hush: fix more obscure ${var%...} cases
[oweals/busybox.git] / shell / hush.c
index f8f7482b18fedaa74704786eee41dce114a9cb7e..32b90876fde26c265a53b61af9678d9ca8661173 100644 (file)
@@ -5,7 +5,8 @@
  * "small and simple is beautiful" philosophy, which
  * incidentally is a good match to today's BusyBox.
  *
- * Copyright (C) 2000,2001  Larry Doolittle  <larry@doolittle.boa.org>
+ * Copyright (C) 2000,2001  Larry Doolittle <larry@doolittle.boa.org>
+ * Copyright (C) 2008,2009  Denys Vlasenko <vda.linux@googlemail.com>
  *
  * Credits:
  *      The parser routines proper are all original material, first
@@ -20,8 +21,8 @@
  *      rewrites.
  *
  * Other credits:
- *      o_addchr() derived from similar w_addchar function in glibc-2.2.
- *      setup_redirect(), redirect_opt_num(), and big chunks of main()
+ *      o_addchr derived from similar w_addchar function in glibc-2.2.
+ *      parse_redirect, redirect_opt_num, and big chunks of main
  *      and many builtins derived from contributions by Erik Andersen.
  *      Miscellaneous bugfixes from Matt Kraai.
  *
  * handle the recursion implicit in the various substitutions, especially
  * across continuation lines.
  *
- * POSIX syntax not implemented:
+ * TODOs:
+ *      grep for "TODO" and fix (some of them are easy)
+ *      special variables (done: PWD, PPID, RANDOM)
+ *      tilde expansion
  *      aliases
- *      <(list) and >(list) Process Substitution
- *      Here Documents ( << word )
- *      Functions
- *      Tilde Expansion
- *      Parameter Expansion for substring processing ${var#word} ${var%word}
- *
- * Bash stuff maybe optional enable:
- *      &> and >& redirection of stdout+stderr
- *      Brace expansion
- *      reserved words: [[ ]] function select
- *      substrings ${var:1:5}
- *
- * Major bugs:
- *      job handling woefully incomplete and buggy (improved --vda)
- * to-do:
- *      port selected bugfixes from post-0.49 busybox lash - done?
- *      change { and } from special chars to reserved words
- *      builtins: return, trap, ulimit
- *      test magic exec with redirection only
  *      follow IFS rules more precisely, including update semantics
- *      figure out what to do with backslash-newline
- *      propagate syntax errors, die on resource errors?
- *      continuation lines, both explicit and implicit - done?
+ *      builtins mandated by standards we don't support:
+ *          [un]alias, command, fc, getopts, newgrp, readonly, times
+ *      make complex ${var%...} constructs support optional
+ *      make here documents optional
+ *
+ * Bash compat TODO:
+ *      redirection of stdout+stderr: &> and >&
+ *      brace expansion: one/{two,three,four}
+ *      reserved words: function select
+ *      advanced test: [[ ]]
+ *      process substitution: <(list) and >(list)
+ *      =~: regex operator
+ *      let EXPR [EXPR...]
+ *          Each EXPR is an arithmetic expression (ARITHMETIC EVALUATION)
+ *          If the last arg evaluates to 0, let returns 1; 0 otherwise.
+ *          NB: let `echo 'a=a + 1'` - error (IOW: multi-word expansion is used)
+ *      ((EXPR))
+ *          The EXPR is evaluated according to ARITHMETIC EVALUATION.
+ *          This is exactly equivalent to let "EXPR".
+ *      $[EXPR]: synonym for $((EXPR))
+ *      export builtin should be special, its arguments are assignments
+ *          and therefore expansion of them should be "one-word" expansion:
+ *              $ export i=`echo 'a  b'` # export has one arg: "i=a  b"
+ *          compare with:
+ *              $ ls i=`echo 'a  b'`     # ls has two args: "i=a" and "b"
+ *              ls: cannot access i=a: No such file or directory
+ *              ls: cannot access b: No such file or directory
+ *          Note1: same applies to local builtin.
+ *          Note2: bash 3.2.33(1) does this only if export word itself
+ *          is not quoted:
+ *              $ export i=`echo 'aaa  bbb'`; echo "$i"
+ *              aaa  bbb
+ *              $ "export" i=`echo 'aaa  bbb'`; echo "$i"
+ *              aaa
  *
  * Licensed under the GPL v2 or later, see the file LICENSE in this tarball.
  */
-
-#include "busybox.h" /* for APPLET_IS_NOFORK/NOEXEC */
-//TODO: pull in some .h and find out whether we have SINGLE_APPLET_MAIN?
-//#include "applet_tables.h" doesn't work
+#include "busybox.h"  /* for APPLET_IS_NOFORK/NOEXEC */
+#include <malloc.h>   /* for malloc_trim */
 #include <glob.h>
 /* #include <dmalloc.h> */
 #if ENABLE_HUSH_CASE
-#include <fnmatch.h>
+# include <fnmatch.h>
 #endif
+
+#include "shell_common.h"
+#include "builtin_read.h"
+#include "builtin_ulimit.h"
 #include "math.h"
+#include "match.h"
+#if ENABLE_HUSH_RANDOM_SUPPORT
+# include "random.h"
+#else
+# define CLEAR_RANDOM_T(rnd) ((void)0)
+#endif
+#ifndef PIPE_BUF
+# define PIPE_BUF 4096  /* amount of buffering in a pipe */
+#endif
 
-#ifdef WANT_TO_TEST_NOMMU
+
+/* Build knobs */
+#define LEAK_HUNTING 0
+#define BUILD_AS_NOMMU 0
+/* Enable/disable sanity checks. Ok to enable in production,
+ * only adds a bit of bloat. Set to >1 to get non-production level verbosity.
+ * Keeping 1 for now even in released versions.
+ */
+#define HUSH_DEBUG 1
+/* Slightly bigger (+200 bytes), but faster hush.
+ * So far it only enables a trick with counting SIGCHLDs and forks,
+ * which allows us to do fewer waitpid's.
+ * (we can detect a case where neither forks were done nor SIGCHLDs happened
+ * and therefore waitpid will return the same result as last time)
+ */
+#define ENABLE_HUSH_FAST 0
+
+
+#if BUILD_AS_NOMMU
 # undef BB_MMU
 # undef USE_FOR_NOMMU
 # undef USE_FOR_MMU
 # define USE_FOR_MMU(...)
 #endif
 
-#define HUSH_VER_STR "0.93"
-
-#if defined SINGLE_APPLET_MAIN
+#define SKIP_definitions 1
+#include "applet_tables.h"
+#undef SKIP_definitions
+#if NUM_APPLETS == 1
 /* STANDALONE does not make sense, and won't compile */
-#undef CONFIG_FEATURE_SH_STANDALONE
-#undef ENABLE_FEATURE_SH_STANDALONE
-#undef USE_FEATURE_SH_STANDALONE
-#define SKIP_FEATURE_SH_STANDALONE(...) __VA_ARGS__
-#define ENABLE_FEATURE_SH_STANDALONE 0
-#define USE_FEATURE_SH_STANDALONE(...)
-#define SKIP_FEATURE_SH_STANDALONE(...) __VA_ARGS__
+# undef CONFIG_FEATURE_SH_STANDALONE
+# undef ENABLE_FEATURE_SH_STANDALONE
+# undef IF_FEATURE_SH_STANDALONE
+# undef IF_NOT_FEATURE_SH_STANDALONE
+# define ENABLE_FEATURE_SH_STANDALONE 0
+# define IF_FEATURE_SH_STANDALONE(...)
+# define IF_NOT_FEATURE_SH_STANDALONE(...) __VA_ARGS__
 #endif
 
 #if !ENABLE_HUSH_INTERACTIVE
-#undef ENABLE_FEATURE_EDITING
-#define ENABLE_FEATURE_EDITING 0
-#undef ENABLE_FEATURE_EDITING_FANCY_PROMPT
-#define ENABLE_FEATURE_EDITING_FANCY_PROMPT 0
+# undef ENABLE_FEATURE_EDITING
+# define ENABLE_FEATURE_EDITING 0
+# undef ENABLE_FEATURE_EDITING_FANCY_PROMPT
+# define ENABLE_FEATURE_EDITING_FANCY_PROMPT 0
 #endif
 
 /* Do we support ANY keywords? */
 #if ENABLE_HUSH_IF || ENABLE_HUSH_LOOPS || ENABLE_HUSH_CASE
-#define HAS_KEYWORDS 1
-#define IF_HAS_KEYWORDS(...) __VA_ARGS__
-#define IF_HAS_NO_KEYWORDS(...)
+# define HAS_KEYWORDS 1
+# define IF_HAS_KEYWORDS(...) __VA_ARGS__
+# define IF_HAS_NO_KEYWORDS(...)
 #else
-#define HAS_KEYWORDS 0
-#define IF_HAS_KEYWORDS(...)
-#define IF_HAS_NO_KEYWORDS(...) __VA_ARGS__
+# define HAS_KEYWORDS 0
+# define IF_HAS_KEYWORDS(...)
+# define IF_HAS_NO_KEYWORDS(...) __VA_ARGS__
 #endif
 
-/* Keep unconditionally on for now */
-#define HUSH_DEBUG 1
-/* In progress... */
-#define ENABLE_HUSH_FUNCTIONS 0
-
-
 /* If you comment out one of these below, it will be #defined later
  * to perform debug printfs to stderr: */
 #define debug_printf(...)        do {} while (0)
 #define debug_printf_subst(...)  do {} while (0)
 #define debug_printf_clean(...)  do {} while (0)
 
