{"record":{"id":"bae294ba108d22ee","repo":"MuntashirAkon/AppManager","slug":"broken-archive-entry-with-negative-size","errorCode":null,"errorMessage":"broken archive, entry with negative size","messagePattern":"broken archive, entry with negative size","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java","lineNumber":1513,"sourceCode":"    }\n\n    private void parseTarHeader(final byte[] header, final ZipEncoding encoding,\n                                final boolean oldStyle, final boolean lenient)\n            throws IOException {\n        int offset = 0;\n\n        name = oldStyle ? TarUtils.parseName(header, offset, NAMELEN)\n                : TarUtils.parseName(header, offset, NAMELEN, encoding);\n        offset += NAMELEN;\n        mode = (int) parseOctalOrBinary(header, offset, MODELEN, lenient);\n        offset += MODELEN;\n        userId = (int) parseOctalOrBinary(header, offset, UIDLEN, lenient);\n        offset += UIDLEN;\n        groupId = (int) parseOctalOrBinary(header, offset, GIDLEN, lenient);\n        offset += GIDLEN;\n        size = TarUtils.parseOctalOrBinary(header, offset, SIZELEN);\n        if (size < 0) {\n            throw new IOException(\"broken archive, entry with negative size\");\n        }\n        offset += SIZELEN;\n        modTime = parseOctalOrBinary(header, offset, MODTIMELEN, lenient);\n        offset += MODTIMELEN;\n        checkSumOK = TarUtils.verifyCheckSum(header);\n        offset += CHKSUMLEN;\n        linkFlag = header[offset++];\n        linkName = oldStyle ? TarUtils.parseName(header, offset, NAMELEN)\n                : TarUtils.parseName(header, offset, NAMELEN, encoding);\n        offset += NAMELEN;\n        magic = TarUtils.parseName(header, offset, MAGICLEN);\n        offset += MAGICLEN;\n        version = TarUtils.parseName(header, offset, VERSIONLEN);\n        offset += VERSIONLEN;\n        userName = oldStyle ? TarUtils.parseName(header, offset, UNAMELEN)\n                : TarUtils.parseName(header, offset, UNAMELEN, encoding);\n        offset += UNAMELEN;\n        groupName = oldStyle ? TarUtils.parseName(header, offset, GNAMELEN)","sourceCodeStart":1495,"sourceCodeEnd":1531,"githubUrl":"https://github.com/MuntashirAkon/AppManager/blob/0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5/app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java#L1495-L1531","documentation":"Thrown during tar header parsing when the size field of a header block decodes to a negative number. Tar sizes are octal (or base-256 binary), so a negative result means the header is corrupt — the parser refuses to continue rather than reading a wrong number of bytes.","triggerScenarios":"Constructing TarArchiveEntry from a raw 512-byte header whose size field is not valid octal and whose base-256 interpretation is negative — i.e. garbage or deliberately corrupted header bytes.","commonSituations":"Downloading archives over unreliable connections without checksums; archives modified in transit; files created by broken tar writers; random data mistakenly fed to a tar parser.","solutions":["Verify the archive's integrity (checksums, re-download, compare with the publisher's hash)","Re-create the tar with GNU tar or bsdtar","Confirm the file being parsed is actually an uncompressed tar (or wrap the stream in the right decompressor first)","Catch IOException around header parsing and treat the archive as unreadable"],"exampleFix":"// before\nTarArchiveEntry entry = new TarArchiveEntry(rawHeader, encoding);\n// after\nif (!TarUtils.verifyCheckSum(rawHeader)) {\n    throw new IOException(\"corrupt tar header (checksum mismatch)\");\n}\nTarArchiveEntry entry = new TarArchiveEntry(rawHeader, encoding);","handlingStrategy":"try-catch","validationCode":"if (!TarUtils.verifyCheckSum(header)) {\n    throw new IOException(\"tar header checksum mismatch; archive corrupt\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    TarArchiveEntry entry = new TarArchiveEntry(header, encoding);\n} catch (IOException e) {\n    // message contains 'negative size' for this case\n    reportCorruptArchive(e);\n}","preventionTips":["Verify archive checksums before parsing","Confirm the file is really a tar (check 'ustar' magic at offset 257)","Re-download truncated or modified archives"],"tags":["tar","corrupt-archive","io"],"backgroundTag":"corrupt-archive-header","analyzedSha":"0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5","analyzedAt":"2026-09-12T14:03:37.243Z","contentChangedAt":"2026-09-12T14:03:37.243Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}