feat(lock): main-window lock screen; harden env gating, sandbox and ssh teardown
Lock screen (main-window overlay, no second window): - scrypt password verifier in <userData>/lock.json (per-write salt, timingSafeEqual); salt/hash/password never leave the main process - lock now / idle auto-lock / lock at startup, growing failure cooldown, lock flags persisted so a quit-and-relaunch cannot bypass the lock - locked shell and body portals go inert while sessions keep running; menu accelerators (reload, DevTools, zoom) are swallowed while locked - settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja Security and stability: - packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv) - renderer preload runs with sandbox: true - unreadable known_hosts store fails closed instead of being overwritten - connect-time secrets gated by the bookmark's auth method (connectPromptFor) - ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once - sysinfo polling is refcounted for split panes (forceStopPolling on close) - session-log index entries are path-contained; settings store writes atomically with EPERM/EBUSY retry - sync-changelog tolerates CRLF checkouts (was a silent no-op) - retry ssh2 host-key generation (flaky malformed key, ~1/500) Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e; GitHub Actions CI (typecheck + 10 offline tests + build)
This commit is contained in:
1 parent
471f8c3e73
commit
35583b2c15
47 files changed
+3058
-105
No files matched your search
+50
-1
@@ -28,7 +28,22 @@ const fail = (msg) => {
|
||||
const wait = (ms) => new Promise((r) => setTimeout(r, ms))
|
||||
|
||||
// ---- 1. Loopback ssh server with canned /proc exec -----------------------------
|
||||
const serverKey = utils.generateKeyPairSync('ed25519')
|
||||
// ssh2's ed25519 keygen turns out a malformed key roughly once per few
|
||||
// hundred runs — its own parser then rejects it ("Malformed OpenSSH private
|
||||
// key"), which is enough to flake a release build's pretest. The Server
|
||||
// constructor parses hostKeys eagerly, so generate until one is accepted.
|
||||
function newHostKey() {
|
||||
for (let attempt = 0; ; attempt++) {
|
||||
const pair = utils.generateKeyPairSync('ed25519')
|
||||
try {
|
||||
new Server({ hostKeys: [pair.private] }, () => {})
|
||||
return pair
|
||||
} catch (err) {
|
||||
if (attempt >= 9) throw err
|
||||
}
|
||||
}
|
||||
}
|
||||
const serverKey = newHostKey()
|
||||
let serverPort = 0
|
||||
|
||||
// Two successive outputs with rising cpu ticks and rx/tx bytes so rates compute.
|
||||
@@ -198,6 +213,40 @@ const after = samples(openResult.id).length
|
||||
if (after !== before) fail(`stopPolling did not halt: got ${after - before} new samples`)
|
||||
console.log('[sysinfo] stopPolling halts the sample stream')
|
||||
|
||||
// ---- 5. Reference counting: split panels share one sessionId ----------------------
|
||||
// Two panels start on the same session; the poll must survive one stop and
|
||||
// only halt on the last release. Counts grow at ~5 samples/s (200ms interval),
|
||||
// so the waits below must show growth while a reference is held.
|
||||
sessionLayer.startPolling(openResult.id, 200)
|
||||
sessionLayer.startPolling(openResult.id, 200)
|
||||
const refCounted = samples(openResult.id).length
|
||||
await wait(600)
|
||||
if (samples(openResult.id).length <= refCounted) fail('shared poll (refs=2) stopped sampling')
|
||||
sessionLayer.stopPolling(openResult.id) // first panel unmounts
|
||||
const oneRef = samples(openResult.id).length
|
||||
await wait(600)
|
||||
if (samples(openResult.id).length <= oneRef) fail('poll stopped while a sibling panel still held a reference')
|
||||
console.log('[sysinfo] shared poll survives one sibling stop')
|
||||
sessionLayer.stopPolling(openResult.id) // last panel unmounts
|
||||
const zeroRefs = samples(openResult.id).length
|
||||
await wait(600)
|
||||
if (samples(openResult.id).length !== zeroRefs) fail('poll must stop only once the last reference is released')
|
||||
console.log('[sysinfo] last release stops the poll')
|
||||
// Restart after a full release must work on fresh state (no stale refs/timer).
|
||||
sessionLayer.startPolling(openResult.id, 200)
|
||||
await wait(600)
|
||||
if (samples(openResult.id).length <= zeroRefs) fail('poll did not restart cleanly after a full release')
|
||||
sessionLayer.stopPolling(openResult.id)
|
||||
console.log('[sysinfo] restart after full release works')
|
||||
// A killed session must force-stop regardless of outstanding references.
|
||||
sessionLayer.startPolling(openResult.id, 200)
|
||||
sessionLayer.startPolling(openResult.id, 200)
|
||||
sessionLayer.forceStopPolling(openResult.id)
|
||||
const forced = samples(openResult.id).length
|
||||
await wait(600)
|
||||
if (samples(openResult.id).length !== forced) fail('forceStopPolling must halt even with outstanding references')
|
||||
console.log('[sysinfo] forceStopPolling overrides outstanding references')
|
||||
|
||||
clearTimeout(timer)
|
||||
srv.close()
|
||||
console.log('[sysinfo] ALL CHECKS PASSED')
|
||||
|
||||
Reference in new issue
Block a user