diff --git a/docs/architecture/adr-0036-scan-uploads-with-clamav.md b/docs/architecture/adr-0036-scan-uploads-with-clamav.md index 62d5f92..90947bc 100644 --- a/docs/architecture/adr-0036-scan-uploads-with-clamav.md +++ b/docs/architecture/adr-0036-scan-uploads-with-clamav.md @@ -33,8 +33,10 @@ and that makes it an ADR (CLAUDE.md ยง14). **no NuGet package** for it (nClam and similar). 4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is stored and the document wait stays open. We never store an unscanned file. -5. **Type check:** content must start with `%PDF-`. This refuses a renamed executable - before the scan, and it costs nothing. +5. **Type check:** content must also start with `%PDF-`, checked **after** the scan. + clamd matches EICAR (and many real signatures) only at the start of a file, so a type + check in front of the scan would report malware as merely "not a PDF". The check also + refuses a renamed non-PDF that is clean. ## Consequences