docs(arch): ADR-0036 — check %PDF- after the scan, not before (refs #191, refs #190)
CI / lint (pull_request) Successful in 2m0s
CI / k8s (pull_request) Successful in 10s
CI / build (pull_request) Successful in 1m14s
CI / unit (pull_request) Successful in 1m18s
CI / docs (pull_request) Successful in 43s
CI / frontend (pull_request) Successful in 2m22s
CI / mutation (pull_request) Successful in 4m57s
CI / verify-stack (pull_request) Skipped

clamd matches EICAR only at the start of a file, so a type check in front of
the scan would report malware as merely not-a-PDF.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:29:56 +02:00
co-authored by Claude Opus 5.5
parent d698267fba
commit f93b4a4426
@@ -33,8 +33,10 @@ and that makes it an ADR (CLAUDE.md §14).
**no NuGet package** for it (nClam and similar). **no NuGet package** for it (nClam and similar).
4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is 4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is
stored and the document wait stays open. We never store an unscanned file. stored and the document wait stays open. We never store an unscanned file.
5. **Type check:** content must start with `%PDF-`. This refuses a renamed executable 5. **Type check:** content must also start with `%PDF-`, checked **after** the scan.
before the scan, and it costs nothing. clamd matches EICAR (and many real signatures) only at the start of a file, so a type
check in front of the scan would report malware as merely "not a PDF". The check also
refuses a renamed non-PDF that is clean.
## Consequences ## Consequences