{"record":{"id":"9800ad8603c58f5e","repo":"Hmbown/CodeWhale","slug":"invalid-update-entry","errorCode":null,"errorMessage":"Invalid update entry.","messagePattern":"Invalid update entry\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"crates/tui/plugins/computer-use/app/updates.mjs","lineNumber":58,"sourceCode":"  return {available:true,version,url,sha256:asset.digest.slice(7),size:asset.size,message:`Computer Use ${version} is available. Install it to restart the helper; existing computer sessions will stop.`};\n}\nexport async function checkForUpdate() {\n  const response=await fetch(\"https://api.github.com/repos/Hmbown/codewhale-cu-plugin/releases/latest\",{redirect:\"error\",headers:{Accept:\"application/vnd.github+json\",\"X-GitHub-Api-Version\":\"2022-11-28\"},signal:AbortSignal.timeout(10_000)});\n  if(response.status===404) return {available:false,message:\"No stable installer has been published yet. Your current app is unchanged.\"};\n  if(!response.ok) throw new Error(`The update service is unavailable (${response.status}). Try again later.`);\n  return releaseUpdate(JSON.parse((await responseBytes(response,1024*1024)).toString(\"utf8\")));\n}\n\n/** Inspect both ZIP headers before extraction: no links, traversal or bombs. */\nexport function validateReleaseZip(bytes) {\n  const minimum=Math.max(0,bytes.length-65557); let end=-1;\n  for(let i=bytes.length-22;i>=minimum;i--) if(bytes.readUInt32LE(i)===0x06054b50&&i+22+bytes.readUInt16LE(i+20)===bytes.length) { end=i; break; }\n  if(end<0||bytes.readUInt16LE(end+4)||bytes.readUInt16LE(end+6)) throw new Error(\"Invalid update archive.\");\n  const count=bytes.readUInt16LE(end+10); let position=bytes.readUInt32LE(end+16),total=0;\n  if(!count||count>2000||bytes.readUInt16LE(end+8)!==count||position+bytes.readUInt32LE(end+12)!==end) throw new Error(\"Invalid update archive index.\");\n  const seen=new Set();\n  for(let i=0;i<count;i++) {\n    if(position+46>end||bytes.readUInt32LE(position)!==0x02014b50) throw new Error(\"Invalid update entry.\");\n    const flags=bytes.readUInt16LE(position+8),method=bytes.readUInt16LE(position+10),length=bytes.readUInt16LE(position+28),extra=bytes.readUInt16LE(position+30),comment=bytes.readUInt16LE(position+32);\n    const name=bytes.subarray(position+46,position+46+length).toString(\"utf8\");\n    const kind=(bytes.readUInt32LE(position+38)>>>16)&0xf000,offset=bytes.readUInt32LE(position+42),compressed=bytes.readUInt32LE(position+20);\n    const size=bytes.readUInt32LE(position+24); total+=size;\n    if(flags&1||![0,8].includes(method)||![0,0x4000,0x8000].includes(kind)||total>512*1024*1024||position+46+length+extra+comment>end) throw new Error(\"Unsupported update entry.\");\n    if(!name.startsWith(`${APP_NAME}.app/`)||name.includes(\"\\\\\")||name.includes(\":\")||name.includes(\"\\0\")||name.split(\"/\").some(part=>part===\"..\"||part===\".\")||seen.has(name)) throw new Error(\"Unsafe update path.\");\n    seen.add(name);\n    if(offset+30>position||bytes.readUInt32LE(offset)!==0x04034b50) throw new Error(\"Invalid update file header.\");\n    const localLength=bytes.readUInt16LE(offset+26),localExtra=bytes.readUInt16LE(offset+28);\n    if(offset+30+localLength+localExtra+compressed>bytes.readUInt32LE(end+16)||bytes.subarray(offset+30,offset+30+localLength).toString(\"utf8\")!==name) throw new Error(\"Inconsistent update file header.\");\n    if(bytes.readUInt16LE(offset+8)!==method||bytes.readUInt16LE(offset+6)!==flags||(!(flags&8)&&(bytes.readUInt32LE(offset+18)!==compressed||bytes.readUInt32LE(offset+22)!==size))) throw new Error(\"Inconsistent update sizes or compression.\");\n    const start=offset+30+localLength+localExtra;\n    // Header sizes are untrusted. Bound actual expansion before ditto writes\n    // anything, including a compressed payload whose headers understate size.\n    const payload=bytes.subarray(start,start+compressed);\n    let expanded;\n    try { expanded=method===0?payload.length:inflateRawSync(payload,{maxOutputLength:Math.max(size,1)}).length; }\n    catch { throw new Error(\"Invalid or oversized compressed update entry.\"); }","sourceCodeStart":40,"sourceCodeEnd":76,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/plugins/computer-use/app/updates.mjs#L40-L76","documentation":"validateReleaseZip manually parses the ZIP central directory without an archive library. Before reading each central-directory header it checks that the full 46-byte fixed header fits before the end-of-central-directory record and that the bytes at the cursor carry the central-directory file-header signature 0x02014b50 (PK\\x01\\x02). Either check failing means the archive's central directory is corrupt, truncated, or points at garbage, so the library refuses to trust any further offsets.","triggerScenarios":"Calling validateReleaseZip on bytes whose central-directory `position` cursor walks past `end` (a 46-byte header would cross the EOCD) or where the signature at `position` is not 0x02014b50 — e.g. a truncated download, a self-extracting or non-ZIP file, or a zip whose central directory offset fields don't match its EOCD.","commonSituations":"Serving a partially downloaded or HTML error page instead of the release zip; a build step (some incremental/staged zip writers) emitting a central directory that disagrees with the file; tampered or fuzzed update payloads; wrong file fetched from a mirror.","solutions":["Re-download the release zip from the exact GitHub release URL and confirm its SHA-256 digest against the release metadata before calling validateReleaseZip.","Verify the file is a real zip: check the bytes start with PK\\x03\\x04 and end with a valid EOCD signature PK\\x05\\x06, e.g. with `unzip -t file.zip`.","Rebuild the artifact with a standard zip writer (zip/Info-ZIP or the packaging pipeline) rather than a hand-rolled or post-processed archive.","If the error appears in tests, regenerate the test fixture zip — it was likely truncated or hand-edited."],"exampleFix":"// before\nconst bytes = fs.readFileSync(args[2]);\nvalidateReleaseZip(bytes);\n// after\nconst bytes = fs.readFileSync(args[2]);\nif (bytes.subarray(0,4).toString(\"latin1\") !== \"PK\\x03\\x04\") throw new Error(\"Not a zip file — check the download URL/digest.\");\nvalidateReleaseZip(bytes);","handlingStrategy":"validation","validationCode":"const bytes = fs.readFileSync(zipPath);\nif (bytes.length < 22 || bytes.subarray(0,4).toString(\"latin1\") !== \"PK\\x03\\x04\") throw new Error(\"Not a zip file\");","typeGuard":"function looksLikeZip(buf){return Buffer.isBuffer(buf)&&buf.length>=22&&buf.readUInt32LE(0)===0x04034b50;}","tryCatchPattern":"try { validateReleaseZip(bytes); } catch (e) { if (e.message === \"Invalid update entry.\") { /* re-download / republish artifact */ } else throw e; }","preventionTips":["Verify the downloaded asset's SHA-256 before validating","Smoke-test the artifact with `unzip -t` in CI before publishing","Never truncate or post-process the zip after writing","Fetch only from the canonical GitHub release URL"],"tags":["zip","archive-parsing","update-integrity","corrupt-file"],"backgroundTag":"unexpected-response-shape","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}