{"record":{"id":"52c21d6d035c7aad","repo":"ruvnet/ruflo","slug":"label-contains-null-bytes","errorCode":null,"errorMessage":"${label} contains null bytes","messagePattern":"(.+?) contains null bytes","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/daemon.ts","lineNumber":372,"sourceCode":"\n      return { success: true };\n    } catch (error) {\n      output.printError(`Failed to start daemon: ${error instanceof Error ? error.message : String(error)}`);\n      return { success: false, exitCode: 1 };\n    }\n  },\n};\n\n/**\n * Validate path for security - prevents path traversal and injection\n */\nfunction validatePath(path: string, label: string): void {\n  // Must be absolute after resolution\n  const resolved = resolve(path);\n\n  // Check for null bytes (injection attack)\n  if (path.includes('\\0')) {\n    throw new Error(`${label} contains null bytes`);\n  }\n\n  // Check for shell metacharacters in path components\n  if (/[;&|`$<>]/.test(path)) {\n    throw new Error(`${label} contains shell metacharacters`);\n  }\n\n  // Prevent path traversal outside expected directories\n  if (!resolved.includes('.claude-flow') && !resolved.includes('bin')) {\n    // Allow only paths within project structure\n    const cwd = process.cwd();\n    if (!resolved.startsWith(cwd)) {\n      throw new Error(`${label} escapes project directory`);\n    }\n  }\n}\n\n/**","sourceCodeStart":354,"sourceCodeEnd":390,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/commands/daemon.ts#L354-L390","documentation":"validatePath() in daemon.ts is a security gate for paths the daemon command accepts (log/pid/workspace-related paths later embedded in a forked child's argv and used in filesystem calls). Any path containing a NUL byte (\\0) is rejected before use — the classic null-byte injection defense against C-string truncation tricks where 'safe/../../evil\\0' could be cut short by underlying native APIs. The thrown Error propagates up to daemon start's catch and prints 'Failed to start daemon: <label> contains null bytes'.","triggerScenarios":"Starting the daemon with a path flag or environment-derived path containing a literal NUL: e.g. --log-file '/var/log/d\\0evil' or a %00 that was URL-decoded into \\0 by a wrapper script. Only a string actually containing the \\0 code point triggers it.","commonSituations":"CI/CD pipelines URL-decoding %00 from a parameter into the path; shell scripts with unescaped escape sequences; probing/malicious input fuzzing path flags; copy-paste from web content carrying hidden control characters.","solutions":["Strip or reject NUL bytes at the source: sanitize inputs with path.replace(/\\0/g, '') or refuse them before invoking the daemon command","Fix the upstream producer (CI variable, env file, script) that introduced the \\0 — this error means your input pipeline is already corrupt","Check the exact flag path in the error label to identify which argument carried the byte"],"exampleFix":"// before\nconst logFile = decodeURIComponent(process.env.DAEMON_LOG); // may contain %00 -> \\0\nawait daemonStart({ logFile });\n// after\nconst raw = decodeURIComponent(process.env.DAEMON_LOG ?? '');\nif (raw.includes('\\0')) throw new Error('DAEMON_LOG contains NUL byte');\nconst logFile = raw.replace(/\\0/g, '');\nawait daemonStart({ logFile });","handlingStrategy":"validation","validationCode":"function rejectNul(s: string, label: string): string {\n  if (s.includes('\\0')) throw new Error(`${label} contains NUL byte`);\n  return s;\n}\nconst logFile = rejectNul(decodeURIComponent(process.env.DAEMON_LOG ?? ''), 'DAEMON_LOG');","typeGuard":"function isNullByteFreePath(v: unknown): v is string {\n  return typeof v === 'string' && !v.includes('\\0') && !/[;&|`$<>]/.test(v);\n}","tryCatchPattern":"try {\n  await startDaemon(projectRoot, config);\n} catch (err) {\n  if (err instanceof Error && /contains null bytes/.test(err.message)) {\n    // input pipeline corruption — fix the source of the \\0, do not retry as-is\n  }\n}","preventionTips":["Sanitize every path assembled from env vars, CI parameters, or decoded URLs before passing it to daemon commands","URL-decode then reject %00-derived NUL bytes at your system boundary","Never retry the same input after this error — it indicates corrupted or hostile input, not a transient failure"],"tags":["security","path-validation","null-byte-injection","daemon","input-sanitization"],"backgroundTag":"null-byte-path-injection","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}