File Upload & Scanning Pipeline  ·  View 15 of 21  ·  Runtime

Back-Pressure — Which Promise Breaks First

Four load bands, three lanes, and the one invariant that is never traded.

Editable source SVG draw.io All views
Normal Elevated Saturated Critical Trigger (oldest unscanned) 1–2× target 2–5× target > 5× target Interactive lane Admit, p95 8 s Admit, unchanged Admit, widened target published Reject at initiate, retry hint Background lane Admit, 5× target Admit, target widened Throttle per tenant Reject at initiate Bulk lane Admit, 24 h target Reject new initiations Rejected Rejected Never done Admit what cannot be scanned Degrade to signature-only silently Serve an unscanned object Queue without bound What stays true Bytes already accepted are kept Verdict still recorded for every object No object reaches a reader uncleared Ingest of accepted sessions continues Back-Pressure — Which Promise Breaks, In What Order Red is refusal, green is the invariant. The bottom two rows are the point of the view: the shedding order is published in advance, and the one promise never traded is that nothing reaches a reader without a verdict. v 1.0 · order bulk, then background, then interactive

The invariant

  • Nothing reaches a reader without a current verdict. That holds in every column, including Critical, and it is the only promise with no degraded mode.
  • Bytes already accepted are always kept: the platform never discards an upload it acknowledged, however deep the backlog
  • Every object still gets a verdict recorded — shedding changes what is admitted, never what is forgotten

Decisions

  • The shedding order is published in advance, lane by lane: bulk refuses first, then background throttles, then interactive is rejected at initiation
  • Widening a published verdict target is a declared degradation with a number, not a silent slide — the response says what the target now is
  • Rejection happens at initiation, where it costs the client nothing, and never after bytes have been transferred

What is never done

  • Admitting bytes the platform has already decided it cannot scan within the declared target
  • Degrading to signature-only scanning without saying so, which trades detection strength exactly when an attacker would want it traded
  • Queueing without bound, which converts a capacity problem into an unbounded liability