{"record":{"id":"a2f4fd591f7521f6","repo":"ruvnet/ruflo","slug":"header-length-extends-beyond-buffer","errorCode":null,"errorMessage":"Header length extends beyond buffer","messagePattern":"Header length extends beyond buffer","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/appliance/rvfa-signing.ts","lineNumber":183,"sourceCode":"  headerEnd: number;\n  sectionData: Buffer;\n  footer: Buffer;\n} {\n  if (buf.length < PREAMBLE_SIZE + SHA256_SIZE) {\n    throw new Error('Buffer too small to be a valid RVFA file');\n  }\n\n  const magic = buf.subarray(0, 4).toString('ascii');\n  if (magic !== 'RVFA') {\n    throw new Error(`Invalid RVFA magic: expected \"RVFA\", got \"${magic}\"`);\n  }\n\n  const headerLen = buf.readUInt32LE(8);\n  const headerStart = PREAMBLE_SIZE;\n  const headerEnd = headerStart + headerLen;\n\n  if (headerEnd > buf.length - SHA256_SIZE) {\n    throw new Error('Header length extends beyond buffer');\n  }\n\n  const headerJson = buf.subarray(headerStart, headerEnd).toString('utf-8');\n  let header: Record<string, unknown>;\n  try {\n    header = JSON.parse(headerJson) as Record<string, unknown>;\n  } catch {\n    throw new Error('Failed to parse RVFA header JSON');\n  }\n\n  const footer = buf.subarray(buf.length - SHA256_SIZE);\n  const sectionData = buf.subarray(headerEnd, buf.length - SHA256_SIZE);\n\n  return { header, headerStart, headerEnd, sectionData, footer };\n}\n\n/**\n * Compute the signing digest for an RVFA file.","sourceCodeStart":165,"sourceCodeEnd":201,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/appliance/rvfa-signing.ts#L165-L201","documentation":"In the signing parser, headerLen (read as u32LE at offset 8) plus the 12-byte preamble extends past buf.length - 32, i.e. the declared header would overlap or exceed the region reserved for section data plus the 32-byte footer. Equivalent to RvfaReader's 'Buffer too small' check but reached via the signing path, which skips magic/version validation of the header body itself.","triggerScenarios":"Any signing/verification API built on parseRvfaBinary receiving a file where readUInt32LE(8) is inflated or the file is truncated after the preamble: partially transferred images, or a corrupted length field from bit rot or bad tooling.","commonSituations":"Same family as the reader-side error: interrupted transfers and truncated writes; additionally, signing pipelines that run over a file still being written concurrently (read a half-flushed preamble with a stale length).","solutions":["Verify file integrity first: size at both ends, then footer SHA256 — truncation or length corruption will also break verification anyway","Ensure signing runs after the file write completes (await + fsync), not concurrently with the builder","If the length field is corrupt, the image is unrecoverable — rebuild it","Compare the value at offset 8 against file size: it must satisfy 12 + headerLen <= length - 32"],"exampleFix":"// before — sign while the builder may still be flushing\nconst sig = await signer.signFile(await readFile(path));\n\n// after — serialize build and sign\nawait builder.buildAndWrite(path); // internally: writeFile + fh.sync()\nconst sig = await signer.signFile(await readFile(path));","handlingStrategy":"validation","validationCode":"const headerLen = buf.readUInt32LE(8);\nif (12 + headerLen > buf.length - 32) throw new Error('header would overrun file — truncated');","typeGuard":null,"tryCatchPattern":"try { await verifyFile(buf, pub); }\ncatch (e) {\n  if (/Header length extends beyond buffer/.test(String((e as Error).message))) {\n    // re-fetch/rebuild; length field or file size is wrong\n  }\n  throw e;\n}","preventionTips":["Serialize build and sign steps — never sign a file still being written","Checksum transfers end-to-end","Treat a bad length field as unrecoverable: rebuild the image"],"tags":["rvfa","signing","truncated-file","buffer-bounds"],"backgroundTag":"truncated-file","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}