Some Kata/microVM guest kernels (e.g. the CI runner's 6.18.x) are built
without CONFIG_PROC_CHILDREN, so /proc/<pid>/task/<tid>/children does not
exist. The Linux children() relied on it with no fallback, making
children()/live_descendants() return empty and silently turning shell
cancellation cleanup into a no-op inside such containers.
Fall back to scanning /proc and grouping by parent pid (the same primitive
the macOS path already uses) when no children file is readable; kernels
with the file keep the cheap per-task fast path. Also fixes
process::tests::descendants_includes_freshly_spawned_child under Kata CI.
Same containerized-CI issue as the pi-natives wrapper test: in a PID
namespace the host process's session leader lives outside the namespace,
so getsid(0) returns 0 (not -1). Relax the host_sid > 0 sanity asserts in
embedded_external_command_runs_in_its_own_session and
embedded_pipeline_stage_runs_in_its_own_session to host_sid >= 0; the
child-session invariants (own session, distinct from host) are unchanged.
- Marked heredoc redirects as unsafe for chain segmentation so commands with here-docs run via the single execution path instead of being replayed.
- Added regression tests in minimizer and shell modules covering quoted, escaped, and chained here-doc pipelines.
- Recorded the fix in the natives changelog for multi-command quoted/escaped heredoc handling.
- Added `ensure_trailing_newline_for_heredoc` to normalize commands by appending a newline for heredoc inputs missing one.
- Applied the helper in both one-shot and streaming shell execution paths before invoking `run_string`.
- Added a regression test for quoted heredocs at EOF in Unix and documented the fix in the natives changelog.
- Added a transparent_background_wrapper flag to builtin registrations and a helper constructor.
- Updated async background job creation to classify transparent wrapper builtins and launch the unwrapped command as the tracked job.
- Marked nohup as a transparent background wrapper and added a test asserting `nohup cmd &` exposes a child PID in `$!`.
- Added isMacosMallocStackLoggingEnvName() function to identify MallocStackLogging and MallocStackLoggingNoCompact variables. Updated filterProcessEnv() and Bun.env initialization to skip these variables during environment filtering. Added test case to verify malloc stack logging toggles are dropped instead of forwarded.
- Applied #[must_use] annotations across minimizer and process APIs to flag ignored return values.
- Replaced direct serde_json field reads with typed Value helper calls in several filters.
- Simplified filter parsing with chained if-let guards, rfind checks, and related cleanup.
- Updated minimizer tests and fixtures to build outputs via write! and fmt::Write.
Prevent oversized fixtures from silently triggering the size passthrough path
and causing a misleading savings-gate failure instead of a real filter failure.
Op: correct
The --format=json / --format json flag forms were not recognised by the
machine-readable opt-out; the output was parsed and rewritten as a text summary.
Extend the opt-out to cover both flag forms.
Op: correct
Restores: spec:any pip list --format=<machine-readable> output passes through unchanged
Whitespace-only lines are not markdown horizontal rules. Current callers trim
first so no live bug, but the invariant should be enforced in the function.
Op: correct
Op: correct
Restores: spec:detect_phase and detect_task return last recognised lifecycle
goal/task, not the value of a value-taking option like -pl or -p
The match_output 'ok (synced)' shortcut was not exit-gated: a rsync run
that exits non-zero but happens to emit 'total size is' without the
(?i) unless keywords would silently succeed. Add only_on_exit = [0] at
the filter level so the entire rsync def is bypassed on failure exits,
passing the raw diagnostic output through.
Op: correct
Five byte-identical private helpers across gh.rs and glab.rs
(command_has_ordered_tokens, command_has_any_token, head_tail_dedup,
is_markdown_badge_or_image, is_horizontal_rule) are now pub fn in
primitives.rs. Both callers updated to use primitives::.
Op: compress
The failure-block parser in the Gradle test filter only kept exception lines
starting with 'java.' or 'kotlin.', silently dropping JUnit5 assertion messages
(org.opentest4j.AssertionFailedError: expected...). Now any non-stack non-blank
line inside a failure block is treated as exception/message and kept.