-#ifndef debug_printf
-#define debug_printf(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_parse
-#define debug_printf_parse(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_exec
-#define debug_printf_exec(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_env
-#define debug_printf_env(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_jobs
-#define debug_printf_jobs(...) fprintf(stderr, __VA_ARGS__)
-#define DEBUG_JOBS 1
-#else
-#define DEBUG_JOBS 0
-#endif
-
-#ifndef debug_printf_expand
-#define debug_printf_expand(...) fprintf(stderr, __VA_ARGS__)
-#define DEBUG_EXPAND 1
-#else
-#define DEBUG_EXPAND 0
-#endif
-
-#ifndef debug_printf_glob
-#define debug_printf_glob(...) fprintf(stderr, __VA_ARGS__)
-#define DEBUG_GLOB 1
-#else
-#define DEBUG_GLOB 0
-#endif
-
-#ifndef debug_printf_list
-#define debug_printf_list(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_subst
-#define debug_printf_subst(...) fprintf(stderr, __VA_ARGS__)
-#endif
-
-#ifndef debug_printf_clean
-/* broken, of course, but OK for testing */
-static const char *indenter(int i)
-{
-       static const char blanks[] ALIGN1 =
-               "                                    ";
-       return &blanks[sizeof(blanks) - i - 1];
-}
-#define debug_printf_clean(...) fprintf(stderr, __VA_ARGS__)
-#define DEBUG_CLEAN 1
-#endif
-
-#if DEBUG_EXPAND
-static void debug_print_strings(const char *prefix, char **vv)
-{
-       fprintf(stderr, "%s:\n", prefix);
-       while (*vv)
-               fprintf(stderr, " '%s'\n", *vv++);
-}
-#else
-#define debug_print_strings(prefix, vv) ((void)0)
-#endif
-
-/*
- * Leak hunting. Use hush_leaktool.sh for post-processing.
- */
-#ifdef FOR_HUSH_LEAKTOOL
-static void *xxmalloc(int lineno, size_t size)
-{
-       void *ptr = xmalloc((size + 0xff) & ~0xff);
-       fdprintf(2, "line %d: malloc %p\n", lineno, ptr);
-       return ptr;
-}
-static void *xxrealloc(int lineno, void *ptr, size_t size)
-{
-       ptr = xrealloc(ptr, (size + 0xff) & ~0xff);
-       fdprintf(2, "line %d: realloc %p\n", lineno, ptr);
-       return ptr;
-}
-static char *xxstrdup(int lineno, const char *str)
-{
-       char *ptr = xstrdup(str);
-       fdprintf(2, "line %d: strdup %p\n", lineno, ptr);
-       return ptr;
-}
-static void xxfree(void *ptr)
-{
-       fdprintf(2, "free %p\n", ptr);
-       free(ptr);
-}
-#define xmalloc(s)     xxmalloc(__LINE__, s)
-#define xrealloc(p, s) xxrealloc(__LINE__, p, s)
-#define xstrdup(s)     xxstrdup(__LINE__, s)
-#define free(p)        xxfree(p)
-#endif
-
-
 #define ERR_PTR ((void*)(long)1)
 
-static const char hush_version_str[] ALIGN1 = "HUSH_VERSION="HUSH_VER_STR;
-
 #define JOB_STATUS_FORMAT "[%d] %-22s %.40s\n"
 
 #define SPECIAL_VAR_SYMBOL 3
 
-typedef enum redir_type {
-       REDIRECT_INPUT     = 1,
-       REDIRECT_OVERWRITE = 2,
-       REDIRECT_APPEND    = 3,
-       REDIRECT_HEREIS    = 4,
-       REDIRECT_IO        = 5
-} redir_type;
+struct variable;
 
-/* The descrip member of this structure is only used to make
- * debugging output pretty */
-static const struct {
-       int mode;
-       signed char default_fd;
-       char descrip[3];
-} redir_table[] = {
-       { 0,                         0, "()" },
-       { O_RDONLY,                  0, "<"  },
-       { O_CREAT|O_TRUNC|O_WRONLY,  1, ">"  },
-       { O_CREAT|O_APPEND|O_WRONLY, 1, ">>" },
-       { O_RDONLY,                 -1, "<<" },
-       { O_RDWR,                    1, "<>" }
-};
+static const char hush_version_str[] ALIGN1 = "HUSH_VERSION="BB_VER;
 
-typedef enum pipe_style {
-       PIPE_SEQ = 1,
-       PIPE_AND = 2,
-       PIPE_OR  = 3,
-       PIPE_BG  = 4,
-} pipe_style;
+/* This supports saving pointers malloced in vfork child,
+ * to be freed in the parent.
+ */
+#if !BB_MMU
+typedef struct nommu_save_t {
+       char **new_env;
+       struct variable *old_vars;
+       char **argv;
+       char **argv_from_re_execing;
+} nommu_save_t;
+#endif
 
 typedef enum reserved_style {
        RES_NONE  = 0,
@@ -297,9 +219,10 @@ typedef enum reserved_style {
 #endif
 #if ENABLE_HUSH_CASE
        RES_CASE  ,
-       /* two pseudo-keywords support contrived "case" syntax: */
-       RES_MATCH , /* "word)" */
-       RES_CASEI , /* "this command is inside CASE" */
+       /* three pseudo-keywords support contrived "case" syntax: */
+       RES_CASE_IN,   /* "case ... IN", turns into RES_MATCH when IN is observed */
+       RES_MATCH ,    /* "word)" */
+       RES_CASE_BODY, /* "this command is inside CASE" */
        RES_ESAC  ,
 #endif
        RES_XXXX  ,
@@ -314,7 +237,9 @@ typedef struct o_string {
         * (by prepending \ to *, ?, [, \) */
        smallint o_escape;
        smallint o_glob;
-       smallint nonnull;
+       /* At least some part of the string was inside '' or "",
+        * possibly empty one: word"", wo''rd etc. */
+       smallint o_quoted;
        smallint has_empty_slot;
        smallint o_assignment; /* 0:maybe, 1:yes, 2:no */
 } o_string;
@@ -339,48 +264,123 @@ typedef struct in_str {
        smallint promptmode; /* 0: PS1, 1: PS2 */
 #endif
        FILE *file;
-       int (*get) (struct in_str *);
-       int (*peek) (struct in_str *);
+       int (*get) (struct in_str *) FAST_FUNC;
+       int (*peek) (struct in_str *) FAST_FUNC;
 } in_str;
 #define i_getch(input) ((input)->get(input))
 #define i_peek(input) ((input)->peek(input))
 
+/* The descrip member of this structure is only used to make
+ * debugging output pretty */
+static const struct {
+       int mode;
+       signed char default_fd;
+       char descrip[3];
+} redir_table[] = {
+       { O_RDONLY,                  0, "<"  },
+       { O_CREAT|O_TRUNC|O_WRONLY,  1, ">"  },
+       { O_CREAT|O_APPEND|O_WRONLY, 1, ">>" },
+       { O_CREAT|O_RDWR,            1, "<>" },
+       { O_RDONLY,                  0, "<<" },
+/* Should not be needed. Bogus default_fd helps in debugging */
+/*     { O_RDONLY,                 77, "<<" }, */
+};
+
 struct redir_struct {
        struct redir_struct *next;
        char *rd_filename;          /* filename */
-       int fd;                     /* file descriptor being redirected */
-       int dup;                    /* -1, or file descriptor being duplicated */
-       smallint /*enum redir_type*/ rd_type;
+       int rd_fd;                  /* fd to redirect */
+       /* fd to redirect to, or -3 if rd_fd is to be closed (n>&-) */
+       int rd_dup;
+       smallint rd_type;           /* (enum redir_type) */
+       /* note: for heredocs, rd_filename contains heredoc delimiter,
+        * and subsequently heredoc itself; and rd_dup is a bitmask:
+        * bit 0: do we need to trim leading tabs?
+        * bit 1: is heredoc quoted (<<'delim' syntax) ?
+        */
 };
+typedef enum redir_type {
+       REDIRECT_INPUT     = 0,
+       REDIRECT_OVERWRITE = 1,
+       REDIRECT_APPEND    = 2,
+       REDIRECT_IO        = 3,
+       REDIRECT_HEREDOC   = 4,
+       REDIRECT_HEREDOC2  = 5, /* REDIRECT_HEREDOC after heredoc is loaded */
+
+       REDIRFD_CLOSE      = -3,
+       REDIRFD_SYNTAX_ERR = -2,
+       REDIRFD_TO_FILE    = -1,
+       /* otherwise, rd_fd is redirected to rd_dup */
+
+       HEREDOC_SKIPTABS = 1,
+       HEREDOC_QUOTED   = 2,
+} redir_type;
+
 
 struct command {
        pid_t pid;                  /* 0 if exited */
        int assignment_cnt;         /* how many argv[i] are assignments? */
        smallint is_stopped;        /* is the command currently running? */
-       smallint grp_type;          /* GRP_xxx */
-       struct pipe *group;         /* if non-NULL, this "command" is { list },
-                                    * ( list ), or a compound statement */
+       smallint cmd_type;          /* CMD_xxx */
+#define CMD_NORMAL   0
+#define CMD_SUBSHELL 1
+
+/* used for "[[ EXPR ]]" */
+#if ENABLE_HUSH_BASH_COMPAT
+# define CMD_SINGLEWORD_NOGLOB 2
+#endif
+
+/* used for "export noglob=* glob* a=`echo a b`" */
+//#define CMD_SINGLEWORD_NOGLOB_COND 3
+// It is hard to implement correctly, it adds significant amounts of tricky code,
+// and all this is only useful for really obscure export statements
+// almost nobody would use anyway. #ifdef CMD_SINGLEWORD_NOGLOB_COND
+// guards the code which implements it, but I have doubts it works
+// in all cases (especially with mixed globbed/non-globbed arguments)
+
+#if ENABLE_HUSH_FUNCTIONS
+# define CMD_FUNCDEF 3
+#endif
+
+       /* if non-NULL, this "command" is { list }, ( list ), or a compound statement */
+       struct pipe *group;
 #if !BB_MMU
        char *group_as_string;
+#endif
+#if ENABLE_HUSH_FUNCTIONS
+       struct function *child_func;
+/* This field is used to prevent a bug here:
+ * while...do f1() {a;}; f1; f1() {b;}; f1; done
+ * When we execute "f1() {a;}" cmd, we create new function and clear
+ * cmd->group, cmd->group_as_string, cmd->argv[0].
+ * When we execute "f1() {b;}", we notice that f1 exists,
+ * and that its "parent cmd" struct is still "alive",
+ * we put those fields back into cmd->xxx
+ * (struct function has ->parent_cmd ptr to facilitate that).
+ * When we loop back, we can execute "f1() {a;}" again and set f1 correctly.
+ * Without this trick, loop would execute a;b;b;b;...
+ * instead of correct sequence a;b;a;b;...
+ * When command is freed, it severs the link
+ * (sets ->child_func->parent_cmd to NULL).
+ */
 #endif
        char **argv;                /* command name and arguments */
-       struct redir_struct *redirects; /* I/O redirections */
-};
 /* argv vector may contain variable references (^Cvar^C, ^C0^C etc)
  * and on execution these are substituted with their values.
  * Substitution can make _several_ words out of one argv[n]!
  * Example: argv[0]=='.^C*^C.' here: echo .$*.
  * References of the form ^C`cmd arg^C are `cmd arg` substitutions.
  */
-#define GRP_NORMAL   0
-#define GRP_SUBSHELL 1
-#if ENABLE_HUSH_FUNCTIONS
-#define GRP_FUNCTION 2
-#endif
+       struct redir_struct *redirects; /* I/O redirections */
+};
+/* Is there anything in this command at all? */
+#define IS_NULL_CMD(cmd) \
+       (!(cmd)->group && !(cmd)->argv && !(cmd)->redirects)
+
 
