Addresses a broad audit of built-in shell utilities against their real counterparts: timeout gains signal delivery, -s/-k/--preserve-status/--foreground/-v, and GNU exit codes; diff defaults to normal format and gains -w/-b/-B/-i/-c/-x/-L/-s/--strip-trailing-cr and proper -r gating; find fixes -newerXY timestamp comparison direction, anchors -regex to whole paths, and gains BSD -perm +mode, -type lists, -size T/P suffixes, -E/-x/-s flags; date gains BSD -r epoch, -v adjustments, -j -f strptime, and non-greedy -I; tail/head accept obsolete -N/+N at any position with any file count; rg resolves case flags by last occurrence and gains --path-separator and clean -0 output; stat prints integer epochs for %X/%Y/%Z and gains BSD -s/-x/-t; cksum is registered as a builtin; truncate implements -o/--io-blocks and b/= size suffixes; sleep/timeout accept infinity; yes/errno/kill accept hyphen-prefixed operands; nohup -- cmd no longer runs --; which gains BSD -s.
std::env::vars() panics the moment a host env key or value is not valid
Unicode, before any command can run. A corrupt GHOSTTY_BIN_DIR (bytes 9d d9 50)
staged by cmux/Ghostty tripped both sinks:
- pi-shell's session env copy in create_session_for_run (also merged PATH)
- brush-core's get_host_env_vars, which process builtins (sleep, timeout,
pgrep, ...) use to inherit the host env into the shells they build
Both now read via std::env::vars_os() and skip entries that cannot be decoded
as Unicode: a corrupt entry carries no usable meaning. PATH merge behavior is
unchanged. Regression tests inject a non-UTF-8 key and value and assert the
shell still starts and PATH survives.
Reported in issue #8925.
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
The leak regression waited only 100ms while the leaked job could not write its marker until a 1s sleep elapsed, so the pre-fix path passed vacuously. Wait past the delay; verified the test fails when the drop-time abort is neutralized.
Fixes#8341
Abort shell-internal background tasks when their owning session is dropped, and propagate task abortion into blocking utility cancellation so infinite writers stop.
Fixes#8341
- Synced pi-builtins bazel crate_features with cargo's resolved default
set: bazel features are literal, so the meta-features never expanded
and the procs/rg cluster (nohup, pgrep, pidwait, pkill, proc-match,
ps, rg, sleep, timeout, top) was silently compiled out, leaving the
process builtins unregistered under bazel and failing pi-shell tests.
- Repaired windows compilation of pi-builtins: cfg-gated the
uucore::mode import in mkdir, imported std::env in sort's non-unix
locale probe, mapped ProcInfo::pid through a closure in kill, brought
MetadataExt into scope in wc, and replaced stat's unstable
windows_by_handle metadata with a stable GetFileInformationByHandle
query (volume serial, link count, file index, no-dereference aware).
- Imported HashSet for pi-shell's windows-only PATH merge.
- Added a clippy-ported bazel config + CI bucket so pi-builtins keeps
its manifest-declared clippy allows under the bazel aspect while rustc
warnings stay denied, and zeroed the remaining windows-target rustc
warnings (unused params/imports in find, mv, rm, proc_match, ps).
- Add minimum character threshold to bypass minimization for short outputs.
- Add preserve-if-empty configuration and pipeline support for filters.
- Update test fixtures and integration tests to meet length thresholds.
- Added `HostProcesses` snapshot and `ChainNode` validation to track ancestry and prevent pid recycling.
- Updated process matching and signal handling to refuse signalling the shell or its ancestor processes.
- Added regression tests verifying that kill builtins safely block ancestor targeting while permitting unrelated processes.
- Added the `smallvec` dependency to support efficient process snapshot tracking.
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
Protect only the harness pid during cancellation sweeps. The host recorded parent pid can be stale on Windows and recycled onto the hung command; adding that raw pid to the protected set spared the cancellation target and pruned its whole subtree from cleanup.
Keep protected-subtree pruning rooted at the harness itself, which still spares its real workers while allowing the timed-out target to be reaped.
Fixes#7452
The flattened descendant list can contain a protected node (the
harness, on a Windows PID-reuse false-descendant) together with that
node's real children, collected by recursing through it. Skipping only
the exact protected pid kept omp alive but still TerminateProcess'd its
unrelated worker/tool subprocesses.
signal_tree/terminate_tree now drop every node whose recorded parent
chain within the enumerated set passes through a protected pid, so a
false descendant of the harness can no longer drag the harness's real
children into the kill set.
Fixes#7452
On Windows the descendant tree used to reap a cancelled bash run is
built from raw th32ParentProcessID links that outlive their recorded
parent. A recycled pid matching the harness's stale parent pid could
surface omp itself (or an ancestor) as a false descendant, and
signal_tree TerminateProcess'd it — killing the session with no
cleanup and no session_exit record when a blocking command hit its
timeout.
Add host_protected_pids() (harness pid plus its resolvable ancestor
chain) and skip those pids in signal_tree and terminate_tree. The
guard is cross-platform: a no-op on Unix, where the descendant walk is
already identity-pinned, and the safety net that keeps a tool timeout
from ever taking down the harness on Windows.
Fixes#7452
- Added the `ps` shell builtin with BSD and procps selection forms, custom formatting, and sorting capabilities.
- Implemented the `sanitize_process_command` helper to clean process command names and arguments.
- Updated the bash prompt template and package changelogs to document the new builtin.
