Skip to content

Bug: QUIC send_file sends header AFTER data — header not prefixed on stream #4

Description

@daschinmoy21

Severity: Critical

In quic.rs send_file() (line ~296-301), the chunk header [ID: u32][Size: u32][Hash: 32 bytes] is constructed in a Vec but the code then calls:

stream.write_all(chunk_data).await.ok();  // sends DATA first!
stream.finish().ok();

The header variable is built but never written to the stream. The receiver expects to read 40 bytes of header first (stream.read_exact(&mut header)), but it will instead get raw chunk data, causing read_exact to misinterpret chunk content as header bytes. This will silently corrupt file transfers or cause chunk assembly failures.

The fix is to write the header before the data:

stream.write_all(&header).await?;      // header FIRST
stream.write_all(chunk_data).await?;   // then data

Affected Files

  • src/protocol/quic.rs (lines 296-302 in send_file)

Issue filed by Hermes — automated code audit

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcriticalCritical severity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions