{"record":{"id":"de6277b578af15fc","repo":"MuntashirAkon/AppManager","slug":"the-offset-can-not-be-smaller-than-0","errorCode":null,"errorMessage":"The offset can not be smaller than 0","messagePattern":"The offset can not be smaller than 0","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java","lineNumber":1185,"sourceCode":"    /**\n     * {@inheritDoc}\n     *\n     * @since 1.21\n     */\n    @Override\n    public long getDataOffset() {\n        return dataOffset;\n    }\n\n    /**\n     * Set the offset of the data for the tar entry.\n     *\n     * @param dataOffset the position of the data in the tar.\n     * @since 1.21\n     */\n    public void setDataOffset(final long dataOffset) {\n        if (dataOffset < 0) {\n            throw new IllegalArgumentException(\"The offset can not be smaller than 0\");\n        }\n        this.dataOffset = dataOffset;\n    }\n\n    /**\n     * {@inheritDoc}\n     *\n     * @since 1.21\n     */\n    @Override\n    public boolean isStreamContiguous() {\n        return true;\n    }\n\n    /**\n     * get extra PAX Headers\n     *\n     * @return read-only map containing any extra PAX Headers","sourceCodeStart":1167,"sourceCodeEnd":1203,"githubUrl":"https://github.com/MuntashirAkon/AppManager/blob/0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5/app/src/main/java/org/apache/commons/compress/archivers/tar/TarArchiveEntry.java#L1167-L1203","documentation":"Thrown by TarArchiveEntry.setDataOffset when a negative data offset is supplied. The offset marks where the entry's file data begins within the tar stream; negative values are meaningless and indicate a bug in the caller or corrupt archive metadata.","triggerScenarios":"Calling setDataOffset(long) with a negative value — typically when archive metadata (entry sizes, header offsets) is computed from corrupt or maliciously modified tar data.","commonSituations":"Streaming archives where byte offsets are accumulated from header fields that overflowed or were misparsed; custom archive readers built on top of this library.","solutions":["Validate the offset is non-negative before calling setDataOffset","Verify entry sizes/offsets computed from headers haven't overflowed (use unsigned parsing helpers)","Regenerate the archive with a compliant tool if the source archive is corrupt","Catch IllegalArgumentException around entry construction and surface a corrupt-archive message"],"exampleFix":"// before\nentry.setDataOffset(currentPosition()); // can be -1 when stream position is unknown\n// after\nlong pos = currentPosition();\nif (pos < 0) {\n    throw new IOException(\"invalid data offset for entry \" + entry.getName());\n}\nentry.setDataOffset(pos);","handlingStrategy":"validation","validationCode":"if (dataOffset < 0) { throw new IOException(\"Invalid negative data offset\"); }\nentry.setDataOffset(dataOffset);","typeGuard":"boolean isValidOffset(long offset) { return offset >= 0; }","tryCatchPattern":"try {\n    entry.setDataOffset(offset);\n} catch (IllegalArgumentException e) {\n    throw new IOException(\"Corrupt archive: negative data offset\", e);\n}","preventionTips":["Track stream positions with unsigned-safe arithmetic","Validate offsets computed from header fields before assignment","Use TarUtils parsing helpers rather than manual byte decoding"],"tags":["tar","archive-parsing","validation"],"backgroundTag":"invalid-argument-value","analyzedSha":"0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5","analyzedAt":"2026-09-12T14:03:37.243Z","contentChangedAt":"2026-09-12T14:03:37.243Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}