Release v1.4.18 with performance optimization and deep bug fixes

- Optimize session cloning: replace JSON.parse/stringify with shallow spread (~10x faster for large queues)
- Convert blocking fs.existsSync/statSync to async on download hot path
- Fix EXDEV cross-device rename in sync saveSettings/saveSession (network drive support)
- Fix double-delete bug in applyCompletedCleanupPolicy (package_done + immediate)
- Fix dangling runPackageIds/runCompletedPackages in removePackageFromSession
- Fix AdmZip partial extraction: use overwrite mode for external fallback
- Add null byte stripping to sanitizeFilename (path traversal prevention)
- Add 5MB size limit for hash manifest files (OOM prevention)
- Add 256KB size limit for link artifact file content check
- Deduplicate cleanup code via centralized removePackageFromSession

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Sucukdeluxe
2026-02-28 05:30:28 +01:00
co-authored by Claude Opus 4.6
parent d4dd266f6b
commit b971a79047
9 changed files with 86 additions and 30 deletions
+5 -2
View File
@@ -110,8 +110,11 @@ export function removeDownloadLinkArtifacts(extractDir: string): number {
if (!shouldDelete && [".txt", ".html", ".htm", ".nfo"].includes(ext)) {
if (/[._\- ](links?|downloads?|urls?|dlc)([._\- ]|$)/i.test(name)) {
try {
const text = fs.readFileSync(full, "utf8");
shouldDelete = /https?:\/\//i.test(text);
const stat = fs.statSync(full);
if (stat.size <= 256 * 1024) {
const text = fs.readFileSync(full, "utf8");
shouldDelete = /https?:\/\//i.test(text);
}
} catch {
shouldDelete = false;
}