From f93b4a4426acdf706cff2d0e57e54a3e5d72f2e0 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Fri, 2 Oct 2026 09:29:56 +0200 Subject: [PATCH] =?UTF-8?q?docs(arch):=20ADR-0036=20=E2=80=94=20check=20%P?= =?UTF-8?q?DF-=20after=20the=20scan,=20not=20before=20(refs=20#191,=20refs?= =?UTF-8?q?=20#190)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit clamd matches EICAR only at the start of a file, so a type check in front of the scan would report malware as merely not-a-PDF. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/architecture/adr-0036-scan-uploads-with-clamav.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/architecture/adr-0036-scan-uploads-with-clamav.md b/docs/architecture/adr-0036-scan-uploads-with-clamav.md index 62d5f92..90947bc 100644 --- a/docs/architecture/adr-0036-scan-uploads-with-clamav.md +++ b/docs/architecture/adr-0036-scan-uploads-with-clamav.md @@ -33,8 +33,10 @@ and that makes it an ADR (CLAUDE.md ยง14). **no NuGet package** for it (nClam and similar). 4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is stored and the document wait stays open. We never store an unscanned file. -5. **Type check:** content must start with `%PDF-`. This refuses a renamed executable - before the scan, and it costs nothing. +5. **Type check:** content must also start with `%PDF-`, checked **after** the scan. + clamd matches EICAR (and many real signatures) only at the start of a file, so a type + check in front of the scan would report malware as merely "not a PDF". The check also + refuses a renamed non-PDF that is clean. ## Consequences