Chapter 02 · Syphio Runtime
Upload
Upload establishes the immutable input that every later Finding and Evidence record must reference.
Chapter outcome
You will know which archive to submit, what preflight checks mean and when an audit is consumed.
Current access status
Theme ZIP upload is not open during Phase 0. This chapter defines the target archive, preflight, snapshot and consumption contract that must apply before user Runtime execution is enabled.
Archive contract
Submit one ZIP containing one Shopify theme directory. Preserve the original folders and filenames so source locations in the report remain reviewable.
- Keep layout, templates, sections, snippets, assets, config and locales in their normal structure
- Do not combine multiple theme versions in one archive
- Remove secrets, exports, backups and files unrelated to the theme
Preflight
Before Runtime processing begins, Syphio checks that the input is accepted as a theme snapshot. A rejected archive or failed preflight does not consume an audit.
Immutable snapshot
The accepted archive becomes the fixed input for that execution. Later edits to your local theme do not alter an existing report; submit a new snapshot for a new verification.
Usage accounting
An audit is consumed when the Runtime starts processing an accepted snapshot. A rejected upload, failed preflight, or Syphio failure before a result is produced does not consume an audit. If reserved, the audit is restored automatically.
- An audit stopped by the user after Runtime processing starts remains consumed.
- Reviewing the completed report never consumes another audit.
Access boundary
The current workflow reads the uploaded snapshot only. It does not write to Shopify, apply a patch or deploy a theme.