Class AntivirusScanService
- Namespace
- Archiver.Core.Services
- Assembly
- Archiver.Core.dll
T-F146. Scans an archive's expanded contents for threats via AMSI — deliberately not an extension of IArchiveService/ITarService (see docs/DECISIONS.md's T-F146 entry): this never writes anything to a real destination, has no conflict/MOTW dimension, and adding a method to those interfaces would ripple through every hand-rolled test fake in the repo for a capability that isn't a variant of extraction. Never throws — every failure becomes an Inconclusive ThreatFinding.
public sealed class AntivirusScanService : IAntivirusScanService
- Inheritance
-
AntivirusScanService
- Implements
- Inherited Members
Remarks
T-F146. Two independent scan paths, dispatched by ArchiveFormatPolicy.Classify (shared with ExtractionRouter so policy gating can never drift between "extract" and "scan"):
- ZIP: in-process, no disk writes — reads each entry's bytes directly from the trusted System.IO.Compression reader into a rented buffer.
- tar-family: reuses TarSandboxScope/T-F49's whole-archive pre-scan and extracts into the quarantine "out\" directory exactly as a real Extract would, but STOPS there — no move-to-destination phase ever runs, and the quarantine is always deleted (scope.Dispose()).
Never throws to callers — every failure (unsupported/blocked format, no AMSI provider registered, an unreadable/oversized entry, a rejected/unsandboxable tar archive) becomes an Inconclusive finding, never silently dropped and never rendered as Clean.
Constructors
AntivirusScanService(TarCapabilities, GroupPolicyOptions)
Creates a scanner wired to the real AMSI provider.
public AntivirusScanService(TarCapabilities tarCapabilities, GroupPolicyOptions groupPolicyOptions)
Parameters
tarCapabilitiesTarCapabilitiesgroupPolicyOptionsGroupPolicyOptions
Methods
ScanAsync(AntivirusScanOptions, IProgress<ProgressReport>?, CancellationToken)
Scans one or more archives via AMSI. Never throws — a scan failure (no AV provider, a per-entry read error) becomes an Inconclusive ThreatFinding instead.
public Task<ThreatScanResult> ScanAsync(AntivirusScanOptions options, IProgress<ProgressReport>? progress = null, CancellationToken cancellationToken = default)
Parameters
optionsAntivirusScanOptionsprogressIProgress<ProgressReport>cancellationTokenCancellationToken