Skip to content

fix: protect checksum workers and GUI garbage collection - #15

Open
lukisch wants to merge 8 commits into
masterfrom
fix/codex-checksum-close-lifecycle-20261001
Open

lukisch wants to merge 8 commits into
masterfrom
fix/codex-checksum-close-lifecycle-20261001

Conversation

@lukisch

@lukisch lukisch commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Keep the checksum dialog and its native worker alive until the worker has actually stopped.
  • Run cyclic Qt-object cleanup on the GUI thread; initialize the timer before disabling automatic collection and restore the original GC state even when shutdown cleanup raises.
  • Close the GUI collector if any application setup after installation fails.
  • Preserve the current master changelog entry alongside the checksum and GUI-GC entry.

Validation

  • Focused checksum and GUI-GC tests: 25 passed.
  • Full local suite: 416 passed, 2 skipped. Release smoke needs a locally built EXE; screenshot smoke needs a native Qt platform and was skipped with the offscreen platform.
  • Translation check: 356 strings complete in all six languages.
  • Ruff, compileall, and diff checks passed.
  • GitHub CI and CodeQL for this updated head are pending.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Welcome! Thanks for your first pull request in this repository.

A maintainer will review it soon. Please make sure:

  • Your changes are tested
  • Documentation is updated if needed
  • The PR description explains what changed and why

Thanks for contributing.

@lukisch lukisch changed the title fix: close checksum dialog after native worker has joined fix: protect checksum workers and GUI garbage collection Oct 1, 2026
lukisch and others added 3 commits October 1, 2026 20:00

@lukisch lukisch left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Zweitmodell-Review: CI grün (12/12), derselbe Sicherheitsbefund wie in #14.

1. Befehlsinjektion beim Terminal-Start (src/core/platform_utils.py, get_terminal_command)
Der Verzeichnisname wird in powershell -Command "Set-Location -LiteralPath '{directory}'" und cmd /K "cd /d {directory}" interpoliert. Ein Ordnername mit ' oder & (unter Windows zulässig) führt zu Codeausführung. Popen(..., cwd=target_dir) setzt das Arbeitsverzeichnis bereits, die Interpolation kann entfallen:

if shutil.which("powershell"):
    return ["powershell", "-NoExit"]
return ["cmd", "/K"]

Dazu ein Test mit einem Ordner a'b&c.

2. Überlappung
Der Inhalt ist (bis auf die Laufwerkskapazität) in #14 enthalten, batch_rename_service, checksum_dialog, gui_gc und properties_dialog sind in beiden PRs identisch oder fast identisch. Es sollte nur eine der beiden Varianten gemergt werden, sonst Konflikte.

Sonst: Tests für Batch-Rename-Rollback, Properties-Dialog und Terminal vorhanden. Keine Credentials oder Nutzerpfade im Diff.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant