sizeof(PackIndexEntry)) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
uint64_t index_bytes = hdr->index_count * (uint64_t)sizeof(PackIndexEntry);
uint64_t index_end = hdr->index_offset + index_bytes;
if (hdr->strings_offset < index_end || hdr->strings_offset > len ||
hdr->strings_len > len - hdr->strings_offset) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
uint64_t strings_end = hdr->strings_offset + hdr->strings_len;
if (strings_end > len) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
uint64_t checksum = pfs_fnv1a64((const char *)map + hdr->index_offset,
(size_t)(strings_end - hdr->index_offset));
if (checksum != hdr->checksum) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
const PackIndexEntry *entries = (const PackIndexEntry *)((const char *)map + hdr->index_offset);
const char *strings_base = (const char *)map + hdr->strings_offset;
for (uint64_t i = 0; i < hdr->index_count; i++) {
const PackIndexEntry *e = &entries[i];
if (e->data_off < sizeof(PackHeader) || e->data_off > hdr->index_offset ||
e->size > hdr->index_offset - e->data_off) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
if (e->name_off > hdr->strings_len || e->name_len > hdr->strings_len - e->name_off) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
/* Section 9's names are NUL-terminated in the strings region; a
* missing terminator is treated as corruption, not tolerated. */
if (strings_base[e->name_off + e->name_len] != '\0') {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT;
return -1;
}
if (i > 0) {
const PackIndexEntry *prev = &entries[i - 1];
if (strcmp(strings_base + prev->name_off, strings_base + e->name_off) >= 0) {
munmap(map, len); close(fd);
if (err) *err = VFS_ERR_CORRUPT; /* Section 9.1 relies on sortedness */
return -1;
}
}
}
Pack *p = (Pack *)calloc(1, sizeof(Pack));
if (!p) { munmap(map, len); close(fd); if (err) *err = VFS_ERR_NOSPC; return -1; }
p->fd = fd;
p->map = map;
p->map_len = len;
p->entries = entries;
p->entry_count = (size_t)hdr->index_count;
p->strings_base = strings_base;
p->strings_len = (size_t)hdr->strings_len;
p->path = strdup(path);
*out = p;
return 0;
}
const char *pack_entry_name(const Pack *p, const PackIndexEntry *e) {
return p->strings_base + e->name_off;
}
const void *pack_entry_data(const Pack *p, const PackIndexEntry *e) {
return (const char *)p->map + e->data_off;
}
int pack_find(const Pack *p, const char *name, const PackIndexEntry **out) {
size_t lo = 0, hi = p->entry_count;
while (lo < hi) {
size_t mid = lo + (hi - lo) / 2;
int c = strcmp(pack_entry_name(p, &p->entries[mid]), name);
if (c == 0) { *out = &p->entries[mid]; return 1; }
if (c < 0) lo = mid + 1; else hi = mid;
}
return 0;
}
static size_t lower_bound_str(const Pack *p, const char *key) {
size_t lo = 0, hi = p->entry_count;
while (lo < hi) {
size_t mid = lo + (hi - lo) / 2;
if (strcmp(pack_entry_name(p, &p->entries[mid]), key) < 0) lo = mid + 1; else hi = mid;
}
return lo;
}
void pack_range(const Pack *p, const char *prefix, size_t *lo_out, size_t *hi_out) {
size_t lo = lower_bound_str(p, prefix);
size_t plen = strlen(prefix);
char *upper = (char *)malloc(plen + 2);
memcpy(upper, prefix, plen);
upper[plen] = (char)0x7F; /* > any valid path byte, per Section 9.1's argument */
upper[plen + 1] = '\0';
size_t hi = lower_bound_str(p, upper);
free(upper);
*lo_out = lo;
*hi_out = hi;
}
/* ---- writing (compaction target, Section 4.1 / 4.3 / 9.2) ---- */
static int pack_build_entry_cmp(const void *a, const void *b) {
return strcmp(((const PackBuildEntry *)a)->name, ((const PackBuildEntry *)b)->name);
}
typedef struct DedupSlot {
uint64_t hash;
uint64_t size;
uint64_t data_off;
} DedupSlot;
