Verify artifacts
Promote hostile uploads only after trusted streaming validation and tenant-scoped create-only storage.
Outcome
An artifact becomes canonical only after trusted verification computes its digest and commits one tenant-scoped immutable manifest.
Prerequisites
Separate staging upload authority from finalization authority. Define maximum size, accepted media and magic types, archive/symlink policy, malware policy, retention class, and tenant/project ownership.
Steps
- Mint a random, one-use, short-lived staging upload target.
- Stream the uploaded object through size, digest, media, magic, ownership, and content-policy checks.
- Compute the canonical digest in the trusted finalizer.
- Conditionally promote to the workspace/project content-addressed namespace without overwrite.
- Commit manifest, lineage, retention, and event only after promotion succeeds.
- Quarantine invalid bytes and reconcile ambiguous finalization by the deterministic operation ID.
Both canonical adapters implement this boundary. The filesystem adapter uses private staging,
descriptor-based path checks, bounded streaming, digest verification, and create-only promotion. The
R2 adapter separates staging and canonical buckets and keeps app staging/read credentials distinct
from worker finalization credentials. Selecting r2 requires the complete explicit configuration;
filesystem mode rejects stray R2 credentials.
Verify
Test overwrite, mismatch, partial upload, duplicate finalization, collision, symlink/archive abuse, cross-tenant deduplication, and a lost finalize response. Every valid retry yields one manifest.
For an exact workspace, run the bounded consistency scanner from a trusted worker environment:
scripts/verify-artifact-consistency --workspace-id wsp_0123456789abcdef0123456789abcdefThe command reads worker database and object-store configuration only from its explicit process
environment. It streams every referenced object through digest and size verification, returns a
redacted JSON report, exits 0 only when the scan completes with no defect, and never repairs bytes
or manifests. In local filesystem mode only, --repair-filesystem-permissions may restrict existing
manifest-owned workspace/project directories to 0700 before the same scan; it does not create or
delete paths and is not available for R2.
Recover
If bytes and database diverge, mark affected evidence unavailable, stop promotion, run the consistency scanner, and restore or re-upload only from a verified source. Do not edit a digest to match bad bytes.