Skip to content

feat(envd): reject watching paths on network filesystems - #1810

Merged
mishushakov merged 9 commits into
mainfrom
mishushakov/envd-watch-mount-err
Jan 29, 2026
Merged

mishushakov merged 9 commits into
mainfrom
mishushakov/envd-watch-mount-err

Conversation

@mishushakov

@mishushakov mishushakov commented Jan 29, 2026 •

Copy link
Copy Markdown
Member

Summary

Prevent envd from watching files on network filesystem mounts (NFS, CIFS, SMB, FUSE) by detecting the filesystem type via statfs and returning a FailedPrecondition error to clients before attempting to create a watcher.

Changes

  • Added IsPathOnNetworkMount() utility function using syscall.Statfs
  • Added network mount checks in both streaming (WatchDir) and non-streaming (CreateWatcher) watch endpoints
  • Added test coverage for the new utility function

Test Plan

  • Filesystem watch tests pass on local system
  • New test verifies non-network directories are allowed

🤖 Generated with Claude Code


Note

Medium Risk
Changes request validation for watcher creation and can reject paths that were previously allowed, potentially impacting clients relying on watching network-mounted directories; also adds a CI dependency on FUSE tooling.

Overview
envd now blocks directory watch creation when the target path resides on a network-backed filesystem (NFS/CIFS/SMB/FUSE), by adding IsPathOnNetworkMount() (via statfs) and applying the check in both streaming (WatchDir) and non-streaming (CreateWatcher) watch endpoints.

Adds unit tests including a FUSE-based case using bindfs, and updates the PR test workflow to install bindfs for packages/envd so the new test can run in CI.

Written by Cursor Bugbot for commit f17e5b9. This will update automatically on new commits. Configure here.

Prevent file watching on NFS, CIFS, SMB, and FUSE mounts by detecting
the filesystem type via statfs. Returns FailedPrecondition error to clients.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Comment thread packages/envd/internal/services/filesystem/utils.go Outdated
Comment thread packages/envd/internal/services/filesystem/watch.go Outdated
Comment thread packages/envd/internal/services/filesystem/watch.go
Comment thread packages/envd/internal/services/filesystem/utils_test.go

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6d8c0ab3ee

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/envd/internal/services/filesystem/utils.go Outdated
Extract IsNetworkFilesystemType helper and add table-driven tests
verifying all supported magic numbers (NFS, CIFS, SMB, SMB2, FUSE)
and common non-network filesystems (ext4, tmpfs, overlay, xfs).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

Comment thread packages/envd/internal/services/filesystem/utils.go Outdated
mishushakov and others added 2 commits January 29, 2026 19:12
Replace unit tests with an integration test that creates an actual
FUSE mount using bindfs to verify network filesystem detection works
correctly. Test skips if bindfs/fusermount are not available.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Use exec.CommandContext instead of exec.Command and add t.Parallel().

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Comment thread packages/envd/internal/services/filesystem/utils_test.go Outdated
- Add setup step to install bindfs in CI for envd tests
- Change test to fail instead of skip if dependencies missing

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Comment thread .github/workflows/pr-tests.yml
Comment thread packages/envd/internal/services/filesystem/watch.go Outdated
mishushakov and others added 3 commits January 29, 2026 19:58
- Change error code from FailedPrecondition to InvalidArgument
- Remove bindfs setup step from CI (test skips if not available)
- Revert test to skip instead of fail when bindfs missing

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@mishushakov
mishushakov enabled auto-merge (squash) January 29, 2026 19:04
@mishushakov
mishushakov merged commit 50fd95d into main Jan 29, 2026
29 checks passed
@mishushakov
mishushakov deleted the mishushakov/envd-watch-mount-err branch January 29, 2026 19:12
mishushakov added a commit that referenced this pull request Jun 12, 2026
## Summary

- Adds an `allow_network_mounts` field to `WatchDirRequest` and
`CreateWatcherRequest` so clients can explicitly opt into watching paths
on network filesystem mounts (NFS, CIFS, SMB, FUSE), which are rejected
by default since #1810.
- The streaming (`WatchDir`) and non-streaming (`CreateWatcher`)
handlers skip the network-mount rejection when the flag is set; default
behavior is unchanged.
- Regenerates the filesystem proto code in envd and shared, and bumps
envd to 0.6.4.

## Test Plan

- Added `TestCreateWatcherOnNetworkMount` (bindfs FUSE mount,
Linux-only) verifying the watcher is rejected without the flag and
created with it; existing filesystem watch tests pass.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants