1.6 KiB
M12-04E Status
status: done task: archive first reads the central directory or manifest before payload extraction updated: 2026-08-18 America/New_York enablingTask: false parityStateChange: false
Scope
ZIP requests produce a bounded CENTRAL_DIRECTORY first-read plan; TAR requests produce a bounded
MANIFEST first-read plan. The plan contains no payload ranges. A read trace is accepted only when
the first exact range is the declared metadata range and every later range is payload; payload-first,
wrong-range, duplicate-metadata, out-of-order, oversized, and out-of-archive reads fail closed with
IO_ARCHIVE_UNSAFE.
Evidence
npm --prefix web run test:library-metadata-firstpassed 4/4 unit tests.- ZIP and TAR plans expose metadata-only first reads with an empty payload plan.
- Payload-first, wrong-range, duplicate metadata, out-of-archive, and metadata-budget cases are rejected before extraction can be scheduled.
Artifact Hashes
- parent manifest:
1c09abd1f4bd5908d22ab3b22e3e71d050f694af0b82a7f78a351d7a1bf1e664 - protocol:
869586b041e134c7d1cb2ebd7e13b35218b337223d401697a179f71cd1420f5b - unit:
2da649722acee9cace8db6f337b4a93500a9c775a0b0f086bf38dd2b3e7f9e91 - package commands:
cfb232baa494ff59f6c8d65514a08c86332ee9354350b2a0392b6f932a7ee42c
Next Task
M12-04F: enforce per-entry bytes, total bytes, entry count, directory depth, and filename length budgets.
Rollback
Remove the metadata-first protocol, unit suite, manifest, package command, and this status entry. Restore
M12-04D to pending and move the machine queue back to M12-04E. No parity ledger rollback is required.