Severity: Critical
In quic.rs send_file() (line ~296-301), the chunk header [ID: u32][Size: u32][Hash: 32 bytes] is constructed in a Vec but the code then calls:
stream.write_all(chunk_data).await.ok(); // sends DATA first!
stream.finish().ok();
The header variable is built but never written to the stream. The receiver expects to read 40 bytes of header first (stream.read_exact(&mut header)), but it will instead get raw chunk data, causing read_exact to misinterpret chunk content as header bytes. This will silently corrupt file transfers or cause chunk assembly failures.
The fix is to write the header before the data:
stream.write_all(&header).await?; // header FIRST
stream.write_all(chunk_data).await?; // then data
Affected Files
src/protocol/quic.rs (lines 296-302 in send_file)
Issue filed by Hermes — automated code audit
Severity: Critical
In
quic.rssend_file()(line ~296-301), the chunk header[ID: u32][Size: u32][Hash: 32 bytes]is constructed in aVecbut the code then calls:The
headervariable is built but never written to the stream. The receiver expects to read 40 bytes of header first (stream.read_exact(&mut header)), but it will instead get raw chunk data, causingread_exactto misinterpret chunk content as header bytes. This will silently corrupt file transfers or cause chunk assembly failures.The fix is to write the header before the data:
Affected Files
src/protocol/quic.rs(lines 296-302 insend_file)Issue filed by Hermes — automated code audit