napi-rs 3.9.4 registers async-work `execute` at src/async_work.rs:109 as
a plain `unsafe extern "C" fn` — not `extern "C-unwind"`. Any panic
inside a `Blocking::compute` closure unwound past that boundary and
force-aborted the host process under Rust's stabilized C-unwind rules
(RFC 2945, stable since 1.81), losing the JS Promise and session state.
Wrap the user closure in `std::panic::catch_unwind` inside
`Blocking::compute` and map the panic payload to
`Error::new(Status::GenericFailure, ...)` so it flows through napi-rs's
existing rejection path (`inner_task.reject` in `complete_impl`) and
surfaces as a rejected JS Promise instead of a host abort. Every
`task::blocking` caller (grep, ast, glob, listWorkspace, html-to-markdown,
snapcompact, fuzzy find, clipboard image read) inherits the guard.
Correct the root Cargo.toml `panic = "unwind"` comment — napi-rs's
per-call `catch_unwind` only covers the tokio-future path, not the
`Task`/`AsyncTask` async-work path we use here.
Regression test in `crates/pi-natives/src/task.rs` synchronously invokes
`Blocking::compute` with panicking closures (str literal, formatted,
`panic_any`, plus Ok/Err/double-invoke controls) and asserts the returned
`napi::Error` carries the tag and payload — proving the invariant: a
panicking closure MUST NOT unwind past this method.
Fixes#4071
Propagated the native shell working directory in ShellRunResult so AgentSession can refresh cwd without running a hidden pwd command in the persistent shell.
Added regression coverage for cd plus a failing command followed by echo $?, proving cwd sync no longer overwrites the user's last shell status.
Fixes#3958
Retained only the requested AST search page window in native ast_grep/ast_match and the coding-agent multi-target wrapper while preserving exact totals.
Fixes#3935
- Replaced custom fast-walk and fs-cache implementations in pi-natives with a new dedicated pi-walker library.
- Integrated the thread-safe, parallel pi-walker library across pi-natives, pi-shell, pi-uu-grep, and uu-find.
- Rewrote file search, fuzzy finding, and glob-matching logic to leverage pi-walker configurations and visitor traits.
- Optimized shell process tracking in pi-shell by replacing global descendant-diff logic with an isolated, per-run SpawnRegistry.
- Added parallel rayon-based walking and optimized fast paths for directory scanning and entry classification.
- Added a platform-native fast filesystem traversal implementation leveraging `getattrlistbulk` on macOS, `getdents64` and `statx` on Linux, and `NtQueryDirectoryFile` on Windows.
- Integrated the fast traversal path as a preferred, high-performance fallback before standard walk operations in both cache collection and streaming search routines.
- Consolidated grep search logic by extracting a unified file-matching helper to support both standard and fast-walk execution paths.
- Introduced platform-specific Windows system dependency configurations and unit tests validating correct hidden-file filtering during scanning.
- Added Silver.ttf TrueType font support to `pi-natives` with automated fallback logic for bitmap font rendering.
- Implemented wide code point detection and cell-width calculation to improve CJK character handling and layout.
- Introduced dynamic font-aware preflight probing via `resolveShapeForText` and `renderabilityProbeText` for better font selection.
- Enabled semantic emoji folding and improved text normalization to handle non-Latin characters and emoji filtering.
- Reserved one probed Windows thread for native helper spawns before enabling Rayon's global pool.
- Treated one-spawnable-worker capacity as sequential-only so vendored sort can still create its mandatory helper thread.
- Updated regression coverage for the reserved-capacity threshold.
Fixes#3770
- Used the probed worker count instead of registering the loader thread as Rayon's only worker.
- Kept patched Rayon callsites sequential when no worker thread can be spawned.
- Guarded count_tokens and vendored sort from lazily touching the global pool in the zero-worker case.
Fixes#3770
- Configured Rayon's global pool during the post-load native runtime install.
- Fell back to a current-thread Rayon pool when the Windows spawn probe detects commit pressure.
- Added regression coverage for the Windows pool sizing decision.
Fixes#3770
The in-process grep builtin in pi-shell (backed by pi-uu-grep) shadowed /usr/bin/grep with a clap subset that rejected three universal GNU-grep flags. The common bashrc alias 'grep --color=auto' guaranteed that bare 'grep' in any pipeline failed with exit 2, and probes like 'grep --version' from shell startup scripts errored out the same way.
Add --color[=WHEN] (alias --colour) as an accepted-and-ignored flag — the builtin writes to in-process file descriptors, never a TTY, so injecting ANSI escapes would corrupt downstream consumers. Add --version routed through clap so it lands on the context stdout via the same path as --help.
Fixes#3755
- Propagated IO errors from the bounded tail internal logic to avoid panics.
- Updated `print_target_section` to return `io::Result` instead of unwrapping.
- Added a test case to verify that `BrokenPipe` is correctly surfaced when the consumer closes the pipe.
- Added `rewrite-changelog.ts` and `fix-changelogs.ts` utilities to automate the consolidation of release notes using LLM-assisted processing.
- Updated multiple internal changelog files by consolidating redundant entries and improving phrasing for readability.
- Implemented `previewLine` utility in `coding-agent` to prevent visual spillover in status rows by managing text truncation and whitespace.
- Updated `package.json` with new workflow scripts for managing package-level change histories and documentation indexes.
- Ensure `-exec` commands run in the shell current working directory rather than the host process CWD.
- Update operand path resolution in `find` matchers to use the display path, matching behavior expected by shell-integrated utilities.
- Add an integration test to verify path substitution and execution context for shell-integrated `find`.
Replace the compile-time cfg!(target_os = "macos") jamo-width heuristic
with a runtime override (process-global AtomicU8 in pi-natives, mirrored in
the TS width engine) plus terminal-identity detection: Ghostty renders
Hangul Compatibility Jamo (U+3131..U+318E) at 2 cells, so it is forced wide;
every other terminal keeps the platform default (macOS narrow, otherwise
UAX#11), making the override a no-op outside Ghostty.
Fixes doubled/ghosted jamo during Korean IME composition on Ghostty, where
the hardware cursor landed inside the typed text and the IME candidate window
drifted from the glyph. The width is resolved synchronously before the first
paint, so no stdin/CPR probe or async cache invalidation is needed.
A runtime DSR/CPR probe that auto-detects the width on unknown terminals is
tracked in a follow-up.