1.1 KiB
1.1 KiB
ADDED Requirements
Requirement: Active Run update jobs can read approved artifact ranges
The artifact channel SHALL provide a signed, bounded, resumable read contract exclusively for an active fenced run.self-update attempt whose artifact is an available same-server target-matched Run distribution.
Scenario: Run reads the next update range
- WHEN Run presents the selected endpoint/session/job/attempt/lease and a valid offset and length
- THEN Platform MUST return only that bounded artifact range plus artifact ID, offset, total size, checksum, and completion metadata
Scenario: Run requests unrelated artifact data
- WHEN the job is inactive, the artifact/distribution/server/endpoint/target differs, or the range exceeds bounds
- THEN Platform MUST reject the request without returning bytes, paths, credentials, browser download sessions, secret refs, or cross-owner metadata
Scenario: Update transfer is slow
- WHEN an update range read or network response is blocked
- THEN control, job ack/result/cancel, log ingest, and independent artifact upload routes MUST continue without waiting on the read