{"record":{"id":"cfbb6bfb77eb20e9","repo":"ruvnet/ruflo","slug":"failed-to-parse-rvfa-header-json-cfbb6b","errorCode":null,"errorMessage":"Failed to parse RVFA header JSON","messagePattern":"Failed to parse RVFA header JSON","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/appliance/rvfa-signing.ts","lineNumber":191,"sourceCode":"  const magic = buf.subarray(0, 4).toString('ascii');\n  if (magic !== 'RVFA') {\n    throw new Error(`Invalid RVFA magic: expected \"RVFA\", got \"${magic}\"`);\n  }\n\n  const headerLen = buf.readUInt32LE(8);\n  const headerStart = PREAMBLE_SIZE;\n  const headerEnd = headerStart + headerLen;\n\n  if (headerEnd > buf.length - SHA256_SIZE) {\n    throw new Error('Header length extends beyond buffer');\n  }\n\n  const headerJson = buf.subarray(headerStart, headerEnd).toString('utf-8');\n  let header: Record<string, unknown>;\n  try {\n    header = JSON.parse(headerJson) as Record<string, unknown>;\n  } catch {\n    throw new Error('Failed to parse RVFA header JSON');\n  }\n\n  const footer = buf.subarray(buf.length - SHA256_SIZE);\n  const sectionData = buf.subarray(headerEnd, buf.length - SHA256_SIZE);\n\n  return { header, headerStart, headerEnd, sectionData, footer };\n}\n\n/**\n * Compute the signing digest for an RVFA file.\n *\n * The digest is SHA256 of: canonical_header_json (without signature field)\n *                         + section_data_bytes\n *                         + footer_32_bytes\n */\nfunction computeSigningDigest(\n  header: Record<string, unknown>,\n  sectionData: Buffer,","sourceCodeStart":173,"sourceCodeEnd":209,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/appliance/rvfa-signing.ts#L173-L209","documentation":"The signing path's parseRvfaBinary could not JSON.parse the header region [12, 12+headerLen). Same root causes as the reader-side error of the same name — corrupt or misaligned header bytes — but hit through signing/verification APIs, which parse more leniently (no full validateHeader pass) yet still require the header to be valid JSON to compute the canonical signing digest.","triggerScenarios":"Calling sign/verify helpers on an RVFA file whose header bytes aren't valid JSON: truncated header, off-by-N headerLen, re-encoded file. Note the signing digest is computed over canonical header JSON, so a header that parses but was modified is caught later as a signature mismatch instead.","commonSituations":"CI pipelines signing artifacts produced by a different (older or external) builder whose header serialization differs; files transferred through systems that mangle bytes (FTP ASCII mode); manual header edits that broke JSON syntax before signing.","solutions":["Inspect the header slice: buf.subarray(12, 12 + buf.readUInt32LE(8)).toString('utf8') and find the JSON syntax error position","Rebuild the image with a matching toolchain version — header serialization mismatch between builder and signer is the systematic cause","Avoid ASCII-mode transfers and editors; move .rvfa files as binary only","If signing third-party images, require them pre-parsed/validated before entering the signing step"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"const headerLen = buf.readUInt32LE(8);\nJSON.parse(buf.subarray(12, 12 + headerLen).toString('utf8')); // pre-check parseability","typeGuard":null,"tryCatchPattern":"try { await verifyFile(buf, pub); }\ncatch (e) {\n  if (e instanceof Error && e.message === 'Failed to parse RVFA header JSON') {\n    // inspect the slice; likely builder/signer toolchain mismatch\n  }\n  throw e;\n}","preventionTips":["Use the same package version to build and sign images","Move .rvfa files as binary only (no ASCII-mode FTP, no editors)","Validate third-party images before they enter the signing pipeline"],"tags":["rvfa","signing","json-parse","corruption"],"backgroundTag":"invalid-json-parse","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}