 struct pipe {
        struct pipe *next;
-       int num_cmds;               /* total number of commands in job */
+       int num_cmds;               /* total number of commands in pipe */
        int alive_cmds;             /* number of commands running (not exited) */
        int stopped_cmds;           /* number of commands alive, but stopped */
 #if ENABLE_HUSH_JOB
@@ -393,6 +393,15 @@ struct pipe {
        IF_HAS_KEYWORDS(smallint pi_inverted;) /* "! cmd | cmd" */
        IF_HAS_KEYWORDS(smallint res_word;) /* needed for if, for, while, until... */
 };
+typedef enum pipe_style {
+       PIPE_SEQ = 1,
+       PIPE_AND = 2,
+       PIPE_OR  = 3,
+       PIPE_BG  = 4,
+} pipe_style;
+/* Is there anything in this pipe at all? */
+#define IS_NULL_PIPE(pi) \
+       ((pi)->num_cmds == 0 IF_HAS_KEYWORDS( && (pi)->res_word == RES_NONE))
 
 /* This holds pointers to the various results of parsing */
 struct parse_context {
@@ -437,6 +446,9 @@ struct parse_context {
 struct variable {
        struct variable *next;
        char *varstr;        /* points to "name=" portion */
+#if ENABLE_HUSH_LOCAL
+       unsigned func_nest_level;
+#endif
        int max_len;         /* if > 0, name is part of initial env; else name is malloced */
        smallint flg_export; /* putenv should be done on this var */
        smallint flg_read_only;
@@ -447,48 +459,84 @@ enum {
        BC_CONTINUE = 2,
 };
 
+#if ENABLE_HUSH_FUNCTIONS
+struct function {
+       struct function *next;
+       char *name;
+       struct command *parent_cmd;
+       struct pipe *body;
+# if !BB_MMU
+       char *body_as_string;
+# endif
+};
+#endif
+
 
 /* "Globals" within this file */
 /* Sorted roughly by size (smaller offsets == smaller code) */
 struct globals {
+       /* interactive_fd != 0 means we are an interactive shell.
+        * If we are, then saved_tty_pgrp can also be != 0, meaning
+        * that controlling tty is available. With saved_tty_pgrp == 0,
+        * job control still works, but terminal signals
+        * (^C, ^Z, ^Y, ^\) won't work at all, and background
+        * process groups can only be created with "cmd &".
+        * With saved_tty_pgrp != 0, hush will use tcsetpgrp()
+        * to give tty to the foreground process group,
+        * and will take it back when the group is stopped (^Z)
+        * or killed (^C).
+        */
 #if ENABLE_HUSH_INTERACTIVE
        /* 'interactive_fd' is a fd# open to ctty, if we have one
         * _AND_ if we decided to act interactively */
        int interactive_fd;
        const char *PS1;
        const char *PS2;
-#define G_interactive_fd (G.interactive_fd)
+# define G_interactive_fd (G.interactive_fd)
 #else
-#define G_interactive_fd 0
+# define G_interactive_fd 0
 #endif
 #if ENABLE_FEATURE_EDITING
        line_input_t *line_input_state;
 #endif
        pid_t root_pid;
+       pid_t root_ppid;
        pid_t last_bg_pid;
+#if ENABLE_HUSH_RANDOM_SUPPORT
+       random_t random_gen;
+#endif
 #if ENABLE_HUSH_JOB
        int run_list_level;
-       pid_t saved_tty_pgrp;
        int last_jobid;
+       pid_t saved_tty_pgrp;
        struct pipe *job_list;
-       struct pipe *toplevel_list;
-////   smallint ctrl_z_flag;
+# define G_saved_tty_pgrp (G.saved_tty_pgrp)
+#else
+# define G_saved_tty_pgrp 0
 #endif
        smallint flag_SIGINT;
 #if ENABLE_HUSH_LOOPS
        smallint flag_break_continue;
+#endif
+#if ENABLE_HUSH_FUNCTIONS
+       /* 0: outside of a function (or sourced file)
+        * -1: inside of a function, ok to use return builtin
+        * 1: return is invoked, skip all till end of func
+        */
+       smallint flag_return_in_progress;
 #endif
        smallint fake_mode;
+       smallint exiting; /* used to prevent EXIT trap recursion */
        /* These four support $?, $#, and $1 */
-       smalluint last_return_code;
+       smalluint last_exitcode;
        /* are global_argv and global_argv[1..n] malloced? (note: not [0]) */
        smalluint global_args_malloced;
+       smalluint inherited_set_is_saved;
        /* how many non-NULL argv's we have. NB: $# + 1 */
        int global_argc;
        char **global_argv;
 #if !BB_MMU
        char *argv0_for_re_execing;
-       char **argv_from_re_execing;
 #endif
 #if ENABLE_HUSH_LOOPS
        unsigned depth_break_continue;
@@ -498,21 +546,29 @@ struct globals {
        const char *cwd;
        struct variable *top_var; /* = &G.shell_ver (set in main()) */
        struct variable shell_ver;
+#if ENABLE_HUSH_FUNCTIONS
+       struct function *top_func;
+# if ENABLE_HUSH_LOCAL
+       struct variable **shadowed_vars_pp;
+       unsigned func_nest_level;
+# endif
+#endif
        /* Signal and trap handling */
-//     unsigned count_SIGCHLD;
-//     unsigned handled_SIGCHLD;
+#if ENABLE_HUSH_FAST
+       unsigned count_SIGCHLD;
+       unsigned handled_SIGCHLD;
+       smallint we_have_children;
+#endif
        /* which signals have non-DFL handler (even with no traps set)? */
        unsigned non_DFL_mask;
        char **traps; /* char *traps[NSIG] */
        sigset_t blocked_set;
        sigset_t inherited_set;
-       char user_input_buf[ENABLE_FEATURE_EDITING ? BUFSIZ : 2];
-#if ENABLE_FEATURE_SH_STANDALONE
-       struct nofork_save_area nofork_save;
-#endif
-#if ENABLE_HUSH_JOB
-       sigjmp_buf toplevel_jb;
+#if HUSH_DEBUG
+       unsigned long memleak_value;
+       int debug_indent;
 #endif
+       char user_input_buf[ENABLE_FEATURE_EDITING ? CONFIG_FEATURE_EDITING_MAX_LEN : 2];
 };
 #define G (*ptr_to_globals)
 /* Not #defining name to G.name - this quickly gets unwieldy
@@ -524,33 +580,46 @@ struct globals {
 
 
 /* Function prototypes for builtins */
-static int builtin_cd(char **argv);
-static int builtin_echo(char **argv);
-static int builtin_eval(char **argv);
-static int builtin_exec(char **argv);
-static int builtin_exit(char **argv);
-static int builtin_export(char **argv);
+static int builtin_cd(char **argv) FAST_FUNC;
+static int builtin_echo(char **argv) FAST_FUNC;
+static int builtin_eval(char **argv) FAST_FUNC;
+static int builtin_exec(char **argv) FAST_FUNC;
+static int builtin_exit(char **argv) FAST_FUNC;
+static int builtin_export(char **argv) FAST_FUNC;
 #if ENABLE_HUSH_JOB
-static int builtin_fg_bg(char **argv);
-static int builtin_jobs(char **argv);
+static int builtin_fg_bg(char **argv) FAST_FUNC;
+static int builtin_jobs(char **argv) FAST_FUNC;
 #endif
 #if ENABLE_HUSH_HELP
-static int builtin_help(char **argv);
-#endif
-static int builtin_pwd(char **argv);
-static int builtin_read(char **argv);
-static int builtin_test(char **argv);
-static int builtin_trap(char **argv);
-static int builtin_true(char **argv);
-static int builtin_set(char **argv);
-static int builtin_shift(char **argv);
-static int builtin_source(char **argv);
-static int builtin_umask(char **argv);
-static int builtin_unset(char **argv);
-static int builtin_wait(char **argv);
+static int builtin_help(char **argv) FAST_FUNC;
+#endif
+#if ENABLE_HUSH_LOCAL
+static int builtin_local(char **argv) FAST_FUNC;
+#endif
+#if HUSH_DEBUG
+static int builtin_memleak(char **argv) FAST_FUNC;
+#endif
+#if ENABLE_PRINTF
+static int builtin_printf(char **argv) FAST_FUNC;
+#endif
+static int builtin_pwd(char **argv) FAST_FUNC;
+static int builtin_read(char **argv) FAST_FUNC;
+static int builtin_set(char **argv) FAST_FUNC;
+static int builtin_shift(char **argv) FAST_FUNC;
+static int builtin_source(char **argv) FAST_FUNC;
+static int builtin_test(char **argv) FAST_FUNC;
+static int builtin_trap(char **argv) FAST_FUNC;
+static int builtin_type(char **argv) FAST_FUNC;
+static int builtin_true(char **argv) FAST_FUNC;
+static int builtin_umask(char **argv) FAST_FUNC;
+static int builtin_unset(char **argv) FAST_FUNC;
+static int builtin_wait(char **argv) FAST_FUNC;
 #if ENABLE_HUSH_LOOPS
-static int builtin_break(char **argv);
-static int builtin_continue(char **argv);
+static int builtin_break(char **argv) FAST_FUNC;
+static int builtin_continue(char **argv) FAST_FUNC;
+#endif
+#if ENABLE_HUSH_FUNCTIONS
+static int builtin_return(char **argv) FAST_FUNC;
 #endif
 
