The metadata wire format uses metadata_to_buf/metadata_from_buf which serializes/deserializes these types directly with memcpy. If a 32-bit client communicates with a 64-bit server, the metadata wire format will be interpreted differently, causing data corruption or crashes.
Then explicitly cast or convert each field when serializing and deserializing.
Severity
High
Category
Bug
## Description
In `src/shared/metadata.h` line 8-9, `FILE_METADATA_WIRE_SIZE` is computed based on compile-time type sizes:
```c
#define FILE_METADATA_WIRE_SIZE (sizeof(mode_t) + sizeof(uid_t) + sizeof(gid_t) + sizeof(time_t) + sizeof(long))
```
Type sizes differ between architectures:
- **64-bit Linux**: mode_t=4, uid_t=4, gid_t=4, time_t=8, long=8 → 28 bytes
- **32-bit Linux**: mode_t=4, uid_t=4, gid_t=4, time_t=4, long=4 → 20 bytes
The metadata wire format uses `metadata_to_buf`/`metadata_from_buf` which serializes/deserializes these types directly with `memcpy`. If a 32-bit client communicates with a 64-bit server, the metadata wire format will be interpreted differently, causing data corruption or crashes.
## Location
`src/shared/metadata.h:8-9`, `src/shared/metadata.c:11-47`
## Suggested Fix
Use fixed-width integer types for the wire format instead of relying on `sizeof()` for native types. Define explicit wire-format fields:
```c
#define METADATA_WIRE_MODE_SIZE 4 // always uint32_t
#define METADATA_WIRE_UID_SIZE 4 // always uint32_t
#define METADATA_WIRE_GID_SIZE 4 // always uint32_t
#define METADATA_WIRE_MTIME_SEC_SIZE 8 // always int64_t
#define METADATA_WIRE_MTIME_NSEC_SIZE 8 // always int64_t
```
Then explicitly cast or convert each field when serializing and deserializing.
## Severity
High
## Category
Bug
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
src/shared/metadata.hline 8-9,FILE_METADATA_WIRE_SIZEis computed based on compile-time type sizes:Type sizes differ between architectures:
The metadata wire format uses
metadata_to_buf/metadata_from_bufwhich serializes/deserializes these types directly withmemcpy. If a 32-bit client communicates with a 64-bit server, the metadata wire format will be interpreted differently, causing data corruption or crashes.Location
src/shared/metadata.h:8-9,src/shared/metadata.c:11-47Suggested Fix
Use fixed-width integer types for the wire format instead of relying on
sizeof()for native types. Define explicit wire-format fields:Then explicitly cast or convert each field when serializing and deserializing.
Severity
High
Category
Bug