int pack_write(const char *path, const PackBuildEntry *in, size_t count, int *err) {
PackBuildEntry *entries = NULL;
if (count > 0) {
entries = (PackBuildEntry *)malloc(count * sizeof(PackBuildEntry));
if (!entries) { if (err) *err = VFS_ERR_NOSPC; return -1; }
memcpy(entries, in, count * sizeof(PackBuildEntry));
}
qsort(entries, count, sizeof(PackBuildEntry), pack_build_entry_cmp);
/* Pass 1: compute blob region with exact-duplicate elimination
* (Section 9.2) and the strings region size. */
DedupSlot *slots = count ? (DedupSlot *)malloc(count * sizeof(DedupSlot)) : NULL;
size_t slot_count = 0;
uint64_t *data_off_for = count ? (uint64_t *)malloc(count * sizeof(uint64_t)) : NULL;
uint64_t blob_cursor = align8(sizeof(PackHeader));
uint64_t strings_total = 0;
for (size_t i = 0; i < count; i++) {
uint64_t h = pfs_fnv1a64(entries[i].data, (size_t)entries[i].size);
uint64_t reuse = UINT64_MAX;
for (size_t j = 0; j < slot_count; j++) {
if (slots[j].hash == h && slots[j].size == entries[i].size) {
reuse = slots[j].data_off;
break;
}
}
if (reuse != UINT64_MAX) {
data_off_for[i] = reuse;
} else {
data_off_for[i] = blob_cursor;
slots[slot_count].hash = h;
slots[slot_count].size = entries[i].size;
slots[slot_count].data_off = blob_cursor;
slot_count++;
blob_cursor += entries[i].size;
}
strings_total += strlen(entries[i].name) + 1;
}
free(slots);
uint64_t index_offset = align8(blob_cursor);
uint64_t index_bytes = (uint64_t)count * sizeof(PackIndexEntry);
uint64_t strings_offset = index_offset + index_bytes;
uint64_t total_size = strings_offset + strings_total;
unsigned char *buf = (unsigned char *)calloc(1, (size_t)total_size);
if (!buf) { free(entries); free(data_off_for); if (err) *err = VFS_ERR_NOSPC; return -1; }
for (size_t i = 0; i < count; i++) {
/* Deduplicated entries (Section 9.2) share a data_off; writing
* the same bytes to it more than once is redundant but harmless. */
memcpy(buf + data_off_for[i], entries[i].data, entries[i].size);
}
PackIndexEntry *out_entries = (PackIndexEntry *)(buf + index_offset);
uint64_t str_cursor = 0;
for (size_t i = 0; i < count; i++) {
size_t nlen = strlen(entries[i].name);
out_entries[i].name_off = str_cursor;
out_entries[i].name_len = (uint32_t)nlen;
out_entries[i].data_off = data_off_for[i];
out_entries[i].size = entries[i].size;
out_entries[i].mode = entries[i].mode;
out_entries[i].mtime = entries[i].mtime;
memcpy(buf + strings_offset + str_cursor, entries[i].name, nlen + 1);
str_cursor += nlen + 1;
}
PackHeader hdr;
memset(&hdr, 0, sizeof(hdr));
memcpy(hdr.magic, "PKFS", 4);
hdr.version = PACK_VERSION;
hdr.index_offset = index_offset;
hdr.index_count = count;
hdr.strings_offset = strings_offset;
hdr.strings_len = strings_total;
hdr.checksum = pfs_fnv1a64(buf + index_offset, (size_t)(strings_offset + strings_total - index_offset));
memcpy(buf, &hdr, sizeof(hdr));
free(entries);
free(data_off_for);
/* Atomic compaction (Section 4.3): write to a temp file, fsync, then
* rename over the target. A failure here aborts compaction and
* leaves the existing pack untouched. */
char tmp_path[PFS_PATH_MAX];
snprintf(tmp_path, sizeof(tmp_path), "%s.tmp", path);
int fd = open(tmp_path, O_WRONLY | O_CREAT | O_TRUNC, 0644);
if (fd < 0) { free(buf); if (err) *err = VFS_ERR_IO; return -1; }
size_t written = 0;
while (written < (size_t)total_size) {
ssize_t w = write(fd, buf + written, (size_t)total_size - written);
if (w < 0) { close(fd); free(buf); unlink(tmp_path); if (err) *err = VFS_ERR_IO; return -1; }
written += (size_t)w;
}
free(buf);
if (fsync(fd) < 0) { close(fd); unlink(tmp_path); if (err) *err = VFS_ERR_IO; return -1; }
close(fd);
if (rename(tmp_path, path) < 0) { unlink(tmp_path); if (err) *err = VFS_ERR_IO; return -1; }
return 0;
}