- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
clap consumes the -- marker before execute for the default-signal and -s/-n forms, so kill -- -10 and kill -s TERM -- -10 previously misread the negative PID as a signal. Captured post-marker operands via a dedicated last=true field and treated a preselected -s/-n signal as closing the option position.
Added a regression covering both marker-consumed forms.
Fixes#6779
Recorded per-target PID and jobspec errors while continuing through every remaining operand, then returned a non-zero aggregate status.
Added a regression with a stale PID between two live processes.
Fixes#6779
Restricted -sigspec parsing to the option position and consumed the -- end-of-options marker, so negative PIDs (process groups) and post-marker operands are signaled rather than parsed as signals.
Added a process-group regression covering kill -TERM -- -<pgid> <pid>.
Fixes#6779
Accepted numeric signal specifications, signaled every process operand, and restored SIGTERM as the default.
Added process-level regressions for multi-target SIGKILL and graceful default termination.
Fixes#6779
Returning end-of-input from chunks::read on a disconnected receiver
also masked a panicking ext_sort sorter thread (comparator or Rayon
panic in sort_by), letting sort exit 0 with truncated or empty output.
Retain the sorter JoinHandle and join it after read_write_loop, mapping
a thread panic to an error; drop the sorted-chunk receiver first so a
still-running sorter unblocks instead of deadlocking the join. Added an
external multi-chunk sort test covering the spill-to-files join path.
Fixes#6736
The vendored uu-sort reader unwrapped the chunk-channel send at
chunks.rs:248, panicking with `SendError(..)` whenever the receiver
disconnected early (a consumer thread stopping after an error or a
closed output). Diverge from upstream: on a failed send, stop reading
gracefully and report end-of-input, matching the pattern already used
by the sorter thread. Added a regression test that drives read against
a dropped receiver.
Fixes#6736
Validate the operand with std::fs::metadata before querying its volume.
This keeps Windows stat -f from succeeding for a missing path whose
containing volume exists.
Fixes#6723
%b promised allocated 512-byte blocks but used Metadata::len() (logical
size), overstating allocation for sparse or compressed files. Query the
on-disk size via GetCompressedFileSizeW and fall back to the logical
length only when the call fails.
Fixes#6723
The vendored uu-stat routed every non-Unix invocation to a stub that
printed "stat: unsupported on this platform" and exited 1, so the bash
tool's stat builtin was dead on native Windows even though it was still
advertised and registered.
Add a Windows-native backend that reimplements the GNU stat directives on
top of std::fs::Metadata, the windows_by_handle metadata extensions
(inode, hard-link count, and device via GetFileInformationByHandle), and
the Win32 volume APIs for --file-system mode. Permission bits, file type,
and timestamps are synthesized from Windows attributes; ownership fields
that have no Windows equivalent report 0/UNKNOWN. The format parser,
printer, and BSD-compat layer are now shared across platforms and Unix
behavior is unchanged.
Fixes#6723
Drive desktop batches from a shared action, settle, and capture sequence so the regression test exercises the same ordering as DesktopWorker::execute. Add external contributor attribution to the unreleased changelog entry.
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
- find -exec/-execdir children inherited the omp process's real
stdout/stderr, spamming output into the TUI terminal and bypassing
shell redirects; they also inherited the host env instead of the
shell's exported environment.
- Added pi_uutils_ctx::run_captured (moved from uu-xargs' private
helper): stdin null, stdout streamed into scope stdout, stderr
drained on a helper thread and forwarded after exit.
- uu-find exec matchers now use env_clear + env_snapshot and
run_captured; MultiExecMatcher rebuilds a std Command from the
argmax command's accumulated state (argmax only Derefs immutably).
- uu-xargs reuses the shared helper; added pi-shell regression test
asserting -exec child stdout flows through the shell redirect with
the exported env.
- Added six builtin commands: ts, sponge, ifne, isutf8, combine, and errno to pi-shell.
- Created moreutils module with independent implementations for all tools.
- Added jiff dependency for timestamp and timezone functionality.
- Integrated builtins into shell execution pipeline with in-process execution.
- Added integration tests verifying pipe chains like ts | sponge with isutf8.
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
- Replaced puppeteer-based WebRTC with native LiveWebRtcPeer for cross-platform live audio delivery.
- Added cross-platform microphone capture via miniaudio and Opus codec integration for live encoding/decoding.
- Added Apple DeviceCheck attestation token generation via raw Objective-C FFI for macOS.
- Updated live session model to "gpt-live-1-codex" and default voice to "sol" across protocol and controller.
- Added LiveWebRtcPeer and deviceCheckGenerateToken to the public native bindings API.
- Added cmp builtin with full POSIX-compatible flag support including `-b`, `-i`, `-l`, `-s`, `-x`, `-h`, `-z`.
- Integrated into shell builtin registry and coreutils module.
- Added comprehensive tests using tempfile for temporary directories.
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
XTest input with keysym mapping) compiled into the core addon on every
published target; Linux arm64 and musl are now supported and headless
hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
build dependencies, and the now-unreferenced vendored libspa crate;
reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
XTest layouts reject negative origins and coordinates beyond 0..=32767,
batch coordinates stay bound to the frame last returned to JS with
intermediate screenshots deferred, coordinate input requires a
previously returned frame, and failed chord releases still release
every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
no input is emitted after expiry and wait-heavy batches are rejected
upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
a regular function tool with a typed GA action schema across OpenAI,
Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
- Implemented native UTF-16 text processing in Rust diff module with support for unpaired surrogates.
- Removed `similar` crate from Rust workspace and `diff` npm package from coding-agent, hashline, and natives.
- Removed jsdiff fallback wrappers and `isWellFormed()` guards from TypeScript diff implementations.
- Added comprehensive test suite for native diff functions covering random inputs and edge cases including surrogates and emoji.
- Renamed model `codex-auto-review` to `gpt-5.3-codex-spark` with updated pricing and context window.
- #6266 replaced openaiCodexModelManagerOptions' accessToken field with resolveAccounts; #6219's authoritative-pruning test predates that and silently skipped discovery, leaving the absent static model unpruned.
count_files resolved "" to the scoped cwd, so rm -r --progress with an
empty operand walked the whole working directory and inflated the
progress total even though remove() rejects the operand.
The in-process rm builtin passed each operand through
pi_uutils_ctx::resolve, which joins "" onto the shell working
directory and yields the cwd itself. rm -rf "" therefore resolved to
the cwd and recursively deleted it -- a real data-loss path when a
failed command substitution left an empty variable in a cleanup line.
Reject empty operands at the top of remove(), before resolution,
mirroring GNU rm: report ENOENT for an empty operand and stay silent
under -f. Added a regression test that runs the builtin rm -rf "" in a
scoped temp cwd and asserts the cwd and a sentinel file survive.
Fixes#6287