# 0009: Shared S3 upload checksum bytes

Status: accepted for implementation. Date: 2026-09-30.
Work: t_ad153e0a, c30; first need: c4 t_759d88a5.

S3-compatible uploads can provide a checksum before storing the bytes. The kernel has signing and hash helpers,
but no shared CRC wire calculation; a pack-local CRC would duplicate a protocol mechanic. The S3 namespace owns
base64 digests for MD5, SHA1, SHA256, CRC32, CRC32C and CRC64NVME. CRC bytes are network-order, with reflected
polynomials and the algorithm's initial/final complement. Byte concatenation is also shared for multipart assembly.

The vendor pack owns supported algorithms, checksum types, stored metadata, and its BadDigest/InvalidDigest wire.
A checksum is computed from received bytes before a write. This does not establish streaming framing or trailer
validation. No conformance run is claimed during construction; the final slate verifies independent known vectors.

Sources: [AWS upload integrity](https://docs.aws.amazon.com/AmazonS3/latest/userguide/checking-object-integrity-upload.html),
[AWS CRC64NVME algorithm and vectors](https://github.com/awslabs/aws-checksums/blob/main/tests/crc64_test.c), and
[Cloudflare compatibility](https://developers.cloudflare.com/r2/api/s3/api/), read 2026-09-30.
