feat(lock): main-window lock screen; harden env gating, sandbox and ssh teardown

Lock screen (main-window overlay, no second window):
- scrypt password verifier in <userData>/lock.json (per-write salt,
  timingSafeEqual); salt/hash/password never leave the main process
- lock now / idle auto-lock / lock at startup, growing failure cooldown,
  lock flags persisted so a quit-and-relaunch cannot bypass the lock
- locked shell and body portals go inert while sessions keep running;
  menu accelerators (reload, DevTools, zoom) are swallowed while locked
- settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja

Security and stability:
- packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv)
- renderer preload runs with sandbox: true
- unreadable known_hosts store fails closed instead of being overwritten
- connect-time secrets gated by the bookmark's auth method (connectPromptFor)
- ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once
- sysinfo polling is refcounted for split panes (forceStopPolling on close)
- session-log index entries are path-contained; settings store writes
  atomically with EPERM/EBUSY retry
- sync-changelog tolerates CRLF checkouts (was a silent no-op)
- retry ssh2 host-key generation (flaky malformed key, ~1/500)

Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e;
GitHub Actions CI (typecheck + 10 offline tests + build)
This commit is contained in:
Bill committed 2026-09-24 22:16:43 +08:00
1 parent 471f8c3e73
commit 35583b2c15
47 files changed
+3058 -105

No files matched your search

+17 -3
View File
@@ -51,13 +51,27 @@ const sync = ({ notes, changelog, header, required }) => {
return
}
const section = `## v${pkgVersion} - ${new Date().toISOString().slice(0, 10)}\n\n${body}\n`
// The header pattern must match the file's own newlines: a checkout with
// core.autocrlf=true leaves these files CRLF, and an `\n`-only pattern then
// matches nothing — the write below becomes a silent no-op that still logs
// success (exactly what bit the v1.0.17 sync). The inserted section follows
// the file's dominant ending so it does not create mixed line endings.
const nl = existing.includes('\r\n') ? '\r\n' : '\n'
const section =
`## v${pkgVersion} - ${new Date().toISOString().slice(0, 10)}${nl}${nl}` +
`${body.split('\n').join(nl)}${nl}`
// Function replacement, not a string: a notes body containing `$&`, `$1`, `` $` ``
// or `$'` would otherwise be expanded by String.replace and corrupt the merge.
const updated = existing
? existing.replace(new RegExp(`^(${header}\\n\\n)`), (_m, head) => `${head}${section}\n`)
: `${header}\n\n${section}`
? existing.replace(new RegExp(`^(${header}\\r?\\n\\r?\\n)`), (_m, head) => `${head}${section}${nl}`)
: `${header}${nl}${nl}${section}`
fs.writeFileSync(changelogPath, updated, 'utf8')
// Belt and braces: the header replace is the only thing that places the
// section, so prove it landed instead of trusting the pattern.
if (!fs.readFileSync(changelogPath, 'utf8').includes(`## v${pkgVersion} `)) {
console.error(`${changelog}: header pattern did not match — section was NOT inserted`)
process.exit(1)
}
console.log(`${changelog}: added v${pkgVersion} (${body.split('\n').length} lines)`)
}