On macOS, libmalloc writes runtime diagnostics (e.g. "MallocStackLogging:
can't turn off malloc stack logging because it was not enabled") directly
to fd 2 of the running TUI process at arbitrary times, painting into the
viewport. The existing env-strip only protects child processes.
Add a fd-level stderr guard in pi-utils (suppressTerminalStderr /
restoreTerminalStderr) that dup2-redirects fd 2 to the omp log file while
the TUI owns the terminal, and restores it at every ownership handoff
(external editor, Ctrl+Z suspend, shutdown, crash restore). Postmortem
fatal handlers restore fd 2 before printing so crash reports stay visible.
Mirrors openai/codex#24459.
- Introduced a rejection interception mechanism to capture unhandled promise rejections from eval cell code.
- Attributed floating rejections to specific runs to fail the owning cell instead of crashing the process or worker.
- Downgraded rejections occurring after a cell finished to warn logs to prevent silent failures.
- Added markExpectedCleanupError and isExpectedCleanupError to identify and downgrade routine teardown errors to warnings.
- Updated global uncaughtException and unhandledRejection handlers to suppress process exit for tagged cleanup errors.
- Introduced a 10s execution deadline for cleanup callbacks to prevent process hanging during teardown.
- Added `safeSend` helper wrapping `Subprocess.send()` so sync throws and async EPIPE rejections cannot escape.
- Replaced inline try/catch send wrappers in STT, TTS, and tiny-title clients with shared `safeSend`.
- Added `isIpcSendEpipe` predicate and made matching rejections non-fatal in the `unhandledRejection` handler.
- Added contract tests for `safeSend` and `isIpcSendEpipe` covering sync throws, async rejections, and edge cases.
Caught asynchronous stdout error events from ProcessTerminal writes and disabled future terminal rendering instead of letting the stream error escape as an uncaught exception.
Made cleanup reentry no-op idempotently so fatal shutdown paths do not flood logs with recursive cleanup errors.
Fixes#2284
- Added a custom JSON replacer that unwraps `Error` instances in logger output, preserving name, message, stack, cause, and enumerable fields.
- Updated uncaught-exception and unhandled-rejection logging paths to pass only `{ err }`, relying on the logger serializer for full error details.
- Extended transient socket-close matching to detect HTTP2 stream reset/refused/calm errors and added regression tests for logger error serialization behavior.
- Updated plan-mode and hindsight session state lookups to use Array.findLast for selecting the latest assistant or user message.
- Updated postmortem callback iteration to use Array.toReversed before mapping cleanup callbacks.
- Renamed package directory from packages/pi-utils to packages/utils.
- Updated all path aliases and references in tsconfig.base.json to reflect new package location.
- Updated workspace references in bun.lock and package.json to point to new packages/utils directory.
- Updated documentation and build scripts to reference the renamed utils package.