{"record":{"id":"a6e83e4f67cc214e","repo":"ruvnet/ruflo","slug":"rvfp-header-magic-mismatch","errorCode":null,"errorMessage":"RVFP header magic mismatch","messagePattern":"RVFP header magic mismatch","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/appliance/rvfa-distribution.ts","lineNumber":199,"sourceCode":"      header.signedBy = opts.signedBy;\n    }\n    const hJson = Buffer.from(JSON.stringify(header), 'utf-8');\n    const magic = Buffer.from('RVFP');\n    const ver = Buffer.alloc(4); ver.writeUInt32LE(RVFP_VERSION, 0);\n    const hLen = Buffer.alloc(4); hLen.writeUInt32LE(hJson.length, 0);\n    return Buffer.concat([magic, ver, hLen, hJson, payload, sha256B(payload)]);\n  }\n\n  static parsePatchHeader(buf: Buffer): RvfpHeader {\n    if (buf.length < PRE) throw new Error('Buffer too small for RVFP preamble');\n    const magic = buf.subarray(0, 4).toString('ascii');\n    if (magic !== 'RVFP') throw new Error(`Invalid RVFP magic: \"${magic}\"`);\n    const ver = buf.readUInt32LE(4);\n    if (ver !== RVFP_VERSION) throw new Error(`Unsupported RVFP version: ${ver}`);\n    const hLen = buf.readUInt32LE(8);\n    if (PRE + hLen > buf.length) throw new Error('Buffer too small for declared header');\n    const h = JSON.parse(buf.subarray(PRE, PRE + hLen).toString('utf-8')) as RvfpHeader;\n    if (h.magic !== 'RVFP') throw new Error('RVFP header magic mismatch');\n    return h;\n  }\n\n  static async verifyPatch(buf: Buffer): Promise<PatchVerifyResult> {\n    const errors: string[] = [];\n    let header: RvfpHeader;\n    try { header = RvfaPatcher.parsePatchHeader(buf); } catch (e) {\n      const empty: RvfpHeader = {\n        magic: 'RVFP', version: 0, targetApplianceName: '', targetApplianceVersion: '',\n        targetSection: '', patchVersion: '', created: '', newSectionSize: 0,\n        newSectionSha256: '', compression: 'none',\n      };\n      return { valid: false, header: empty, errors: [(e as Error).message] };\n    }\n    const { start, end, section } = patchData(buf);\n    if (end < start) {\n      errors.push('Patch too small: no room for section data and footer');\n      return { valid: false, header, errors };","sourceCodeStart":181,"sourceCodeEnd":217,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/appliance/rvfa-distribution.ts#L181-L217","documentation":"After the outer binary preamble passes, the JSON header embedded at offset 12 must itself carry magic === 'RVFP'. This second check catches files whose envelope is genuine but whose header JSON was swapped, hand-edited, or rebuilt — e.g. someone rewrote the header to change patch metadata and dropped the magic field.","triggerScenarios":"`parsePatchHeader` on a file whose first 12 bytes are genuine but whose header JSON was replaced by a rewriter that omitted or renamed the magic field; spliced/concatenated patches; corruption that spared the preamble.","commonSituations":"Editing patch headers in place to bump patchVersion or retarget an appliance; partially applied binary edits; malformed patches from non-library tooling.","solutions":["Never hand-edit RVFP files — regenerate with RvfaPatcher.createPatch with the desired metadata","If metadata must change, rebuild the patch from the source artifacts","Run RvfaPatcher.verifyPatch() for a structured report of everything wrong (it also checks signature and hashes)"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"const result = await RvfaPatcher.verifyPatch(buf); // catches header errors AND checks signature/hashes\nif (result.errors.length > 0) {\n  // reject with the full defect report; do not call parsePatchHeader at all\n} else {\n  const header = RvfaPatcher.parsePatchHeader(buf); // now safe\n}","preventionTips":["Treat patches as immutable artifacts — regenerate instead of editing headers in place","Route untrusted patches through verifyPatch(), which reports all defects in one structured result"],"tags":["rvfa-distribution","rvfp-patch","magic-number","integrity"],"backgroundTag":"invalid-magic-number","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}