Lumen
Security

Verify artifacts

Promote hostile uploads only after trusted streaming validation and tenant-scoped create-only storage.

Outcome

An artifact becomes canonical only after trusted verification computes its digest and commits one tenant-scoped immutable manifest.

Prerequisites

Separate staging upload authority from finalization authority. Define maximum size, accepted media and magic types, archive/symlink policy, malware policy, retention class, and tenant/project ownership.

Steps

  1. Mint a random, one-use, short-lived staging upload target.
  2. Stream the uploaded object through size, digest, media, magic, ownership, and content-policy checks.
  3. Compute the canonical digest in the trusted finalizer.
  4. Conditionally promote to the workspace/project content-addressed namespace without overwrite.
  5. Commit manifest, lineage, retention, and event only after promotion succeeds.
  6. Quarantine invalid bytes and reconcile ambiguous finalization by the deterministic operation ID.

Both canonical adapters implement this boundary. The filesystem adapter uses private staging, descriptor-based path checks, bounded streaming, digest verification, and create-only promotion. The R2 adapter separates staging and canonical buckets and keeps app staging/read credentials distinct from worker finalization credentials. Selecting r2 requires the complete explicit configuration; filesystem mode rejects stray R2 credentials.

Verify

Test overwrite, mismatch, partial upload, duplicate finalization, collision, symlink/archive abuse, cross-tenant deduplication, and a lost finalize response. Every valid retry yields one manifest.

For an exact workspace, run the bounded consistency scanner from a trusted worker environment:

scripts/verify-artifact-consistency --workspace-id wsp_0123456789abcdef0123456789abcdef

The command reads worker database and object-store configuration only from its explicit process environment. It streams every referenced object through digest and size verification, returns a redacted JSON report, exits 0 only when the scan completes with no defect, and never repairs bytes or manifests. In local filesystem mode only, --repair-filesystem-permissions may restrict existing manifest-owned workspace/project directories to 0700 before the same scan; it does not create or delete paths and is not available for R2.

Recover

If bytes and database diverge, mark affected evidence unavailable, stop promotion, run the consistency scanner, and restore or re-upload only from a verified source. Do not edit a digest to match bad bytes.

Next task

Review the local gateway boundary.

On this page