 /* Table of built-in functions.  They can be forked or not, depending on
@@ -560,109 +629,286 @@ static int builtin_continue(char **argv);
  * For example, 'unset foo | whatever' will parse and run, but foo will
  * still be set at the end. */
 struct built_in_command {
-       const char *cmd;
-       int (*function)(char **argv);
+       const char *b_cmd;
+       int (*b_function)(char **argv) FAST_FUNC;
 #if ENABLE_HUSH_HELP
-       const char *descr;
-#define BLTIN(cmd, func, help) { cmd, func, help }
+       const char *b_descr;
+# define BLTIN(cmd, func, help) { cmd, func, help }
 #else
-#define BLTIN(cmd, func, help) { cmd, func }
+# define BLTIN(cmd, func, help) { cmd, func }
 #endif
 };
 
-/* For now, echo and test are unconditionally enabled.
- * Maybe make it configurable? */
-static const struct built_in_command bltins[] = {
-       BLTIN("."       , builtin_source  , "Run commands in a file"),
-       BLTIN(":"       , builtin_true    , "No-op"),
-       BLTIN("["       , builtin_test    , "Test condition"),
+static const struct built_in_command bltins1[] = {
+       BLTIN("."        , builtin_source  , "Run commands in a file"),
+       BLTIN(":"        , builtin_true    , NULL),
 #if ENABLE_HUSH_JOB
-       BLTIN("bg"      , builtin_fg_bg   , "Resume a job in the background"),
+       BLTIN("bg"       , builtin_fg_bg   , "Resume a job in the background"),
 #endif
 #if ENABLE_HUSH_LOOPS
-       BLTIN("break"   , builtin_break   , "Exit from a loop"),
+       BLTIN("break"    , builtin_break   , "Exit from a loop"),
 #endif
-       BLTIN("cd"      , builtin_cd      , "Change directory"),
+       BLTIN("cd"       , builtin_cd      , "Change directory"),
 #if ENABLE_HUSH_LOOPS
-       BLTIN("continue", builtin_continue, "Start new loop iteration"),
+       BLTIN("continue" , builtin_continue, "Start new loop iteration"),
 #endif
-       BLTIN("echo"    , builtin_echo    , "Write to stdout"),
-       BLTIN("eval"    , builtin_eval    , "Construct and run shell command"),
-       BLTIN("exec"    , builtin_exec    , "Execute command, don't return to shell"),
-       BLTIN("exit"    , builtin_exit    , "Exit"),
-       BLTIN("export"  , builtin_export  , "Set environment variable"),
+       BLTIN("eval"     , builtin_eval    , "Construct and run shell command"),
+       BLTIN("exec"     , builtin_exec    , "Execute command, don't return to shell"),
+       BLTIN("exit"     , builtin_exit    , "Exit"),
+       BLTIN("export"   , builtin_export  , "Set environment variables"),
 #if ENABLE_HUSH_JOB
-       BLTIN("fg"      , builtin_fg_bg   , "Bring job into the foreground"),
+       BLTIN("fg"       , builtin_fg_bg   , "Bring job into the foreground"),
 #endif
 #if ENABLE_HUSH_HELP
-       BLTIN("help"    , builtin_help    , "List shell built-in commands"),
+       BLTIN("help"     , builtin_help    , NULL),
 #endif
 #if ENABLE_HUSH_JOB
-       BLTIN("jobs"    , builtin_jobs    , "List active jobs"),
-#endif
-       BLTIN("pwd"     , builtin_pwd     , "Print current directory"),
-       BLTIN("read"    , builtin_read    , "Input environment variable"),
-//     BLTIN("return"  , builtin_return  , "Return from a function"),
-       BLTIN("set"     , builtin_set     , "Set/unset shell local variables"),
-       BLTIN("shift"   , builtin_shift   , "Shift positional parameters"),
-       BLTIN("test"    , builtin_test    , "Test condition"),
-       BLTIN("trap"    , builtin_trap    , "Trap signals"),
-//     BLTIN("ulimit"  , builtin_return  , "Control resource limits"),
-       BLTIN("umask"   , builtin_umask   , "Set file creation mask"),
-       BLTIN("unset"   , builtin_unset   , "Unset environment variable"),
-       BLTIN("wait"    , builtin_wait    , "Wait for process"),
+       BLTIN("jobs"     , builtin_jobs    , "List jobs"),
+#endif
+#if ENABLE_HUSH_LOCAL
+       BLTIN("local"    , builtin_local   , "Set local variables"),
+#endif
+#if HUSH_DEBUG
+       BLTIN("memleak"  , builtin_memleak , NULL),
+#endif
+       BLTIN("read"     , builtin_read    , "Input into variable"),
+#if ENABLE_HUSH_FUNCTIONS
+       BLTIN("return"   , builtin_return  , "Return from a function"),
+#endif
+       BLTIN("set"      , builtin_set     , "Set/unset positional parameters"),
+       BLTIN("shift"    , builtin_shift   , "Shift positional parameters"),
+#if ENABLE_HUSH_BASH_COMPAT
+       BLTIN("source"   , builtin_source  , "Run commands in a file"),
+#endif
+       BLTIN("trap"     , builtin_trap    , "Trap signals"),
+       BLTIN("type"     , builtin_type    , "Show command type"),
+       BLTIN("ulimit"   , shell_builtin_ulimit  , "Control resource limits"),
+       BLTIN("umask"    , builtin_umask   , "Set file creation mask"),
+       BLTIN("unset"    , builtin_unset   , "Unset variables"),
+       BLTIN("wait"     , builtin_wait    , "Wait for process"),
+};
+/* For now, echo and test are unconditionally enabled.
+ * Maybe make it configurable? */
+static const struct built_in_command bltins2[] = {
+       BLTIN("["        , builtin_test    , NULL),
+       BLTIN("echo"     , builtin_echo    , NULL),
+#if ENABLE_PRINTF
+       BLTIN("printf"   , builtin_printf  , NULL),
+#endif
+       BLTIN("pwd"      , builtin_pwd     , NULL),
+       BLTIN("test"     , builtin_test    , NULL),
 };
 
 
-static void maybe_die(const char *notice, const char *msg)
-{
-       /* Was using fancy stuff:
-        * (G_interactive_fd ? bb_error_msg : bb_error_msg_and_die)(...params...)
-        * but it SEGVs. ?! Oh well... explicit temp ptr works around that */
-       void FAST_FUNC (*fp)(const char *s, ...) = bb_error_msg_and_die;
-#if ENABLE_HUSH_INTERACTIVE
-       if (G_interactive_fd)
-               fp = bb_error_msg;
+/* Debug printouts.
+ */
+#if HUSH_DEBUG
+/* prevent disasters with G.debug_indent < 0 */
+# define indent() fprintf(stderr, "%*s", (G.debug_indent * 2) & 0xff, "")
+# define debug_enter() (G.debug_indent++)
+# define debug_leave() (G.debug_indent--)
+#else
+# define indent()      ((void)0)
+# define debug_enter() ((void)0)
+# define debug_leave() ((void)0)
 #endif
-       fp(msg ? "%s: %s" : notice, notice, msg);
-}
-#if 1
-#define syntax(msg) maybe_die("syntax error", msg);
+
+#ifndef debug_printf
+# define debug_printf(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_parse
+# define debug_printf_parse(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_exec
+#define debug_printf_exec(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_env
+# define debug_printf_env(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_jobs
+# define debug_printf_jobs(...) (indent(), fprintf(stderr, __VA_ARGS__))
+# define DEBUG_JOBS 1
 #else
-/* Debug -- trick gcc to expand __LINE__ and convert to string */
-#define __syntax(msg, line) maybe_die("syntax error hush.c:" # line, msg)
-#define _syntax(msg, line) __syntax(msg, line)
-#define syntax(msg) _syntax(msg, __LINE__)
+# define DEBUG_JOBS 0
 #endif
 
+#ifndef debug_printf_expand
+# define debug_printf_expand(...) (indent(), fprintf(stderr, __VA_ARGS__))
+# define DEBUG_EXPAND 1
+#else
+# define DEBUG_EXPAND 0
+#endif
 
-static int glob_needed(const char *s)
-{
-       while (*s) {
-               if (*s == '\\')
-                       s++;
-               if (*s == '*' || *s == '[' || *s == '?')
-                       return 1;
-               s++;
-       }
-       return 0;
-}
+#ifndef debug_printf_glob
+# define debug_printf_glob(...) (indent(), fprintf(stderr, __VA_ARGS__))
+# define DEBUG_GLOB 1
+#else
+# define DEBUG_GLOB 0
+#endif
+
+#ifndef debug_printf_list
+# define debug_printf_list(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_subst
+# define debug_printf_subst(...) (indent(), fprintf(stderr, __VA_ARGS__))
+#endif
+
+#ifndef debug_printf_clean
+# define debug_printf_clean(...) (indent(), fprintf(stderr, __VA_ARGS__))
+# define DEBUG_CLEAN 1
+#else
+# define DEBUG_CLEAN 0
+#endif
 
-static int is_assignment(const char *s)
+#if DEBUG_EXPAND
+static void debug_print_strings(const char *prefix, char **vv)
 {
-       if (!s || !(isalpha(*s) || *s == '_'))
-               return 0;
-       s++;
-       while (isalnum(*s) || *s == '_')
-               s++;
-       return *s == '=';
+       indent();
+       fprintf(stderr, "%s:\n", prefix);
+       while (*vv)
+               fprintf(stderr, " '%s'\n", *vv++);
 }
+#else
+# define debug_print_strings(prefix, vv) ((void)0)
+#endif
 
