v0.14.2
Namespace command execution preserves separate binary stdout and stderr and decodes the command exit status through framing tied to a fresh call nonce. Native transport errors, diagnostics, incomplete records, and trailing bytes prevent acceptance of a command status. Input remains attached directly to the requested child.
Configured/exported locale values are preserved. Accepted P2 risk (E1-F1). A login-shell-local, unexported LC_ALL can become exported, and shell-maintained _ reflects the Python wrapper. No dependence on those details has been demonstrated in the admitted images or reviewed callers; unrestricted process-environment identity is not claimed.
Each command adds one Python process. Fresh native byte/status checks and overhead measurements remain separate acceptance work. The 0.14.1 bootstrap change is retained.