{"record":{"id":"c29219966892cb9c","repo":"MuntashirAkon/AppManager","slug":"minor-device-number-is-out-of-range-devno","errorCode":null,"errorMessage":"Minor device number is out of range: + devNo","messagePattern":"Minor device number is out of range: \\+ devNo","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java","lineNumber":958,"sourceCode":"     * Get this entry's minor device number.\n     *\n     * @return This entry's minor device number.\n     * @since 1.4\n     */\n    public int getDevMinor() {\n        return devMinor;\n    }\n\n    /**\n     * Set this entry's minor device number.\n     *\n     * @param devNo This entry's minor device number.\n     * @throws IllegalArgumentException if the devNo is &lt; 0.\n     * @since 1.4\n     */\n    public void setDevMinor(final int devNo) {\n        if (devNo < 0) {\n            throw new IllegalArgumentException(\"Minor device number is out of \" + \"range: \" + devNo);\n        }\n        this.devMinor = devNo;\n    }\n\n    /**\n     * Indicates in case of an oldgnu sparse file if an extension\n     * sparse header follows.\n     *\n     * @return true if an extension oldgnu sparse header follows.\n     */\n    public boolean isExtended() {\n        return isExtended;\n    }\n\n    /**\n     * Get this entry's real file size in case of a sparse file.\n     * <p>If the file is not a sparse file, return size instead of realSize.</p>\n     *","sourceCodeStart":940,"sourceCodeEnd":976,"githubUrl":"https://github.com/MuntashirAkon/AppManager/blob/0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5/app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java#L940-L976","documentation":"Thrown by TarArchiveEntry.setDevMinor when the minor device number passed in is negative. Device numbers in tar entries are unsigned per the format, so a negative value cannot be represented and the method rejects it eagerly rather than writing a corrupt entry.","triggerScenarios":"Calling setDevMinor(-1) (or any negative int) directly, or indirectly when processPaxHeader parses a PAX header whose 'devminor' value parses to a negative number (e.g. malformed or malicious header data).","commonSituations":"Parsing hand-crafted, truncated, or maliciously crafted tar archives where PAX extended headers contain invalid devminor values; tools that copy file metadata from stat structures on unusual filesystems.","solutions":["Fix the caller so it never passes a negative device number (clamp or validate before calling setDevMinor)","Check the archive integrity: regenerate the tar with a standards-compliant tool (GNU tar, bsdtar)","If you do not care about device metadata, skip calling setDevMinor for device-type entries you don't reproduce","Catch IllegalArgumentException around archive parsing and treat it as a corrupt-archive case"],"exampleFix":"// before\nentry.setDevMinor(readDevMinorFromHeader()); // may be -1 on malformed data\n// after\nint devMinor = readDevMinorFromHeader();\nif (devMinor >= 0) {\n    entry.setDevMinor(devMinor);\n}","handlingStrategy":"validation","validationCode":"if (devNo < 0) { throw new IllegalArgumentException(\"devNo must be >= 0, got \" + devNo); }\nentry.setDevMinor(devNo);","typeGuard":"boolean isValidDevNo(int devNo) { return devNo >= 0; }","tryCatchPattern":"try {\n    entry.setDevMinor(devNo);\n} catch (IllegalArgumentException e) {\n    // treat as corrupt/malicious archive metadata\n    throw new IOException(\"Invalid device number in archive\", e);\n}","preventionTips":["Validate all header-derived numbers before applying them to entries","Only apply device metadata for entries you actually reconstruct","Sanitize untrusted archives with a parser before processing"],"tags":["tar","archive-parsing","validation"],"backgroundTag":"invalid-argument-value","analyzedSha":"0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5","analyzedAt":"2026-09-12T14:03:37.243Z","contentChangedAt":"2026-09-12T14:03:37.243Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}