Table of Contents

Class AntivirusScanService

Namespace
Archiver.Core.Services
Assembly
Archiver.Core.dll

T-F146. Scans an archive's expanded contents for threats via AMSI — deliberately not an extension of IArchiveService/ITarService (see docs/DECISIONS.md's T-F146 entry): this never writes anything to a real destination, has no conflict/MOTW dimension, and adding a method to those interfaces would ripple through every hand-rolled test fake in the repo for a capability that isn't a variant of extraction. Never throws — every failure becomes an Inconclusive ThreatFinding.

public sealed class AntivirusScanService : IAntivirusScanService
Inheritance
AntivirusScanService
Implements
Inherited Members

Remarks

T-F146. Two independent scan paths, dispatched by ArchiveFormatPolicy.Classify (shared with ExtractionRouter so policy gating can never drift between "extract" and "scan"):

  • ZIP: in-process, no disk writes — reads each entry's bytes directly from the trusted System.IO.Compression reader into a rented buffer.
  • tar-family: reuses TarSandboxScope/T-F49's whole-archive pre-scan and extracts into the quarantine "out\" directory exactly as a real Extract would, but STOPS there — no move-to-destination phase ever runs, and the quarantine is always deleted (scope.Dispose()).

Never throws to callers — every failure (unsupported/blocked format, no AMSI provider registered, an unreadable/oversized entry, a rejected/unsandboxable tar archive) becomes an Inconclusive finding, never silently dropped and never rendered as Clean.

Constructors

AntivirusScanService(TarCapabilities, GroupPolicyOptions)

Creates a scanner wired to the real AMSI provider.

public AntivirusScanService(TarCapabilities tarCapabilities, GroupPolicyOptions groupPolicyOptions)

Parameters

tarCapabilities TarCapabilities
groupPolicyOptions GroupPolicyOptions

Methods

ScanAsync(AntivirusScanOptions, IProgress<ProgressReport>?, CancellationToken)

Scans one or more archives via AMSI. Never throws — a scan failure (no AV provider, a per-entry read error) becomes an Inconclusive ThreatFinding instead.

public Task<ThreatScanResult> ScanAsync(AntivirusScanOptions options, IProgress<ProgressReport>? progress = null, CancellationToken cancellationToken = default)

Parameters

options AntivirusScanOptions
progress IProgress<ProgressReport>
cancellationToken CancellationToken

Returns

Task<ThreatScanResult>