- **The alias is a selector and the guards are allow-lists.** `credentials_alias` names a binding an operator provisioned on *this host* (`src/worker/aliases.py`, from `REPLICATOR_REPLICATION_ALIASES_FILE`); unset means nothing is provisioned and everything is refused, which is the current state of every host and the safe default under T5. Guard order is load-bearing and asserted: alias → provider → the alias's own writer → destination → source, so every refusal happens **before any credential is touched** (T1) — observable for the first time now that there is a driver call to precede. **The writers are keyed by alias, not by provider** (CR #26): `AsyncGcsDriver` takes a bucket in its constructor and never sees another, so a driver *is* a bucket and the key has to be whatever selects one — keyed by provider, two `gcs` bindings collapsed onto a single driver and a command could land in a bucket its binding never named, outside the very T3 root `validate_destination` had just checked. A binding whose driver cannot be built (ADC resolves in that constructor) is **skipped and logged, never raised**, because `load_alias_table` promises one line earlier that a replicate misconfiguration will not take down a worker whose actual job is `content.fetch`; the alias is then refused `provider_disabled`, whose remedy is the operator act that fixes it. The blob reaches the driver as a **seekable binary stream** from `BlobStore.open_stream`, not as bytes or a path: a path would make the provider copy something already on disk, bytes would pull a whole artifact into memory, and seekable is required because the driver reads the local md5 only on the 412 path, after the failed create has moved the position. **`blob_uri` is never resolved as a path** — the fingerprint is extracted, validated as 64 lowercase hex, and compared against `uri_for()` of each store this host reads — the temp store, and since #114 the permanent store if `REPLICATOR_PERMANENT_BUCKET` names one — so the only string reaching storage is one a store built, and the bytes come from the store that matched. That is T3a, and it is sharper than the destination guard it was added beside: `file:///etc/replicator/co-pypi-reader.json` as a `blob_uri` would otherwise publish this host's GCS reader key to a permanent, public, undeletable store. `invalid_source` and `blob_expired` stay distinct because only the second is fixed by fetching again. Two charter invariants enforce the rest: the alias is a key and never a value, and no payload field feeds a credential-shaped parameter.
0 commit comments