Claude is just knocking it out of the park. Again.
I have a piece of code called "AudioTime" (historic name) that basically gathers information about AIFF, WAV, MP3, and Flac files. It's basic stuff - "is the file perfectly valid?", "what's the duration?", and other items specific to each format such as bitrates, number of channels, etc. I've also refactored the code slightly into the AudioFileInfo gem.
Every music-related website that I operate uses this code. I sometimes pass audio from the web to other code, such as "lame", so I have to make sure the file is properly formatted to minimize chances of compromise.
I finally got around to having Claude do a deep dive on this piece of code.
Right off the bat:
1. valid_audio_file? regex has a hole for files where the length field contains 0x0A. Lines 874-878:
elsif raw_header =~ /\AFORM....AIF[FC]/
elsif raw_header =~ /\ARIFF....WAVE/
elsif raw_header =~ /\AfLaC/
. in Ruby doesn't match \n (0x0A) without the /m flag. The 4-byte length field is binary and any of those bytes can be 0x0A. A WAV whose RIFF size has an 0x0A byte falls through to mp3_lint, which scans for an MP3 sync, fails, and the file is reported invalid. Probability is ~1.5% per file — small but nonzero and really annoying when it hits. Same hole in determine_file_type at lines 893-898.
Fix: /\ARIFF.{4}WAVE/m (or [\s\S]). Worth checking in production whether audio_file_encoding.rb has ever rejected legit WAVs.
And, yes, it absolutely has rejected legit WAVs. Ugh.