-/* Replace each \x with x in place, return ptr past NUL. */
-static char *unbackslash(char *src)
+
+/* Leak hunting. Use hush_leaktool.sh for post-processing.
+ */
+#if LEAK_HUNTING
+static void *xxmalloc(int lineno, size_t size)
 {
-       char *dst = src;
-       while (1) {
+       void *ptr = xmalloc((size + 0xff) & ~0xff);
+       fdprintf(2, "line %d: malloc %p\n", lineno, ptr);
+       return ptr;
+}
+static void *xxrealloc(int lineno, void *ptr, size_t size)
+{
+       ptr = xrealloc(ptr, (size + 0xff) & ~0xff);
+       fdprintf(2, "line %d: realloc %p\n", lineno, ptr);
+       return ptr;
+}
+static char *xxstrdup(int lineno, const char *str)
+{
+       char *ptr = xstrdup(str);
+       fdprintf(2, "line %d: strdup %p\n", lineno, ptr);
+       return ptr;
+}
+static void xxfree(void *ptr)
+{
+       fdprintf(2, "free %p\n", ptr);
+       free(ptr);
+}
+#define xmalloc(s)     xxmalloc(__LINE__, s)
+#define xrealloc(p, s) xxrealloc(__LINE__, p, s)
+#define xstrdup(s)     xxstrdup(__LINE__, s)
+#define free(p)        xxfree(p)
+#endif
+
+
+/* Syntax and runtime errors. They always abort scripts.
+ * In interactive use they usually discard unparsed and/or unexecuted commands
+ * and return to the prompt.
+ * HUSH_DEBUG >= 2 prints line number in this file where it was detected.
+ */
+#if HUSH_DEBUG < 2
+# define die_if_script(lineno, ...)             die_if_script(__VA_ARGS__)
+# define syntax_error(lineno, msg)              syntax_error(msg)
+# define syntax_error_at(lineno, msg)           syntax_error_at(msg)
+# define syntax_error_unterm_ch(lineno, ch)     syntax_error_unterm_ch(ch)
+# define syntax_error_unterm_str(lineno, s)     syntax_error_unterm_str(s)
+# define syntax_error_unexpected_ch(lineno, ch) syntax_error_unexpected_ch(ch)
+#endif
+
+static void die_if_script(unsigned lineno, const char *fmt, ...)
+{
+       va_list p;
+
+#if HUSH_DEBUG >= 2
+       bb_error_msg("hush.c:%u", lineno);
+#endif
+       va_start(p, fmt);
+       bb_verror_msg(fmt, p, NULL);
+       va_end(p);
+       if (!G_interactive_fd)
+               xfunc_die();
+}
+
+static void syntax_error(unsigned lineno, const char *msg)
+{
+       if (msg)
+               die_if_script(lineno, "syntax error: %s", msg);
+       else
+               die_if_script(lineno, "syntax error", NULL);
+}
+
+static void syntax_error_at(unsigned lineno, const char *msg)
+{
+       die_if_script(lineno, "syntax error at '%s'", msg);
+}
+
+static void syntax_error_unterm_str(unsigned lineno, const char *s)
+{
+       die_if_script(lineno, "syntax error: unterminated %s", s);
+}
+
+/* It so happens that all such cases are totally fatal
+ * even if shell is interactive: EOF while looking for closing
+ * delimiter. There is nowhere to read stuff from after that,
+ * it's EOF! The only choice is to terminate.
+ */
+static void syntax_error_unterm_ch(unsigned lineno, char ch) NORETURN;
+static void syntax_error_unterm_ch(unsigned lineno, char ch)
+{
+       char msg[2] = { ch, '\0' };
+       syntax_error_unterm_str(lineno, msg);
+       xfunc_die();
+}
+
+static void syntax_error_unexpected_ch(unsigned lineno, int ch)
+{
+       char msg[2];
+       msg[0] = ch;
+       msg[1] = '\0';
+       die_if_script(lineno, "syntax error: unexpected %s", ch == EOF ? "EOF" : msg);
+}
+
+#if HUSH_DEBUG < 2
+# undef die_if_script
+# undef syntax_error
+# undef syntax_error_at
+# undef syntax_error_unterm_ch
+# undef syntax_error_unterm_str
+# undef syntax_error_unexpected_ch
+#else
+# define die_if_script(...)             die_if_script(__LINE__, __VA_ARGS__)
+# define syntax_error(msg)              syntax_error(__LINE__, msg)
+# define syntax_error_at(msg)           syntax_error_at(__LINE__, msg)
+# define syntax_error_unterm_ch(ch)     syntax_error_unterm_ch(__LINE__, ch)
+# define syntax_error_unterm_str(s)     syntax_error_unterm_str(__LINE__, s)
+# define syntax_error_unexpected_ch(ch) syntax_error_unexpected_ch(__LINE__, ch)
+#endif
+
+
+#if ENABLE_HUSH_INTERACTIVE
+static void cmdedit_update_prompt(void);
+#else
+# define cmdedit_update_prompt() ((void)0)
+#endif
+
+
+/* Utility functions
+ */
+/* Replace each \x with x in place, return ptr past NUL. */
+static char *unbackslash(char *src)
+{
+       char *dst = src = strchrnul(src, '\\');
+       while (1) {
                if (*src == '\\')
                        src++;
                if ((*dst++ = *src++) == '\0')
@@ -699,7 +945,18 @@ static char **add_strings_to_strings(char **strings, char **add, int need_to_dup
                v[count1 + i] = (need_to_dup ? xstrdup(add[i]) : add[i]);
        return v;
 }
+#if LEAK_HUNTING
+static char **xx_add_strings_to_strings(int lineno, char **strings, char **add, int need_to_dup)
+{
+       char **ptr = add_strings_to_strings(strings, add, need_to_dup);
+       fdprintf(2, "line %d: add_strings_to_strings %p\n", lineno, ptr);
+       return ptr;
+}
+#define add_strings_to_strings(strings, add, need_to_dup) \
+       xx_add_strings_to_strings(__LINE__, strings, add, need_to_dup)
+#endif
 
+/* Note: takes ownership of "add" ptr (it is not strdup'ed) */
 static char **add_string_to_strings(char **strings, char *add)
 {
        char *v[2];
@@ -707,65 +964,75 @@ static char **add_string_to_strings(char **strings, char *add)
        v[1] = NULL;
        return add_strings_to_strings(strings, v, /*dup:*/ 0);
 }
-
-static void putenv_all(char **strings)
-{
-       if (!strings)
-               return;
-       while (*strings) {
-               debug_printf_env("putenv '%s'\n", *strings);
-               putenv(*strings++);
-       }
-}
-
-static char **putenv_all_and_save_old(char **strings)
+#if LEAK_HUNTING
+static char **xx_add_string_to_strings(int lineno, char **strings, char *add)
 {
-       char **old = NULL;
-       char **s = strings;
-
-       if (!strings)
-               return old;
-       while (*strings) {
-               char *v, *eq;
-
-               eq = strchr(*strings, '=');
-               if (eq) {
-                       *eq = '\0';
-                       v = getenv(*strings);
-                       *eq = '=';
-                       if (v) {
-                               /* v points to VAL in VAR=VAL, go back to VAR */
-                               v -= (eq - *strings) + 1;
-                               old = add_string_to_strings(old, v);
-                       }
-               }
-               strings++;
-       }
-       putenv_all(s);
-       return old;
+       char **ptr = add_string_to_strings(strings, add);
+       fdprintf(2, "line %d: add_string_to_strings %p\n", lineno, ptr);
+       return ptr;
 }
+#define add_string_to_strings(strings, add) \
+       xx_add_string_to_strings(__LINE__, strings, add)
+#endif
 
-static void free_strings_and_unsetenv(char **strings, int unset)
+static void free_strings(char **strings)
 {
        char **v;
 
        if (!strings)
                return;
-
        v = strings;
        while (*v) {
-               if (unset) {
-                       debug_printf_env("unsetenv '%s'\n", *v);
-                       bb_unsetenv(*v);
-               }
-               free(*v++);
+               free(*v);
+               v++;
        }
        free(strings);
 }
 
-static void free_strings(char **strings)
+
+/* Helpers for setting new $n and restoring them back
+ */
+typedef struct save_arg_t {
+       char *sv_argv0;
+       char **sv_g_argv;
+       int sv_g_argc;
+       smallint sv_g_malloced;
+} save_arg_t;
+
+static void save_and_replace_G_args(save_arg_t *sv, char **argv)
+{
+       int n;
+
+       sv->sv_argv0 = argv[0];
+       sv->sv_g_argv = G.global_argv;
+       sv->sv_g_argc = G.global_argc;
+       sv->sv_g_malloced = G.global_args_malloced;
+
+       argv[0] = G.global_argv[0]; /* retain $0 */
+       G.global_argv = argv;
+       G.global_args_malloced = 0;
+
+       n = 1;
+       while (*++argv)
+               n++;
+       G.global_argc = n;
+}
+
+static void restore_G_args(save_arg_t *sv, char **argv)
 {
-       free_strings_and_unsetenv(strings, 0);
+       char **pp;
+
+       if (G.global_args_malloced) {
+               /* someone ran "set -- arg1 arg2 ...", undo */
+               pp = G.global_argv;
+               while (*++pp) /* note: does not free $0 */
+                       free(*pp);
+               free(G.global_argv);
+       }
+       argv[0] = sv->sv_argv0;
+       G.global_argv = sv->sv_g_argv;
+       G.global_argc = sv->sv_g_argc;
+       G.global_args_malloced = sv->sv_g_malloced;
 }
 