Op: correct
detect_phase (Maven): was picking the LAST non-flag token, so 'mvn test -pl
module-a' resolved to Passthrough. Now picks the last RECOGNIZED lifecycle goal,
ignoring option-value tokens.
detect_task (Gradle): was picking the LAST non-flag non-clean token, so 'gradle
test --tests FooSpec' resolved to Other (Foo not recognized). Now picks the FIRST
recognized task token, since tasks precede option-values in gradle command lines.
Op: correct
ssh.toml: narrow Welcome-to strip to distro MOTD banners only; the broad
pattern stripped remote command output starting with that phrase.
rsync.toml: make the unless= guard case-insensitive ((?i)) and add
only_on_exit=[0] so the ok-synced shortcut doesn't fire on error exits.
gcloud.toml: delete the WARNING: access strip — combined with on_empty it
silently returned 'gcloud: ok' on auth failures.
Op: correct
In -json mode render_go_test_json_line returned Some(ok\t{pkg}) for package-level
pass events, but the Output event already carries that line, causing double counting
in aggregate_go_test_success. Return None for package-level pass events.
Also: route benchmark output (BenchmarkXxx-N lines) through head_tail instead of
the count-only aggregator, so benchmark results are preserved on exit 0.
Op: correct
df -h in containers shows the root / as an overlay filesystem. The compact_summary
filter unconditionally stripped ALL overlay rows, silently dropping container disk
usage. Now keep overlay/none rows whose mount point is /.
Op: correct
eslint -f json / --format compact etc. produce machine-readable output that
the condenser destroyed. Pass through any explicit non-stylish -f/--format.
Stylish (the default) still goes through the condenser.
Op: correct
is_rake_keep_line dropped warning: lines from rake tasks such as asset
compilation and database migrations. These carry signal (deprecation notices,
compatibility warnings) that users need to see.
Op: correct
rtk/ is absent from disk with no .gitmodules entry, so the four include_str!
calls in glab.rs pointing at rtk/tests/fixtures/ caused a compile failure on
\`--lib --tests\`. Vendor the three integration .raw files into the crate under
src/minimizer/filters/fixtures/glab/ (parallel to the existing fixtures/jvm/
pattern) and repoint all four include_str! paths.
Op: correct
Restores: test:glab_* unit tests compile
Fix P1 findings from code review:
1. ruby.rs is_rake_keep_line: replace substring contains() with
whole-word matching. "ok" matched "token", "broken", "took";
"test" matched "fastest", "contest". Now uses split_whitespace
+ exact word match.
2. glab.rs/gh.rs filter_markdown_body_view/filter_markdown_noise:
unclosed HTML comment (<!-- without -->) silently dropped ALL
remaining output. Add 50-line safety cap on comment consumption
to prevent data loss from malformed/truncated markdown.
Op: correct
Restores: invariant:filter-output-never-silently-drops-all-content
parse_ls_long_line locates the date/time anchor and reads the name as
the text after it and the size as the rightmost integer before it, so
filenames with spaces and year-form dates parse correctly.
compact_summary_output strips tmpfs/devtmpfs/overlay rows from df
output only past the 30-line passthrough threshold, keeping short
listings verbatim.
Op: correct
Restores: spec:rtk/src/cmds/system/ls.rs
filter_build_like short-circuits to 'ok (build|restore succeeded)' on
zero warnings and zero errors; the redundant defs/dotnet-build.toml
is removed and its inline tests are ported into dotnet.rs.
Op: compress
- filter_docker_logs/filter_logs now collapse repeated lines to order-
preserving '(×N)' counts via shared compact_log_lines helper.
- kubectl apply|delete|rollout|scale|create|wait|label|annotate now
route through head_tail_dedup instead of raw passthrough.
- filter_helm strips client-go glog 'W####' warnings and kube-config
permission warnings before table compaction.
- normalize_program maps standalone 'docker-compose' (v1) to 'docker'
so it routes through the docker filter with proper subcommand detection.
Op: compress
Guards that rails-migrate/rails-routes defs run standalone (not as
overlays) and that bundle exec correctly re-dispatches to wrapped
filters.
Op: extend
'bundle exec rspec|rubocop|rake|rails' now routes to the ruby/lint
filter for the wrapped tool (mirroring the uv wrapper), parsing the
command for the wrapped word since detect yields only 'exec'.
Op: extend