{"record":{"id":"da7cd8e9584608c0","repo":"MuntashirAkon/AppManager","slug":"reserved-flags-are-set-in-the-gz-header","errorCode":null,"errorMessage":"Reserved flags are set in the .gz header","messagePattern":"Reserved flags are set in the \\.gz header","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"app/src/main/java/org/apache/commons/compress/compressors/gzip/GzipCompressorInputStream.java","lineNumber":189,"sourceCode":"        if (magic0 == -1 && !isFirstMember) {\n            return false;\n        }\n\n        if (magic0 != 31 || in.read() != 139) {\n            throw new IOException(isFirstMember ? \"Input is not in the .gz format\"\n                    : \"Garbage after a valid .gz stream\");\n        }\n\n        // Parsing the rest of the header may throw EOFException.\n        final DataInput inData = new DataInputStream(in);\n        final int method = inData.readUnsignedByte();\n        if (method != Deflater.DEFLATED) {\n            throw new IOException(\"Unsupported compression method \" + method + \" in the .gz header\");\n        }\n\n        final int flg = inData.readUnsignedByte();\n        if ((flg & FRESERVED) != 0) {\n            throw new IOException(\n                    \"Reserved flags are set in the .gz header\");\n        }\n\n        parameters.setModificationTime(ByteUtils.fromLittleEndian(inData, 4) * 1000);\n        switch (inData.readUnsignedByte()) { // extra flags\n            case 2:\n                parameters.setCompressionLevel(Deflater.BEST_COMPRESSION);\n                break;\n            case 4:\n                parameters.setCompressionLevel(Deflater.BEST_SPEED);\n                break;\n            default:\n                // ignored for now\n                break;\n        }\n        parameters.setOperatingSystem(inData.readUnsignedByte());\n\n        // Extra field, ignored","sourceCodeStart":171,"sourceCodeEnd":207,"githubUrl":"https://github.com/MuntashirAkon/AppManager/blob/0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5/app/src/main/java/org/apache/commons/compress/compressors/gzip/GzipCompressorInputStream.java#L171-L207","documentation":"RFC 1952 reserves the top FLG bits (FRESERVED = 0xE0); init() throws IOException if any reserved flag bit is set in the .gz header. This guards against formats that would be parsed incorrectly by this decoder.","triggerScenarios":"A gzip header with FLG having reserved bits set — produced by a non-conforming or future/proprietary compressor, or header corruption.","commonSituations":"Vendor-specific gzip variants that abuse reserved bits; bit-level corruption in transit; files from custom embedded compressors.","solutions":["Recompress the file with standard gzip (or zlib) so reserved flags are zero.","Identify the producing tool — if it legitimately sets reserved bits, decode with that tool instead.","If corruption is suspected, re-transfer and verify with a checksum."],"exampleFix":"// before\nInputStream gz = new GzipCompressorInputStream(in);\n// after\n// recompress source with: gzip -c file > file.gz  (conformant header)\nInputStream gz = new GzipCompressorInputStream(in);","handlingStrategy":"try-catch","validationCode":"// FLG reserved bits (0xE0) must be zero per RFC 1952\nrawIn.mark(4);\nint flg = readNthByte(rawIn, 3);\nrawIn.reset();\nif ((flg & 0xE0) != 0) throw new IOException(\"reserved gzip flags set\");","typeGuard":null,"tryCatchPattern":"try {\n    InputStream gz = new GzipCompressorInputStream(rawIn);\n} catch (IOException e) {\n    if (e.getMessage().contains(\"Reserved flags\")) {\n        // decompress with the producing tool or recompress with standard gzip\n    } else {\n        throw e;\n    }\n}","preventionTips":["Reject/recompress files from non-conforming compressors at ingest time.","Check for bit corruption via transport checksums.","Standardize on gzip/zlib tooling across the pipeline."],"tags":["gzip","header-validation","rfc1952"],"backgroundTag":"invalid-flag-value","analyzedSha":"0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5","analyzedAt":"2026-09-12T14:03:37.243Z","contentChangedAt":"2026-09-12T14:03:37.243Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}