v0.20.0
Managed Bash commands — Contract 21
This is a forward-only breaking update to the built-in Bash tool surface.
Tool behavior
bashacceptscommand,exec_dir,stdin,auto_confirm,yield_time_ms
(integer 0–10000, default 1000), and optionaltimeout_seconds(integer 1–86400).
timeoutandrun_in_backgroundare removed, not aliases. Useyield_time_ms=0
to return immediately after launch.- Confirmed launch and running observations return a definitive
SUCCESS
tool receipt while reporting the process state separately. Checkpointed runs
can continue to the next model cycle without treating a live child as an
ambiguous tool result. check_background_commandand the newstop_background_commandaccept an
ownedsession_id. Ownership binds the task and workspace; a handle alone is
not permission to read or stop another task's process.- Execution deadlines retain the original process start and are independent of
the initial yield window and subsequent queries. Nonzero exits and timeouts
remain failures, with observed exit information rather than invented success. - Live output has a bounded preview and a recoverable immutable artifact for
oversized prefixes. Artifact persistence does not hold the session state lock
or prevent the watchdog from enforcing a deadline.
Process lifetime and platform boundary
On Linux, a dedicated per-command supervisor tracks and reaps descendants,
including descendants that detach from the initial process group. Confirmed
stop requires the managed tree to have ended. Failed or incomplete cleanup is
reported as stopping or unknown, not as a fabricated successful exit.
Complete process-tree stop confirmation is implemented and tested on Linux.
Other platforms retain their launch/capture paths but must not be treated as
having the same confirmed-tree lifecycle guarantee. Local in-memory sessions do
not provide recovery across host process restarts or distributed workers.
The generic tool executor, deferred resolution protocol, and definitive
checkpoint receipt rules are unchanged. Shared schemas and behavior are pinned
to immutable Contract 21.0.0. Existing callers must update their tool arguments
and retire old pending operations rather than replacing the frozen definition
inside an old checkpoint.
Additional correction
Python Redis controller admission verifies the checkpoint/command observation
as one consistent transaction snapshot. A competing admitted command no longer
causes a spurious failure when an admission is retried.
See docs/bash-process-management.md and docs/parity-contract.md for the
implementation boundary, paired behavior tests, and adoption requirements.