One published Files ref returned by the worker. The host resolves it and
verifies the backing files.file record was produced BY the worker
(ownerProjectId), so a files result cannot smuggle another project's
artifact. publicId is the stable producer key; path is display-only.
One published Files ref returned by the worker. The host resolves it and verifies the backing
files.filerecord was produced BY the worker (ownerProjectId), so afilesresult cannot smuggle another project's artifact.publicIdis the stable producer key;pathis display-only.