{"record":{"id":"ddce2b3f70b55472","repo":"ruvnet/ruflo","slug":"buffer-too-small-for-declared-header","errorCode":null,"errorMessage":"Buffer too small for declared header","messagePattern":"Buffer too small for declared header","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/appliance/rvfa-distribution.ts","lineNumber":197,"sourceCode":"      const signable = Buffer.concat([Buffer.from(canonicalJson(header), 'utf-8'), payload]);\n      header.signature = edSign(signable, opts.privateKey);\n      header.signedBy = opts.signedBy;\n    }\n    const hJson = Buffer.from(JSON.stringify(header), 'utf-8');\n    const magic = Buffer.from('RVFP');\n    const ver = Buffer.alloc(4); ver.writeUInt32LE(RVFP_VERSION, 0);\n    const hLen = Buffer.alloc(4); hLen.writeUInt32LE(hJson.length, 0);\n    return Buffer.concat([magic, ver, hLen, hJson, payload, sha256B(payload)]);\n  }\n\n  static parsePatchHeader(buf: Buffer): RvfpHeader {\n    if (buf.length < PRE) throw new Error('Buffer too small for RVFP preamble');\n    const magic = buf.subarray(0, 4).toString('ascii');\n    if (magic !== 'RVFP') throw new Error(`Invalid RVFP magic: \"${magic}\"`);\n    const ver = buf.readUInt32LE(4);\n    if (ver !== RVFP_VERSION) throw new Error(`Unsupported RVFP version: ${ver}`);\n    const hLen = buf.readUInt32LE(8);\n    if (PRE + hLen > buf.length) throw new Error('Buffer too small for declared header');\n    const h = JSON.parse(buf.subarray(PRE, PRE + hLen).toString('utf-8')) as RvfpHeader;\n    if (h.magic !== 'RVFP') throw new Error('RVFP header magic mismatch');\n    return h;\n  }\n\n  static async verifyPatch(buf: Buffer): Promise<PatchVerifyResult> {\n    const errors: string[] = [];\n    let header: RvfpHeader;\n    try { header = RvfaPatcher.parsePatchHeader(buf); } catch (e) {\n      const empty: RvfpHeader = {\n        magic: 'RVFP', version: 0, targetApplianceName: '', targetApplianceVersion: '',\n        targetSection: '', patchVersion: '', created: '', newSectionSize: 0,\n        newSectionSha256: '', compression: 'none',\n      };\n      return { valid: false, header: empty, errors: [(e as Error).message] };\n    }\n    const { start, end, section } = patchData(buf);\n    if (end < start) {","sourceCodeStart":179,"sourceCodeEnd":215,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/appliance/rvfa-distribution.ts#L179-L215","documentation":"The preamble's hLen word (offset 8) plus the 12-byte preamble must fit within the buffer. This fires when the declared JSON-header size exceeds what actually arrived — either the hLen field is corrupt (huge value) or the file body is truncated relative to its own length table. The preamble checks (magic/version) already passed, so the head is genuine but the tail is missing.","triggerScenarios":"`parsePatchHeader(buf)` where readUInt32LE(8) yields a value with 12 + hLen > buf.length: a partially downloaded patch that got the preamble but not all header bytes, or corruption that scrambled the hLen word.","commonSituations":"Interrupted transfer with a content-length mismatch; files truncated by quota enforcement or sync tools; a producer bug writing wrong header lengths (rare — reproduce from the same source to rule out).","solutions":["Re-fetch or restore the patch — the file contradicts its own length table","Compare the file size with the producer's recorded size if available","If it reproduces consistently from one producer, check that producer for header-length bugs before blaming transport"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"const hLen = buf.readUInt32LE(8);\nif (12 + hLen > buf.length) {\n  throw new Error('Patch header truncated in transit — re-download');\n}","typeGuard":null,"tryCatchPattern":"const result = await RvfaPatcher.verifyPatch(buf); // collects header errors in result.errors\nif (result.errors.length > 0) {\n  // reject with the structured report instead of letting parsePatchHeader throw\n}","preventionTips":["Verify content-length / expected byte size after download before parsing","Prefer verifyPatch() over parsePatchHeader() for any file that crossed a network"],"tags":["rvfa-distribution","rvfp-patch","binary-format","truncation"],"backgroundTag":"truncated-binary-file","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}