Context
std_run --timeout N promises bounded execution, but the fallback timeout implementation only sends TERM and then waits for the command. On systems without timeout or gtimeout, a command that ignores TERM can continue running past the requested timeout.
The current macOS development path commonly exercises the fallback because timeout/gtimeout may not be installed.
Reproduction
Force the fallback path by hiding timeout/gtimeout, then run a command that ignores TERM:
PATH="$fake_bin" std_run --no-exit --quiet --timeout 1 /bin/bash -c 'trap "" TERM; sleep 2'
The function returns 124, but only after the process exits naturally. A permanently stuck process would not be bounded.
Scope
- Make
std_run --timeout enforce a real runtime bound in the Bash fallback path.
- Align external
timeout/gtimeout usage with the same policy where practical.
- Use a clear
TERM then KILL escalation strategy with a short grace period.
- Add BATS coverage for a
TERM-ignoring command in the fallback path.
- Preserve existing timeout, retry, dry-run, and
std_run_with_timeout compatibility behavior.
Acceptance Criteria
- A fallback timeout returns
124 promptly for a command that ignores TERM.
- Timeout-plus-retry still treats
124 as a failed attempt and retries as before.
- Existing simple-command and successful-command behavior is unchanged.
./tests/validate.sh passes.
Context
std_run --timeout Npromises bounded execution, but the fallback timeout implementation only sendsTERMand then waits for the command. On systems withouttimeoutorgtimeout, a command that ignoresTERMcan continue running past the requested timeout.The current macOS development path commonly exercises the fallback because
timeout/gtimeoutmay not be installed.Reproduction
Force the fallback path by hiding
timeout/gtimeout, then run a command that ignoresTERM:The function returns
124, but only after the process exits naturally. A permanently stuck process would not be bounded.Scope
std_run --timeoutenforce a real runtime bound in the Bash fallback path.timeout/gtimeoutusage with the same policy where practical.TERMthenKILLescalation strategy with a short grace period.TERM-ignoring command in the fallback path.std_run_with_timeoutcompatibility behavior.Acceptance Criteria
124promptly for a command that ignoresTERM.124as a failed attempt and retries as before../tests/validate.shpasses.