{"record":{"id":"47dd913ce1c99619","repo":"ruvnet/ruflo","slug":"buffer-too-small-to-be-a-valid-rvfa-file","errorCode":null,"errorMessage":"Buffer too small to be a valid RVFA file","messagePattern":"Buffer too small to be a valid RVFA file","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/appliance/rvfa-signing.ts","lineNumber":170,"sourceCode":"      return sorted;\n    }\n    return val;\n  });\n}\n\n/**\n * Parse an RVFA binary into its components without full validation.\n * Returns the header object, header JSON bytes, section data region, and footer.\n */\nfunction parseRvfaBinary(buf: Buffer): {\n  header: Record<string, unknown>;\n  headerStart: number;\n  headerEnd: number;\n  sectionData: Buffer;\n  footer: Buffer;\n} {\n  if (buf.length < PREAMBLE_SIZE + SHA256_SIZE) {\n    throw new Error('Buffer too small to be a valid RVFA file');\n  }\n\n  const magic = buf.subarray(0, 4).toString('ascii');\n  if (magic !== 'RVFA') {\n    throw new Error(`Invalid RVFA magic: expected \"RVFA\", got \"${magic}\"`);\n  }\n\n  const headerLen = buf.readUInt32LE(8);\n  const headerStart = PREAMBLE_SIZE;\n  const headerEnd = headerStart + headerLen;\n\n  if (headerEnd > buf.length - SHA256_SIZE) {\n    throw new Error('Header length extends beyond buffer');\n  }\n\n  const headerJson = buf.subarray(headerStart, headerEnd).toString('utf-8');\n  let header: Record<string, unknown>;\n  try {","sourceCodeStart":152,"sourceCodeEnd":188,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/appliance/rvfa-signing.ts#L152-L188","documentation":"parseRvfaBinary in rvfa-signing.ts rejects any buffer shorter than 44 bytes (12-byte preamble + 32-byte SHA256 footer) before reading the magic. An RVFA image is at minimum preamble + empty header + footer, so anything smaller cannot be a well-formed file. This is the coarsest gate in the signing/verification path — unlike RvfaReader it reports 'too small' before magic/version checks.","triggerScenarios":"Calling signing/verification helpers (e.g. detached-signature computation or verify flows built on parseRvfaBinary) with an empty or near-empty buffer: readFile on a 0-byte file, an empty response body saved as .rvfa, or a placeholder/stub file created before the real download ran.","commonSituations":"Download pipeline wrote an empty file on a 404/204 and verification ran anyway; touch-ing a placeholder path in a script; race where verification starts before the writer finishes; passing a directory path or /dev/null by configuration mistake.","solutions":["Stat the file before verifying: it must be > 44 bytes and ideally match the expected published size","Fix the upstream fetch — an empty file almost always means the download failed silently (check HTTP status before writing)","If writing then verifying in one pipeline, await the write fully (and fsync) before invoking signing APIs","Add a guard in your code: if (buf.length < 44) skip verification and re-fetch"],"exampleFix":"// before — verify whatever landed on disk\nconst sig = await signer.signFile(await readFile(p));\n\n// after — gate on a plausible minimum size\nconst buf = await readFile(p);\nif (buf.length < 44) throw new Error(`suspect download: ${p} is ${buf.length} bytes`);\nconst sig = await signer.signFile(buf);","handlingStrategy":"validation","validationCode":"const MIN = 12 + 32; // preamble + footer\nif (buf.length < MIN) throw new Error(`not an RVFA image (${buf.length} bytes)`);","typeGuard":"function isPossiblyRvfa(buf: Buffer): boolean { return buf.length >= 44; }","tryCatchPattern":"try { await verifyFile(buf, pub); }\ncatch (e) {\n  if (/too small to be a valid RVFA/.test(String((e as Error).message))) {\n    // empty/partial download: re-fetch and check HTTP status before saving\n  }\n  throw e;\n}","preventionTips":["Stat files before verifying — flag sizes below 44 bytes as failed downloads","Check the HTTP status before writing response bodies to disk","Await writes fully before running signing/verification steps"],"tags":["rvfa","signing","empty-file","buffer-bounds"],"backgroundTag":"truncated-file","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}