 
@@ -779,7 +1046,7 @@ static void free_strings(char **strings)
  * is finished or backgrounded. It is the same in interactive and
  * non-interactive shells, and is the same regardless of whether
  * a user trap handler is installed or a shell special one is in effect.
- * ^C or ^Z from keyboard seem to execute "at once" because it usually
+ * ^C or ^Z from keyboard seems to execute "at once" because it usually
  * backgrounds (i.e. stops) or kills all members of currently running
  * pipe.
  *
@@ -788,18 +1055,19 @@ static void free_strings(char **strings)
  *
  * Trap handlers will execute even within trap handlers. (right?)
  *
- * User trap handlers are forgotten when subshell ("(cmd)") is entered. [TODO]
+ * User trap handlers are forgotten when subshell ("(cmd)") is entered,
+ * except for handlers set to '' (empty string).
  *
  * If job control is off, backgrounded commands ("cmd &")
  * have SIGINT, SIGQUIT set to SIG_IGN.
  *
- * Commands run in command substitution ("`cmd`")
+ * Commands which are run in command substitution ("`cmd`")
  * have SIGTTIN, SIGTTOU, SIGTSTP set to SIG_IGN.
  *
- * Ordinary commands have signals set to SIG_IGN/DFL set as inherited
+ * Ordinary commands have signals set to SIG_IGN/DFL as inherited
  * by the shell from its parent.
  *
- * Siganls which differ from SIG_DFL action
+ * Signals which differ from SIG_DFL action
  * (note: child (i.e., [v]forked) shell is not an interactive shell):
  *
  * SIGQUIT: ignore
@@ -807,13 +1075,14 @@ static void free_strings(char **strings)
  * SIGHUP (interactive):
  *    send SIGCONT to stopped jobs, send SIGHUP to all jobs and exit
  * SIGTTIN, SIGTTOU, SIGTSTP (if job control is on): ignore
- *    (note that ^Z is handled not by trapping SIGTSTP, but by seeing
- *    that all pipe members are stopped) (right?)
+ *    Note that ^Z is handled not by trapping SIGTSTP, but by seeing
+ *    that all pipe members are stopped. Try this in bash:
+ *    while :; do :; done - ^Z does not background it
+ *    (while :; do :; done) - ^Z backgrounds it
  * SIGINT (interactive): wait for last pipe, ignore the rest
  *    of the command line, show prompt. NB: ^C does not send SIGINT
  *    to interactive shell while shell is waiting for a pipe,
  *    since shell is bg'ed (is not in foreground process group).
- *    (check/expand this)
  *    Example 1: this waits 5 sec, but does not execute ls:
  *    "echo $$; sleep 5; ls -l" + "kill -INT <pid>"
  *    Example 2: this does not wait and does not execute ls:
@@ -841,70 +1110,54 @@ static void free_strings(char **strings)
  * "trap 'cmd' SIGxxx":
  *    set bit in blocked_set (even if 'cmd' is '')
  * after [v]fork, if we plan to be a shell:
- *    nothing for {} child shell (say, "true | { true; true; } | true")
- *    unset all traps if () shell. [TODO]
+ *    unblock signals with special interactive handling
+ *    (child shell is not interactive),
+ *    unset all traps except '' (note: regardless of child shell's type - {}, (), etc)
  * after [v]fork, if we plan to exec:
- *    POSIX says pending signal mask is cleared in child - no need to clear it.
+ *    POSIX says fork clears pending signal mask in child - no need to clear it.
  *    Restore blocked signal set to one inherited by shell just prior to exec.
  *
  * Note: as a result, we do not use signal handlers much. The only uses
- * are to count SIGCHLDs [disabled - bug somewhere, + bloat]
+ * are to count SIGCHLDs
  * and to restore tty pgrp on signal-induced exit.
+ *
+ * Note 2 (compat):
+ * Standard says "When a subshell is entered, traps that are not being ignored
+ * are set to the default actions". bash interprets it so that traps which
+ * are set to '' (ignore) are NOT reset to defaults. We do the same.
  */
+enum {
+       SPECIAL_INTERACTIVE_SIGS = 0
+               | (1 << SIGTERM)
+               | (1 << SIGINT)
+               | (1 << SIGHUP)
+               ,
+       SPECIAL_JOB_SIGS = 0
+#if ENABLE_HUSH_JOB
+               | (1 << SIGTTIN)
+               | (1 << SIGTTOU)
+               | (1 << SIGTSTP)
+#endif
+};
 
-//static void SIGCHLD_handler(int sig UNUSED_PARAM)
-//{
-//     G.count_SIGCHLD++;
-//}
-
-static int check_and_run_traps(int sig)
+#if ENABLE_HUSH_FAST
+static void SIGCHLD_handler(int sig UNUSED_PARAM)
 {
-       static const struct timespec zero_timespec = { 0, 0 };
-       smalluint save_rcode;
-       int last_sig = 0;
-
-       if (sig)
-               goto jump_in;
-       while (1) {
-               sig = sigtimedwait(&G.blocked_set, NULL, &zero_timespec);
-               if (sig <= 0)
-                       break;
- jump_in:
-               last_sig = sig;
-               if (G.traps && G.traps[sig]) {
-                       if (G.traps[sig][0]) {
-                               /* We have user-defined handler */
-                               char *argv[] = { NULL, xstrdup(G.traps[sig]), NULL };
-                               save_rcode = G.last_return_code;
-                               builtin_eval(argv);
-                               free(argv[1]);
-                               G.last_return_code = save_rcode;
-                       } /* else: "" trap, ignoring signal */
-                       continue;
-               }
-               /* not a trap: special action */
-               switch (sig) {
-//             case SIGCHLD:
-//                     G.count_SIGCHLD++;
-//                     break;
-               case SIGINT:
-                       bb_putchar('\n');
-                       G.flag_SIGINT = 1;
-                       break;
-//TODO
-//             case SIGHUP: ...
-//                     break;
-               default: /* SIGTERM, SIGQUIT, SIGTTIN, SIGTTOU, SIGTSTP */
-                       break;
-               }
-       }
-       return last_sig;
+       G.count_SIGCHLD++;
+//bb_error_msg("[%d] SIGCHLD_handler: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
 }
+#endif
 
 #if ENABLE_HUSH_JOB
+
+/* After [v]fork, in child: do not restore tty pgrp on xfunc death */
+#define disable_restore_tty_pgrp_on_exit() (die_sleep = 0)
+/* After [v]fork, in parent: restore tty pgrp on xfunc death */
+#define enable_restore_tty_pgrp_on_exit()  (die_sleep = -1)
+
 /* Restores tty foreground process group, and exits.
  * May be called as signal handler for fatal signal
- * (will faithfully resend signal to itself, producing correct exit state)
+ * (will resend signal to itself, producing correct exit state)
  * or called directly with -EXITCODE.
  * We also call it if xfunc is exiting. */
 static void sigexit(int sig) NORETURN;
@@ -915,8 +1168,8 @@ static void sigexit(int sig)
 
        /* Careful: we can end up here after [v]fork. Do not restore
         * tty pgrp then, only top-level shell process does that */
-       if (G_interactive_fd && getpid() == G.root_pid)
-               tcsetpgrp(G_interactive_fd, G.saved_tty_pgrp);
+       if (G_saved_tty_pgrp && getpid() == G.root_pid)
+               tcsetpgrp(G_interactive_fd, G_saved_tty_pgrp);
 
        /* Not a signal, just exit */
        if (sig <= 0)
@@ -924,104 +1177,198 @@ static void sigexit(int sig)
 
        kill_myself_with_sig(sig); /* does not return */
 }
+#else
+
+#define disable_restore_tty_pgrp_on_exit() ((void)0)
+#define enable_restore_tty_pgrp_on_exit()  ((void)0)
+
 #endif
 
 /* Restores tty foreground process group, and exits. */
 static void hush_exit(int exitcode) NORETURN;
 static void hush_exit(int exitcode)
 {
-       if (G.traps && G.traps[0] && G.traps[0][0]) {
-               char *argv[] = { NULL, xstrdup(G.traps[0]), NULL };
-//TODO: do we need to prevent recursion?
+       if (G.exiting <= 0 && G.traps && G.traps[0] && G.traps[0][0]) {
+               /* Prevent recursion:
+                * trap "echo Hi; exit" EXIT; exit
+                */
+               char *argv[] = { NULL, G.traps[0], NULL };
+               G.traps[0] = NULL;
+               G.exiting = 1;
                builtin_eval(argv);
                free(argv[1]);
        }
 
 #if ENABLE_HUSH_JOB
-       fflush(NULL); /* flush all streams */
+       fflush_all();
        sigexit(- (exitcode & 0xff));
 #else
        exit(exitcode);
 #endif
 }
 
+static int check_and_run_traps(int sig)
+{
+       static const struct timespec zero_timespec = { 0, 0 };
+       smalluint save_rcode;
+       int last_sig = 0;
+
+       if (sig)
+               goto jump_in;
+       while (1) {
+               sig = sigtimedwait(&G.blocked_set, NULL, &zero_timespec);
+               if (sig <= 0)
+                       break;
+ jump_in:
+               last_sig = sig;
+               if (G.traps && G.traps[sig]) {
+                       if (G.traps[sig][0]) {
+                               /* We have user-defined handler */
+                               char *argv[] = { NULL, xstrdup(G.traps[sig]), NULL };
+                               save_rcode = G.last_exitcode;
+                               builtin_eval(argv);
+                               free(argv[1]);
+                               G.last_exitcode = save_rcode;
+                       } /* else: "" trap, ignoring signal */
+                       continue;
+               }
+               /* not a trap: special action */
+               switch (sig) {
+#if ENABLE_HUSH_FAST
+               case SIGCHLD:
+                       G.count_SIGCHLD++;
+//bb_error_msg("[%d] check_and_run_traps: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
+                       break;
+#endif
+               case SIGINT:
+                       /* Builtin was ^C'ed, make it look prettier: */
+                       bb_putchar('\n');
+                       G.flag_SIGINT = 1;
+                       break;
+#if ENABLE_HUSH_JOB
+               case SIGHUP: {
+                       struct pipe *job;
+                       /* bash is observed to signal whole process groups,
+                        * not individual processes */
+                       for (job = G.job_list; job; job = job->next) {
+                               if (job->pgrp <= 0)
+                                       continue;
+                               debug_printf_exec("HUPing pgrp %d\n", job->pgrp);
+                               if (kill(- job->pgrp, SIGHUP) == 0)
+                                       kill(- job->pgrp, SIGCONT);
+                       }
+                       sigexit(SIGHUP);
+               }
+#endif
+               default: /* ignored: */
+                       /* SIGTERM, SIGQUIT, SIGTTIN, SIGTTOU, SIGTSTP */
+                       break;
+               }
+       }
+       return last_sig;
+}
+
 
-static const char *set_cwd(void)
+static const char *get_cwd(int force)
 {
-       /* xrealloc_getcwd_or_warn(arg) calls free(arg),
-        * we must not try to free(bb_msg_unknown) */
-       if (G.cwd == bb_msg_unknown)
-               G.cwd = NULL;
-       G.cwd = xrealloc_getcwd_or_warn((char *)G.cwd);
-       if (!G.cwd)
-               G.cwd = bb_msg_unknown;
+       if (force || G.cwd == NULL) {
+               /* xrealloc_getcwd_or_warn(arg) calls free(arg),
+                * we must not try to free(bb_msg_unknown) */
+               if (G.cwd == bb_msg_unknown)
+                       G.cwd = NULL;
+               G.cwd = xrealloc_getcwd_or_warn((char *)G.cwd);
+               if (!G.cwd)
+                       G.cwd = bb_msg_unknown;
+       }
        return G.cwd;
 }
 
 
-/* Get/check local shell variables */
-static struct variable *get_local_var(const char *name)
+/*
+ * Shell and environment variable support
+ */
+static struct variable **get_ptr_to_local_var(const char *name)
 {
+       struct variable **pp;
        struct variable *cur;
        int len;
 
