_startup_login's background thread and _handle_authenticate's shared the module-level _login_result_queue with no correlation. Since _startup_login can now time out at 10s while its thread keeps running (from the previous fix in this wave), a slow-cold-starting subprocess's first explicit "Connect to Garmin" call could accidentally dequeue the startup thread's stale result instead of its own fresh one, orphaning the loser's result to corrupt a later authenticate/complete_mfa call. _handle_authenticate and _handle_complete_mfa still correctly share _login_result_queue -- they're two halves of one explicit, MFA-capable login flow. _startup_login is a background tokenstore resume with no MFA involved, so it now uses its own private, function-local queue.Queue() instead, making cross-contamination structurally impossible. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
8.5 KiB
8.5 KiB