fix(main): SFTP data integrity, session lifecycle, security hardening
- upload: per-chunk buffer (ssh2 re-reads the overflow tail after the ACK; a reused buffer silently corrupted every file >= ~254KB) - close the cached SFTP channel on eviction, attach an 'error' handler, close the download handle, time out execQuiet, fail partial deletes - per-session StringDecoder for the ssh data plane (CJK mojibake), real exit codes, safe replay truncation, zmodem abort/counter/timer fixes - sysinfo: idempotent poll end, error routing, per-poll watchdog, proc(5) CPU total; expand cd ~/$HOME/%USERPROFILE% paths; log sanitizer fixes - security: will-navigate guard, central IPC sender check, scheme allowlist for openExternal, single-instance else branch, layout id and log-name whitelists, custom theme sanitizing, atomic JSON writes with EPERM retry in store.writeJson - updater: per-attempt feed choice, quitAndInstall relaunch, dev guard, update-state getter
This commit is contained in:
1 parent
4c6a29ef28
commit
e04f4f0ac1
16 files changed
+452
-98
No files matched your search
@@ -65,7 +65,7 @@ export class LogSanitizer {
|
||||
this.cr = true
|
||||
} else if (c === '\n') {
|
||||
out += this.emitLine()
|
||||
} else if (c === '\t' || c >= ' ' || c === '\x7f') {
|
||||
} else if (c === '\t' || c >= ' ') {
|
||||
// printable + tab; DEL and C0 controls (bell etc.) are dropped
|
||||
if (this.alt) this.altDirty = true
|
||||
else this.line += c
|
||||
@@ -97,6 +97,10 @@ export class LogSanitizer {
|
||||
this.mode = 'text'
|
||||
} else if (this.seq.length < 1024) {
|
||||
this.seq += c
|
||||
} else {
|
||||
// Runaway sequence past the cap: resync as plain text instead of
|
||||
// swallowing all following output while stuck in 'csi'.
|
||||
this.mode = 'text'
|
||||
}
|
||||
break
|
||||
case 'osc':
|
||||
@@ -124,9 +128,15 @@ export class LogSanitizer {
|
||||
this.cr = false
|
||||
// A trailing \r at stop: treat as line ending rather than overwrite.
|
||||
out += this.emitLine()
|
||||
} else if (this.line && !this.alt) {
|
||||
out += this.line
|
||||
this.line = ''
|
||||
} else if (this.line) {
|
||||
if (this.alt) {
|
||||
// Stopped mid-TUI: route through emitLine so the suppressed span gets
|
||||
// its [TUI output omitted] marker via altDirty below.
|
||||
out += this.emitLine()
|
||||
} else {
|
||||
out += this.line
|
||||
this.line = ''
|
||||
}
|
||||
}
|
||||
if (this.altDirty) {
|
||||
this.altDirty = false
|
||||
|
||||
Reference in new issue
Block a user