7f7f0c2ecb
write_all() loops until the full buffer is transferred — os.write's return value was ignored at the payload write and in the pump loop, so a short write silently truncated the stream. EPIPE at the payload write (child already dead) now reaps the child and inherits its status instead of dying with a BrokenPipeError traceback; EPIPE in the pump loop falls through to the same waitpid, which is standard `cmd | head` semantics. Tests use deterministic fault injection rather than racing signals: a fork wrapper that waits with waitid(WNOWAIT) so the child is provably dead but still reapable before the parent writes, and an os.write cap of 7 bytes per call as the stand-in for a signal-interrupted partial write. Reviewed three times. Known gaps, tracked, NOT fixed here: signal-killed children still collapse to exit 1 (no 128+WTERMSIG), and the pump loop's `except OSError: pass` is broader than it should be. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>