fix: hardening round from code review (4 P1 + 15 P2)
CI / typecheck + test + build (windows) (push) Canceled after 0s
CI / typecheck + test + build (windows) (push) Canceled after 0s
P1: - settingsStore: back up an unparseable settings.json to .bak before falling back to defaults, so the next mutation can no longer silently wipe custom themes/highlight rules - ptyDispatcher: fan out per-session data/exit handlers (Set instead of a single slot) so SSH split panes stop stealing each other's stream - FilePanel: monotonic refresh token keeps stale listings from painting over a newer navigation; upload finish no longer yanks the panel back - settings.css: active settings-tab label derives from --chrome-fg so it stays visible on the shipped light themes P2 (main/renderer): - paste guard: a paste ending in a newline always confirms - Workspace: closing an SSH pane no longer seeds the local cwd with a remote path - tray: skip close-dialog continuation on a destroyed window - commands: close zombie 'in-progress' session logs at hydrate - zmodem: clear the stale offer timer before arming a new one - connectionsStore: coerce/validate renderer input before persisting - sftp: OperationError marker class keeps translated errors out of the transport-retry classifier - CommandsPanel: surface save failures inside the dialog - ConnectionSidebar: drop a tautological tooltip condition P2 (i18n/tooling/tests): - localize the 16 ANSI color labels and the highlight sample text (21 new keys across zh-CN/zh-TW/en/ja) - sync-changelog: keep ### subheadings, normalize CRLF notes - release.cjs: GitHub release reuse-by-tag (idempotent re-runs); fail loudly on a failed Gitea asset listing - commands-store test: absent historyEnabled now truly tests absence
This commit is contained in:
1 parent
33efbe921e
commit
4e5377f49c
27 files changed
+356
-83
No files matched your search
+18
-3
@@ -65,6 +65,14 @@ const sftpCache = new Map<string, SFTPWrapper>()
|
||||
*/
|
||||
class SessionGoneError extends Error {}
|
||||
|
||||
/**
|
||||
* Our own "operation failed for a non-transport reason" error (server-side
|
||||
* failure summary, user cancellation). isTransportError rejects these outright:
|
||||
* their messages are translated and can embed remote paths/output, so text
|
||||
* matching would make the retry decision locale- and filename-dependent.
|
||||
*/
|
||||
class OperationError extends Error {}
|
||||
|
||||
async function sftpOf(sessionId: string): Promise<SFTPWrapper> {
|
||||
const cached = sftpCache.get(sessionId)
|
||||
if (cached) return cached
|
||||
@@ -100,9 +108,16 @@ function evictSftp(sessionId: string): void {
|
||||
* already exists) mean the CHANNEL IS ALIVE — retrying them would just open
|
||||
* another subsystem channel, which strict sshd (MaxSessions 2) punishes by
|
||||
* dropping the whole connection. Only transport-level death retries.
|
||||
*
|
||||
* Classification is class-based for our own errors (SessionGoneError /
|
||||
* OperationError) and matches only the ssh2 library's own message strings for
|
||||
* the rest: ssh2 is English-only and never translated, so the decision cannot
|
||||
* drift with the UI locale (our translated messages arrive as OperationError
|
||||
* and are rejected before any text is inspected).
|
||||
*/
|
||||
function isTransportError(err: unknown): boolean {
|
||||
if (err instanceof SessionGoneError) return true
|
||||
if (err instanceof OperationError) return false
|
||||
const msg = (err as Error | undefined)?.message ?? ''
|
||||
return /not connected|ECONNRESET|EPIPE|timed out|disconnected|channel|read past end|no response/i.test(msg)
|
||||
}
|
||||
@@ -211,7 +226,7 @@ export function deleteRemote(sessionId: string, paths: string[]): Promise<void>
|
||||
}
|
||||
}
|
||||
if (failures.length > 0) {
|
||||
throw new Error(t('main.sftp.deleteFailed', { detail: failures.join('; ') }))
|
||||
throw new OperationError(t('main.sftp.deleteFailed', { detail: failures.join('; ') }))
|
||||
}
|
||||
})
|
||||
}
|
||||
@@ -329,7 +344,7 @@ export function uploadRemote(
|
||||
let pos = 0
|
||||
let lastEmit = 0
|
||||
for (;;) {
|
||||
if (transfer.cancelled) throw new Error(t('main.sftp.cancelled'))
|
||||
if (transfer.cancelled) throw new OperationError(t('main.sftp.cancelled'))
|
||||
if (firstError) throw firstError
|
||||
while (inflight.size >= UPLOAD_WINDOW) {
|
||||
await Promise.race(inflight)
|
||||
@@ -420,7 +435,7 @@ export function downloadRemote(
|
||||
let lastEmit = 0
|
||||
const buf = Buffer.alloc(CHUNK)
|
||||
for (;;) {
|
||||
if (transfer.cancelled) throw new Error(t('main.sftp.cancelled'))
|
||||
if (transfer.cancelled) throw new OperationError(t('main.sftp.cancelled'))
|
||||
const { bytesRead } = await p<{ bytesRead: number; buffer: Buffer }>(cb =>
|
||||
sftp.read(handle, buf, 0, CHUNK, pos, cb)
|
||||
)
|
||||
|
||||
Reference in new issue
Block a user