This is the staging instance of ATR, for testing only. The production server is at releases.apache.org.

7.22. File handling

Up: 7. Developer guide

Prev: 7.21. SBOM architecture

Next: (none)

Sections:

Overview

ATR validates release uploads in temporary storage before creating a revision. Archives that need validation stay in quarantine until a worker extracts them successfully. The previous revision remains available while this happens.

Uploads and limits

Route Content Default size limit
Browser upload Release files in a multipart form 512 MiB per request
API release/store One file as the raw request body 512 MiB per request
API release/upload One file, base64 encoded in JSON 512 MiB per request
rsync Files and directory trees Files over 2 GB are skipped
SVN import Files from the committee's dist/dev area No byte limit on the import
OpenPGP key One ASCII armored public key 1 MiB
KEYS file ASCII armored public keys 10 MiB
Admin catalogue import Projects, releases, and artifacts CSV files 512 MiB per request

MAX_CONTENT_LENGTH in config sets the HTTP request limit, enforced by body. Form fields and encoding count towards it, so multipart and base64 uploads have less room for file content. There is no limit on the total size of a release.

ssh sets the rsync limit, and shared.keys defines the key limits. Key imports reject private key material. Keys and catalogue CSV files are parsed separately from release uploads.

Format checks

Release upload paths must satisfy the path rules. Before creating a revision, revision validates the whole proposed tree, including files carried over from the previous revision.

detection rejects symlinks and checks file contents against the extensions below. Empty files, unrecognized contents and format mismatches fail these checks. Files with other extensions are not inspected at this stage.

Expected format Extensions
ZIP .apk, .jar, .nar, .nbm, .vsix, .war, .whl, .zip
gzip .pack.gz, .tar.gz, .tgz
bzip2, xz, tar .tar.bz2, .tar.xz, .tar
Debian, RPM, Windows executable, PDF .deb, .rpm, .exe, .pdf

Archive quarantine

Quarantine applies to .tar.gz, .tgz, .zip, .tar.bz2, .tar.xz, .jar, .war, .apk, .nar, and .whl archives. ATR can reuse validation for identical content previously accepted in the same release with the same suffix, and .tgz and .tar.gz count as one suffix.

If any archive needs validation, the whole proposed revision stays outside download paths while a quarantine worker extracts its archives. archives sets these default extraction limits:

  • 2 GiB per file and per archive, configured by MAX_EXTRACT_SIZE
  • 100,000 files per archive
  • A compression ratio of 100
  • A path depth of 32

Absolute paths and hard links are rejected. Symlinks inside archives must stay within the extraction root.

Once all archives pass validation, the worker creates the revision and starts the release checks. Those checks can block a vote, but the files remain downloadable. An extraction error marks the submission failed and removes the quarantined files. A worker interruption can leave the quarantine pending, which blocks starting a vote. See Resource management for worker limits.

Downloads

Individual files are public, except in embargoed releases, which are hidden from users without access. download serves local files as application/octet-stream attachments. safe.StatePath keeps resolved paths inside managed storage. The frontend proxy must supply X-Content-Type-Options: nosniff, as noted in server. Published downloads redirect to the ASF download services.

Committers can also download an unreleased revision as a ZIP, with no size or file count limit. File previews require a committer login and show the first 512 KiB as escaped text or a hex dump.

ATR does not scan files for malware.