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
SIGTERMed probe children (exit 143) on shared-core CI runners, matching
the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
unknown_lints guard for the pinned CI nightly that predates the lint.
- Made infallible ProcInfo accessors const and annotated Option-returning
accessors with allow(unnecessary_wraps) since Option is the shared
cross-platform contract.
- Boxed ParseProcResult::Options to shrink the enum.
- Restructured kill signal resolution to bind signal once instead of
let-then-reassign sequences.
- Simplified liveness re-check with Option::is_none_or.
- Implemented new shell builtins including `top`, `pgrep`, `pkill`, `pidwait`, and `kill`.
- Added a cross-platform process snapshot module supporting Linux, macOS, and Windows.
- Extended job and process handling utilities with process iteration and handle termination methods.
- Replaced test mutex locks with thread-local counters to prevent test races in the minimizer engine.
- Updated the nightly rust toolchain channel in rust-toolchain.toml to nightly-2026-07-28.
- Adopted slice chunking and multiple-of helper methods across native and vendor crates.
- Replaced option map adapters and conditional patterns with idiomatic combinators.
- Add conditional attributes to silence dead-code warnings on platform-specific code and fields.
- Update target dependencies in pi-walker/Cargo.toml with explicit windows-sys feature sets.
- Simplify time cast expressions in linux_reflink and rcopy modules.
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
clap consumes the -- marker before execute for the default-signal and -s/-n forms, so kill -- -10 and kill -s TERM -- -10 previously misread the negative PID as a signal. Captured post-marker operands via a dedicated last=true field and treated a preselected -s/-n signal as closing the option position.
Added a regression covering both marker-consumed forms.
Fixes#6779
Recorded per-target PID and jobspec errors while continuing through every remaining operand, then returned a non-zero aggregate status.
Added a regression with a stale PID between two live processes.
Fixes#6779
Restricted -sigspec parsing to the option position and consumed the -- end-of-options marker, so negative PIDs (process groups) and post-marker operands are signaled rather than parsed as signals.
Added a process-group regression covering kill -TERM -- -<pgid> <pid>.
Fixes#6779
Accepted numeric signal specifications, signaled every process operand, and restored SIGTERM as the default.
Added process-level regressions for multi-target SIGKILL and graceful default termination.
Fixes#6779
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
- find -exec/-execdir children inherited the omp process's real
stdout/stderr, spamming output into the TUI terminal and bypassing
shell redirects; they also inherited the host env instead of the
shell's exported environment.
- Added pi_uutils_ctx::run_captured (moved from uu-xargs' private
helper): stdin null, stdout streamed into scope stdout, stderr
drained on a helper thread and forwarded after exit.
- uu-find exec matchers now use env_clear + env_snapshot and
run_captured; MultiExecMatcher rebuilds a std Command from the
argmax command's accumulated state (argmax only Derefs immutably).
- uu-xargs reuses the shared helper; added pi-shell regression test
asserting -exec child stdout flows through the shell redirect with
the exported env.
- Added six builtin commands: ts, sponge, ifne, isutf8, combine, and errno to pi-shell.
- Created moreutils module with independent implementations for all tools.
- Added jiff dependency for timestamp and timezone functionality.
- Integrated builtins into shell execution pipeline with in-process execution.
- Added integration tests verifying pipe chains like ts | sponge with isutf8.
- Added cmp builtin with full POSIX-compatible flag support including `-b`, `-i`, `-l`, `-s`, `-x`, `-h`, `-z`.
- Integrated into shell builtin registry and coreutils module.
- Added comprehensive tests using tempfile for temporary directories.
Brace expansion joined its results with spaces and re-parsed them as a single word, so tilde-at-word-start only fired on the leading element. Now each brace element is expanded as its own word, so `~/project/{a,b}` expands both tildes instead of leaving a literal `~/project/b`.
Fixes#5819
- Delayed reader cancellation so pipeline consumers can flush after producers are terminated.
- Kept the JavaScript watchdog behind bounded native timeout cleanup.
- Added native and executor regressions for timeout-time output draining.
Fixes#5316
- Rewrote logical /dev/fd operands to live OS descriptors before invoking in-process uutils.
- Added regression coverage for diff reading two process substitutions.
Fixes#5557
- Updated `run_fd_sync` to handle `io::ErrorKind::BrokenPipe` by returning exit code `141` without writing an error message.
- Added a regression test that verifies `fd` exits with `141` and empty stderr when stdout is closed early (e.g. `fd ... | head` scenario).
- Recorded the broken-pipe behavior fix in `packages/coding-agent/CHANGELOG.md`.
- Integrated 17 new coreutils-based shell builtins including `diff`, `date`, `ln`, `stat`, `seq`, `touch`, and others.
- Refactored vendored utilities to execute as in-process shell builtins by routing I/O, environment access, and path resolution through `pi_uutils_ctx`.
- Disabled process-level modifications (e.g., clock setting, hostname modification) to ensure safety and scope adherence within the shell environment.
- Implemented shell-specific features such as cancellation polling, custom exit code management, and efficient output streaming for all new builtins.
- Added base64, checksum utilities (md5, sha1, sha224, sha256, sha384, sha512, b2sum), path utilities (basename, dirname), and text processing tools (cut, tee, tr, paste, comm) to the shell.
- Registered new utility builtins in crates/pi-shell/src/coreutils.rs and crates/pi-shell/src/shell.rs.
- Updated Cargo.toml to include the necessary dependencies for the new core utilities.