File Upload & Scanning Pipeline · View 14 of 21 · Runtime
What the blanks say
- A deduplicated object is never fetched and never unpacked: the 35% hash-hit rate is the single largest cost lever in the design, and it spends nothing but an index lookup
- The poison path never reaches a composition rule — it reaches a dead letter and a human, because a crashed engine has produced no opinion to compose
- Small objects need no unpack stage at all, which is why the median cost of the platform is set by the fast engine and not the slow one
Decisions
- Three execution profiles by size, not one sized for the worst case: a 50 KB screenshot and a 50 GB archive share an API, not a worker shape
- Archive expansion is bounded at depth 12 and a 200× expanded-size ratio; a breach is indeterminate naming the bound, and the object goes to a human within 24 hours
- Any infected member of an archive makes the archive infected — the composition rule resolves to the safest available outcome, never the most convenient
Open
- Whether large objects are scanned streamed or assembled is Question 5, and it is not settled here: this view shows assembly, which is the conservative choice
- How many engines, and the trigger that escalates to the deep engine, is Question 4 — the view assumes fast-always, deep-conditional