Review sweep: fix real bugs found across the service + per-app + settings changes
Parallel code review of this session's changes surfaced several real bugs; fixed the substantive ones (judgment/cleanup calls held for Ed): - HIGH Clearing "remembered peers" was resurrected on the next launch: the per-profile -> global migration re-ran every startup and re-unioned the profile file's stale copy. Added a one-time AppConfig.RememberedPeersMigrated marker so migration runs once and a cleared list stays cleared. Self-test pins the clear-then-reload scenario. - MED PushModeWasapiBackend.Start rethrew on a device-open failure; nothing up the stack wraps it, so device churn (a push-eligible single WASAPI source unplugged mid-open) could crash the app. Now logs and stays stopped like MixingEngine/ASIO; the device watcher / self-heal re-open when a device returns. - MED Service self-heal: (a) the re-open "no send sources" path left PerformanceMode ON and presence up while streaming nothing - now releases cleanly; (b) the 3-attempt ladder never refunded, so 3 hiccups over a days-long stint meant permanent silence - now refunds when real audio is heard, and resets on a device hot-plug. - MED ApplyProfile resolved peers (DNS) and enumerated devices INSIDE the gate lock - a boot-time DNS hang as SYSTEM stalled Suspend()/yield/self-heal. Moved outside the lock. - LOW AudioSessionStartWatcher leaked the AudioSessionManager on every Rehook (the WASAPI handle-leak fingerprint) - now disposed. New lifecycle self-test. - LOW stale docstrings (send-all master toggle; ServiceUpdate in-place scheme; Profile .SendAllApplications "neither reads nor writes"). Gate: 42/42 (added peers-migration + session-watcher-lifecycle tests). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
4b2baa58b5
commit
984bcd042e
@@ -17,9 +17,9 @@ namespace RemSound.App;
|
||||
/// uncertainty (folder unknown, file missing mid-swap, unparseable version) means "don't act". After the
|
||||
/// copy+restart the running bin == the app version, so it never re-triggers.</para>
|
||||
///
|
||||
/// <para>Trust note: the service copies from a user-writable folder and runs it as SYSTEM — the same trust
|
||||
/// posture as the previous in-place scheme. Acceptable for this personal app; a hardened build would
|
||||
/// code-sign and verify before copying.</para>
|
||||
/// <para>Trust note: the service copies from a user-writable folder (the app's install location) and runs
|
||||
/// it as SYSTEM. That is a local-privilege-escalation surface — a hardened build would code-sign the app
|
||||
/// and verify the signature before copying. Accepted deliberately for this personal app.</para>
|
||||
/// </summary>
|
||||
internal static class ServiceUpdate
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user