Concurrent terminal calls in one session both source AND rewrite the shared
env snapshot. The per-command re-dump used `export -p > snap` — a non-atomic
truncate-then-write in place (the code even noted "last-writer-wins"). A
concurrent `source snap` could read a half-written file and embed literal
`declare -x` / `export` fragments into PATH, breaking `ls`/`git`/`tr` with
command-not-found until PATH was manually repaired. The corruption persisted
because the malformed env got saved back into the snapshot.
Write to a unique temp file then `mv -f` over the snapshot. `mv`/rename is
atomic on POSIX (same filesystem), so a reader always sees the old-complete or
new-complete file — never a torn one. Applied at both the init_session
bootstrap and the per-command re-dump. `$$` (bash PID) makes the temp name
unique per concurrent process so their temp writes can't collide before the mv.
Salvaged from #38279 by @kyssta-exe (authorship preserved via cherry-pick).
On top of the original I hardened the temp-path quoting: the static path is now
shlex-quoted with `$$` left outside the quotes to expand, so a snapshot path
with a space or a Windows `C:/Users/...` drive letter doesn't break the shell
(matching the existing quoting care for the snapshot path itself; `bash -n`
verified on a spaced path). Added a regression test class (atomic temp+mv used,
not in-place write; per-process-unique temp; static part quoted; bootstrap also
atomic). 22 tests pass, mutation-verified (reverting to the in-place write fails
the atomic tests), ruff clean.
Closes#38249. Supersedes #38267 (serialize-execution lock — heavier and
serializes the spawn-per-call concurrency this fix preserves).
Remove unused imports (F401) and duplicate/shadowed import
redefinitions (F811) across the codebase using ruff's safe
autofixes. No behavioral changes -- imports only.
- ~1400 safe autofixes applied across 644 files (net -1072 lines)
- __init__.py re-exports preserved (excluded from F401 removal so
public re-export surfaces stay intact)
- Re-exports that are imported or monkeypatched by tests but look
unused in their defining module are kept with explicit # noqa:
F401 (gateway/run.py load_dotenv; run_agent re-exports from
agent.message_sanitization, agent.context_compressor,
agent.retry_utils, agent.prompt_builder, agent.process_bootstrap,
agent.codex_responses_adapter)
- Unsafe F841 (unused-variable) fixes deliberately skipped -- those
can change behavior when the RHS has side effects
- ruff lints remain disabled in pyproject.toml (only PLW1514 is
selected); this is a one-time cleanup, not a config change
Verification:
- python -m compileall: clean
- pytest --collect-only: all 27161 tests collect (zero import errors)
- core entry points import clean (run_agent, model_tools, cli,
toolsets, hermes_state, batch_runner, gateway)
- static scan: every name any test imports directly from an edited
module still resolves