-       if (!name)
-               return NULL;
        len = strlen(name);
-       for (cur = G.top_var; cur; cur = cur->next) {
+       pp = &G.top_var;
+       while ((cur = *pp) != NULL) {
                if (strncmp(cur->varstr, name, len) == 0 && cur->varstr[len] == '=')
-                       return cur;
+                       return pp;
+               pp = &cur->next;
        }
        return NULL;
 }
 
-static const char *get_local_var_value(const char *src)
+static struct variable *get_local_var(const char *name)
+{
+       struct variable **pp = get_ptr_to_local_var(name);
+       if (pp)
+               return *pp;
+       return NULL;
+}
+
+static const char* FAST_FUNC get_local_var_value(const char *name)
 {
-       struct variable *var = get_local_var(src);
-       if (var)
-               return strchr(var->varstr, '=') + 1;
+       struct variable **pp = get_ptr_to_local_var(name);
+       if (pp)
+               return strchr((*pp)->varstr, '=') + 1;
+       if (strcmp(name, "PPID") == 0)
+               return utoa(G.root_ppid);
+       // bash compat: UID? EUID?
+#if ENABLE_HUSH_RANDOM_SUPPORT
+       if (strcmp(name, "RANDOM") == 0) {
+               return utoa(next_random(&G.random_gen));
+       }
+#endif
        return NULL;
 }
 
 /* str holds "NAME=VAL" and is expected to be malloced.
  * We take ownership of it.
  * flg_export:
- *  0: do not export
- *  1: export
- * -1: if NAME is set, leave export status alone
- *     if NAME is not set, do not export
+ *  0: do not change export flag
+ *     (if creating new variable, flag will be 0)
+ *  1: set export flag and putenv the variable
+ * -1: clear export flag and unsetenv the variable
  * flg_read_only is set only when we handle -R var=val
  */
-#if BB_MMU
-#define set_local_var(str, flg_export, flg_read_only) \
+#if !BB_MMU && ENABLE_HUSH_LOCAL
+/* all params are used */
+#elif BB_MMU && ENABLE_HUSH_LOCAL
+#define set_local_var(str, flg_export, local_lvl, flg_read_only) \
+       set_local_var(str, flg_export, local_lvl)
+#elif BB_MMU && !ENABLE_HUSH_LOCAL
+#define set_local_var(str, flg_export, local_lvl, flg_read_only) \
        set_local_var(str, flg_export)
+#elif !BB_MMU && !ENABLE_HUSH_LOCAL
+#define set_local_var(str, flg_export, local_lvl, flg_read_only) \
+       set_local_var(str, flg_export, flg_read_only)
 #endif
-static int set_local_var(char *str, int flg_export, int flg_read_only)
+static int set_local_var(char *str, int flg_export, int local_lvl, int flg_read_only)
 {
+       struct variable **var_pp;
        struct variable *cur;
-       char *value;
+       char *eq_sign;
        int name_len;
 
-       value = strchr(str, '=');
-       if (!value) { /* not expected to ever happen? */
+       eq_sign = strchr(str, '=');
+       if (!eq_sign) { /* not expected to ever happen? */
                free(str);
                return -1;
        }
 
-       name_len = value - str + 1; /* including '=' */
-       cur = G.top_var; /* cannot be NULL (we have HUSH_VERSION and it's RO) */
-       while (1) {
+       name_len = eq_sign - str + 1; /* including '=' */
+       var_pp = &G.top_var;
+       while ((cur = *var_pp) != NULL) {
                if (strncmp(cur->varstr, str, name_len) != 0) {
-                       if (!cur->next) {
-                               /* Bail out. Note that now cur points
-                                * to last var in linked list */
-                               break;
-                       }
-                       cur = cur->next;
+                       var_pp = &cur->next;
                        continue;
                }
                /* We found an existing var with this name */
-               *value = '\0';
                if (cur->flg_read_only) {
 #if !BB_MMU
                        if (!flg_read_only)
@@ -1030,30 +1377,61 @@ static int set_local_var(char *str, int flg_export, int flg_read_only)
                        free(str);
                        return -1;
                }
-               debug_printf_env("%s: unsetenv '%s'\n", __func__, str);
-               unsetenv(str); /* just in case */
-               *value = '=';
-               if (strcmp(cur->varstr, str) == 0) {
+               if (flg_export == -1) { // "&& cur->flg_export" ?
+                       debug_printf_env("%s: unsetenv '%s'\n", __func__, str);
+                       *eq_sign = '\0';
+                       unsetenv(str);
+                       *eq_sign = '=';
+               }
+#if ENABLE_HUSH_LOCAL
+               if (cur->func_nest_level < local_lvl) {
+                       /* New variable is declared as local,
+                        * and existing one is global, or local
+                        * from enclosing function.
+                        * Remove and save old one: */
+                       *var_pp = cur->next;
+                       cur->next = *G.shadowed_vars_pp;
+                       *G.shadowed_vars_pp = cur;
+                       /* bash 3.2.33(1) and exported vars:
+                        * # export z=z
+                        * # f() { local z=a; env | grep ^z; }
+                        * # f
+                        * z=a
+                        * # env | grep ^z
+                        * z=z
+                        */
+                       if (cur->flg_export)
+                               flg_export = 1;
+                       break;
+               }
+#endif
+               if (strcmp(cur->varstr + name_len, eq_sign + 1) == 0) {
  free_and_exp:
                        free(str);
                        goto exp;
                }
-               if (cur->max_len >= strlen(str)) {
-                       /* This one is from startup env, reuse space */
-                       strcpy(cur->varstr, str);
-                       goto free_and_exp;
-               }
-               /* max_len == 0 signifies "malloced" var, which we can
-                * (and has to) free */
-               if (!cur->max_len)
+               if (cur->max_len != 0) {
+                       if (cur->max_len >= strlen(str)) {
+                               /* This one is from startup env, reuse space */
+                               strcpy(cur->varstr, str);
+                               goto free_and_exp;
+                       }
+               } else {
+                       /* max_len == 0 signifies "malloced" var, which we can
+                        * (and has to) free */
                        free(cur->varstr);
+               }
                cur->max_len = 0;
                goto set_str_and_exp;
        }
 
-       /* Not found - create next variable struct */
-       cur->next = xzalloc(sizeof(*cur));
-       cur = cur->next;
+       /* Not found - create new variable struct */
+       cur = xzalloc(sizeof(*cur));
+#if ENABLE_HUSH_LOCAL
+       cur->func_nest_level = local_lvl;
+#endif
+       cur->next = *var_pp;
+       *var_pp = cur;
 
  set_str_and_exp:
        cur->varstr = str;
@@ -1063,49 +1441,80 @@ static int set_local_var(char *str, int flg_export, int flg_read_only)
  exp:
        if (flg_export == 1)
                cur->flg_export = 1;
+       if (name_len == 4 && cur->varstr[0] == 'P' && cur->varstr[1] == 'S')
+               cmdedit_update_prompt();
        if (cur->flg_export) {
-               debug_printf_env("%s: putenv '%s'\n", __func__, cur->varstr);
-               return putenv(cur->varstr);
+               if (flg_export == -1) {
+                       cur->flg_export = 0;
+                       /* unsetenv was already done */
+               } else {
+                       debug_printf_env("%s: putenv '%s'\n", __func__, cur->varstr);
+                       return putenv(cur->varstr);
+               }
        }
        return 0;
 }
 
-static int unset_local_var(const char *name)
+/* Used at startup and after each cd */
+static void set_pwd_var(int exp)
+{
+       set_local_var(xasprintf("PWD=%s", get_cwd(/*force:*/ 1)),
+               /*exp:*/ exp, /*lvl:*/ 0, /*ro:*/ 0);
+}
+
+static int unset_local_var_len(const char *name, int name_len)
 {
        struct variable *cur;
-       struct variable *prev = prev; /* for gcc */
-       int name_len;
+       struct variable **var_pp;
 
        if (!name)
                return EXIT_SUCCESS;
-       name_len = strlen(name);
-       cur = G.top_var;
-       while (cur) {
+       var_pp = &G.top_var;
+       while ((cur = *var_pp) != NULL) {
                if (strncmp(cur->varstr, name, name_len) == 0 && cur->varstr[name_len] == '=') {
                        if (cur->flg_read_only) {
                                bb_error_msg("%s: readonly variable", name);
                                return EXIT_FAILURE;
                        }
-                       /* prev is ok to use here because 1st variable, HUSH_VERSION,
-                        * is ro, and we cannot reach this code on the 1st pass */
-                       prev->next = cur->next;
+                       *var_pp = cur->next;
                        debug_printf_env("%s: unsetenv '%s'\n", __func__, cur->varstr);
                        bb_unsetenv(cur->varstr);
+                       if (name_len == 3 && cur->varstr[0] == 'P' && cur->varstr[1] == 'S')
+                               cmdedit_update_prompt();
                        if (!cur->max_len)
                                free(cur->varstr);
                        free(cur);
                        return EXIT_SUCCESS;
                }
-               prev = cur;
-               cur = cur->next;
+               var_pp = &cur->next;
        }
        return EXIT_SUCCESS;
 }
 
+static int unset_local_var(const char *name)
+{
+       return unset_local_var_len(name, strlen(name));
+}
+
+static void unset_vars(char **strings)
+{
+       char **v;
+
+       if (!strings)
+               return;
+       v = strings;
+       while (*v) {
+               const char *eq = strchrnul(*v, '=');
+               unset_local_var_len(*v, (int)(eq - *v));
+               v++;
+       }
+       free(strings);
+}
+
 #if ENABLE_SH_MATH_SUPPORT
 #define is_name(c)      ((c) == '_' || isalpha((unsigned char)(c)))
 #define is_in_name(c)   ((c) == '_' || isalnum((unsigned char)(c)))
-static char *endofname(const char *name)
+static char* FAST_FUNC endofname(const char *name)
 {
        char *p;
 
@@ -1118,20 +1527,75 @@ static char *endofname(const char *name)
        }
        return p;
 }
+#endif
 
