0008: Verify a declared SigV4 payload hash against received bytes
Status: accepted for implementation. Date: 2026-09-30. Work: t_ad153e0a, t_6e361049; first need: c4 t_759d88a5 R2 object uploads.
The current shared verifier reconstructs the canonical request using the caller's declared payload hash. It can therefore validate that signature while receiving different body bytes. A new R2 implementation must store the authenticated bytes, so a pack-local checksum workaround would duplicate a shared signing mechanic.
The kernel verifier compares an ordinary hexadecimal x-amz-content-sha256 with SHA-256 of the supplied exact
body bytes and refuses a mismatch before reporting authenticated success. Missing hash uses the computed body
hash as before. S3's UNSIGNED-PAYLOAD opt-out remains explicit. Streaming markers are a separate protocol;
this change does not establish chunk signature/trailer verification. Packs retain credential authorization,
feature selection and the vendor's error response shape.
Source: AWS single-chunk SigV4 and common request headers, read 2026-09-30. AWS distinguishes a hashed payload from its explicit unsigned and streaming forms.
Implementation belongs in packages/world-core/src/sigv4.ts. Construction includes source inspection only;
verification of matching and altered byte sequences is deferred to the slate's final checks under the owner's
no-mid-build-verification rule. No passed check is claimed by this decision.