Release v1.4.18 with performance optimization and deep bug fixes
- Optimize session cloning: replace JSON.parse/stringify with shallow spread (~10x faster for large queues) - Convert blocking fs.existsSync/statSync to async on download hot path - Fix EXDEV cross-device rename in sync saveSettings/saveSession (network drive support) - Fix double-delete bug in applyCompletedCleanupPolicy (package_done + immediate) - Fix dangling runPackageIds/runCompletedPackages in removePackageFromSession - Fix AdmZip partial extraction: use overwrite mode for external fallback - Add null byte stripping to sanitizeFilename (path traversal prevention) - Add 5MB size limit for hash manifest files (OOM prevention) - Add 256KB size limit for link artifact file content check - Deduplicate cleanup code via centralized removePackageFromSession Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
d4dd266f6b
commit
b971a79047
@@ -52,6 +52,10 @@ export function readHashManifest(packageDir: string): Map<string, ParsedHashEntr
|
||||
const filePath = path.join(packageDir, entry.name);
|
||||
let lines: string[];
|
||||
try {
|
||||
const stat = fs.statSync(filePath);
|
||||
if (stat.size > 5 * 1024 * 1024) {
|
||||
continue;
|
||||
}
|
||||
lines = fs.readFileSync(filePath, "utf8").split(/\r?\n/);
|
||||
} catch {
|
||||
continue;
|
||||
|
||||
Reference in New Issue
Block a user