Skip to content

SherlockEQ 1.0.2

Choose a tag to compare

@smbrownai smbrownai released this 02 Aug 13:31
· 7 commits to main since this release

SherlockEQ 1.0.2

A maintenance release: one robustness fix for importing files, and two security-hardening changes under the hood. How you use the app doesn't change, and no settings move.

Fixed

  • A very large or unexpected import file can no longer freeze the app. When you import a headphone-correction file, a profile, or an audiogram, SherlockEQ now checks the file first and reads at most 8 MB. Before, pointing the importer at an unusually large file — or at something that wasn't really one of those files — could lock up the window while the whole thing was read. Imports now stop early and show a clear message instead of hanging. Real correction files, profiles, and audiograms are only a few kilobytes, so ordinary imports are unaffected.

Security

Two defense-in-depth changes. Neither responds to any known problem in the field; they close small gaps found in an internal review.

  • Headphone-correction downloads stay on GitHub. When SherlockEQ fetches an AutoEQ headphone-correction profile, it now refuses any redirect that would send the request to a server outside GitHub's content host. That keeps an intercepted or misbehaving response from sourcing correction data from somewhere unexpected. Downloads that stay on GitHub — the normal case — work exactly as before.
  • The command-line tool's profile import is hardened against symlink swaps. The optional sherlockeq command-line helper imports a profile from a path you give it. It now opens that file without following a symbolic link, closing a brief window in which the path could be swapped between the safety check and the read. This affects only the command-line tool; the app's own Import… button is unchanged.

Not a medical device

SherlockEQ is not a healthcare or medical application. It does not diagnose, treat, measure, or monitor any hearing condition, tinnitus, or disability. For concerns about your hearing, consult a doctor, audiologist, or licensed healthcare professional.

Previous release

See the 1.0.1 release notes for what shipped in the prior version.