Volter World

0008: Verify a declared SigV4 payload hash against received bytes

Status: accepted for implementation. Date: 2026-09-30. Work: t_ad153e0a, t_6e361049; first need: c4 t_759d88a5 R2 object uploads.

The current shared verifier reconstructs the canonical request using the caller's declared payload hash. It can therefore validate that signature while receiving different body bytes. A new R2 implementation must store the authenticated bytes, so a pack-local checksum workaround would duplicate a shared signing mechanic.

The kernel verifier compares an ordinary hexadecimal x-amz-content-sha256 with SHA-256 of the supplied exact body bytes and refuses a mismatch before reporting authenticated success. Missing hash uses the computed body hash as before. S3's UNSIGNED-PAYLOAD opt-out remains explicit. Streaming markers are a separate protocol; this change does not establish chunk signature/trailer verification. Packs retain credential authorization, feature selection and the vendor's error response shape.

Source: AWS single-chunk SigV4 and common request headers, read 2026-09-30. AWS distinguishes a hashed payload from its explicit unsigned and streaming forms.

Implementation belongs in packages/world-core/src/sigv4.ts. Construction includes source inspection only; verification of matching and altered byte sequences is deferred to the slate's final checks under the owner's no-mid-build-verification rule. No passed check is claimed by this decision.

View Markdown source