-static void arith_set_local_var(const char *name, const char *val, int flags)
+static void FAST_FUNC set_local_var_from_halves(const char *name, const char *val)
 {
-       /* arith code doesnt malloc space, so do it for it */
        char *var = xasprintf("%s=%s", name, val);
-       set_local_var(var, flags, 0);
+       set_local_var(var, /*flags:*/ 0, /*lvl:*/ 0, /*ro:*/ 0);
 }
-#endif
 
 
 /*
- * in_str support
+ * Helpers for "var1=val1 var2=val2 cmd" feature
  */
-static int static_get(struct in_str *i)
+static void add_vars(struct variable *var)
+{
+       struct variable *next;
+
+       while (var) {
+               next = var->next;
+               var->next = G.top_var;
+               G.top_var = var;
+               if (var->flg_export) {
+                       debug_printf_env("%s: restoring exported '%s'\n", __func__, var->varstr);
+                       putenv(var->varstr);
+               } else {
+                       debug_printf_env("%s: restoring variable '%s'\n", __func__, var->varstr);
+               }
+               var = next;
+       }
+}
+
+static struct variable *set_vars_and_save_old(char **strings)
+{
+       char **s;
+       struct variable *old = NULL;
+
+       if (!strings)
+               return old;
+       s = strings;
+       while (*s) {
+               struct variable *var_p;
+               struct variable **var_pp;
+               char *eq;
+
+               eq = strchr(*s, '=');
+               if (eq) {
+                       *eq = '\0';
+                       var_pp = get_ptr_to_local_var(*s);
+                       *eq = '=';
+                       if (var_pp) {
+                               /* Remove variable from global linked list */
+                               var_p = *var_pp;
+                               debug_printf_env("%s: removing '%s'\n", __func__, var_p->varstr);
+                               *var_pp = var_p->next;
+                               /* Add it to returned list */
+                               var_p->next = old;
+                               old = var_p;
+                       }
+                       set_local_var(*s, /*exp:*/ 1, /*lvl:*/ 0, /*ro:*/ 0);
+               }
+               s++;
+       }
+       return old;
+}
+
+
+/*
+ * in_str support
+ */
+static int FAST_FUNC static_get(struct in_str *i)
 {
        int ch = *i->p++;
        if (ch != '\0')
@@ -1140,21 +1604,25 @@ static int static_get(struct in_str *i)
        return EOF;
 }
 
-static int static_peek(struct in_str *i)
+static int FAST_FUNC static_peek(struct in_str *i)
 {
        return *i->p;
 }
 
 #if ENABLE_HUSH_INTERACTIVE
 
-static void cmdedit_set_initial_prompt(void)
+static void cmdedit_update_prompt(void)
 {
        if (ENABLE_FEATURE_EDITING_FANCY_PROMPT) {
-               G.PS1 = getenv("PS1");
+               G.PS1 = get_local_var_value("PS1");
                if (G.PS1 == NULL)
                        G.PS1 = "\\w \\$ ";
-       } else
+               G.PS2 = get_local_var_value("PS2");
+       } else {
                G.PS1 = NULL;
+       }
+       if (G.PS2 == NULL)
+               G.PS2 = "> ";
 }
 
 static const char* setup_prompt_string(int promptmode)
@@ -1165,7 +1633,10 @@ static const char* setup_prompt_string(int promptmode)
                /* Set up the prompt */
                if (promptmode == 0) { /* PS1 */
                        free((char*)G.PS1);
-                       G.PS1 = xasprintf("%s %c ", G.cwd, (geteuid() != 0) ? '$' : '#');
+                       /* bash uses $PWD value, even if it is set by user.
+                        * It uses current dir only if PWD is unset.
+                        * We always use current dir. */
+                       G.PS1 = xasprintf("%s %c ", get_cwd(0), (geteuid() != 0) ? '$' : '#');
                        prompt_str = G.PS1;
                } else
                        prompt_str = G.PS2;
@@ -1188,7 +1659,7 @@ static void get_user_input(struct in_str *i)
                G.flag_SIGINT = 0;
                /* buglet: SIGINT will not make new prompt to appear _at once_,
                 * only after <Enter>. (^C will work) */
-               r = read_line_input(prompt_str, G.user_input_buf, BUFSIZ-1, G.line_input_state);
+               r = read_line_input(prompt_str, G.user_input_buf, CONFIG_FEATURE_EDITING_MAX_LEN-1, G.line_input_state);
                /* catch *SIGINT* etc (^C is handled by read_line_input) */
                check_and_run_traps(0);
        } while (r == 0 || G.flag_SIGINT); /* repeat if ^C or SIGINT */
@@ -1201,7 +1672,7 @@ static void get_user_input(struct in_str *i)
        do {
                G.flag_SIGINT = 0;
                fputs(prompt_str, stdout);
-               fflush(stdout);
+               fflush_all();
                G.user_input_buf[0] = r = fgetc(i->file);
                /*G.user_input_buf[1] = '\0'; - already is and never changed */
 //do we need check_and_run_traps(0)? (maybe only if stdin)
@@ -1215,7 +1686,7 @@ static void get_user_input(struct in_str *i)
 
 /* This is the magic location that prints prompts
  * and gets data back from the user */
-static int file_get(struct in_str *i)
+static int FAST_FUNC file_get(struct in_str *i)
 {
        int ch;
 
@@ -1227,6 +1698,7 @@ static int file_get(struct in_str *i)
                ch = *i->p++;
                if (i->eof_flag && !*i->p)
                        ch = EOF;
+               /* note: ch is never NUL */
        } else {
                /* need to double check i->file because we might be doing something
                 * more complicated by now, like sourcing or substituting. */
@@ -1240,9 +1712,9 @@ static int file_get(struct in_str *i)
                        goto take_cached;
                }
 #endif
-               ch = fgetc(i->file);
+               do ch = fgetc(i->file); while (ch == '\0');
        }
-       debug_printf("file_get: got '%c' %d\n", ch, ch);
+       debug_printf("file_get: got '%c' %d\n", ch, ch);
 #if ENABLE_HUSH_INTERACTIVE
        if (ch == '\n')
                i->promptme = 1;
@@ -1250,23 +1722,24 @@ static int file_get(struct in_str *i)
        return ch;
 }
 
-/* All the callers guarantee this routine will never be
- * used right after a newline, so prompting is not needed.
+/* All callers guarantee this routine will never
+ * be used right after a newline, so prompting is not needed.
  */
-static int file_peek(struct in_str *i)
+static int FAST_FUNC file_peek(struct in_str *i)
 {
        int ch;
        if (i->p && *i->p) {
                if (i->eof_flag && !i->p[1])
                        return EOF;
                return *i->p;
+               /* note: ch is never NUL */
        }
-       ch = fgetc(i->file);
+       do ch = fgetc(i->file); while (ch == '\0');
        i->eof_flag = (ch == EOF);
        i->peek_buf[0] = ch;
        i->peek_buf[1] = '\0';
        i->p = i->peek_buf;
-       debug_printf("file_peek: got a '%c' %d\n", *i->p, *i->p);
+       debug_printf("file_peek: got '%c' %d\n", ch, ch);
        return ch;
 }
 
@@ -1300,10 +1773,10 @@ static void setup_string_in_str(struct in_str *i, const char *s)
  */
 #define B_CHUNK  (32 * sizeof(char*))
 
-static void o_reset(o_string *o)
+static void o_reset_to_empty_unquoted(o_string *o)
 {
        o->length = 0;
-       o->nonnull = 0;
+       o->o_quoted = 0;
        if (o->data)
                o->data[0] = '\0';
 }
@@ -1349,6 +1822,13 @@ static void o_addstr(o_string *o, const char *str)
 {
        o_addblock(o, str, strlen(str));
 }
+static void nommu_addchr(o_string *o, int ch)
+{
+       if (o)
+               o_addchr(o, ch);
+}
+#else
+# define nommu_addchr(o, str) ((void)0)
 #endif
 
 static void o_addstr_with_NUL(o_string *o, const char *str)
@@ -1369,13 +1849,31 @@ static void o_addblock_duplicate_backslash(o_string *o, const char *str, int len
        }
 }
 
+#undef HUSH_BRACE_EXP
+/*
+ * HUSH_BRACE_EXP code needs corresponding quoting on variable expansion side.
+ * Currently, "v='{q,w}'; echo $v" erroneously expands braces in $v.
+ * Apparently, on unquoted $v bash still does globbing
+ * ("v='*.txt'; echo $v" prints all .txt files),
+ * but NOT brace expansion! Thus, there should be TWO independent
+ * quoting mechanisms on $v expansion side: one protects
+ * $v from brace expansion, and other additionally protects "$v" against globbing.
+ * We have only second one.
+ */
+
+#ifdef HUSH_BRACE_EXP
+# define MAYBE_BRACES "{}"
+#else
+# define MAYBE_BRACES ""
+#endif
+
 /* My analysis of quoting semantics tells me that state information
  * is associated with a destination, not a source.
  */
 static void o_addqchr(o_string *o, int ch)
 {
        int sz = 1;
-       char *found = strchr("*?[\\", ch);
+       char *found = strchr("*?[\\" MAYBE_BRACES, ch);
        if (found)
                sz++;
        o_grow_by(o, sz);
@@ -1391,7 +1889,7 @@ static void o_addqchr(o_string *o, int ch)
 static void o_addQchr(o_string *o, int ch)
 {
        int sz = 1;
-       if (o->o_escape && strchr("*?[\\", ch)) {
+       if (o->o_escape && strchr("*?[\\" MAYBE_BRACES, ch)) {
                sz++;
                o->data[o->length] = '\\';
                o->length++;
@@ -1411,7 +1909,7 @@ static void o_addQstr(o_string *o, const char *str, int len)
        while (len) {
                char ch;
                int sz;
-               int ordinary_cnt = strcspn(str, "*?[\\");
+               int ordinary_cnt = strcspn(str, "*?[\\" MAYBE_BRACES);
                if (ordinary_cnt > len) /* paranoia */
                        ordinary_cnt = len;
                o_addblock(o, str, ordinary_cnt);
@@ -1422,7 +1920,7 @@ static void o_addQstr(o_string *o, const char *str, int len)
 
                ch = *str++;
                sz = 1;
-               if (ch) { /* it is necessarily one of "*?[\\" */
+               if (ch) { /* it is necessarily one of "*?[\\" MAYBE_BRACES */
                        sz++;
                        o->data[o->length] = '\\';
                        o->length++;
@@ -1450,9 +1948,12 @@ static void debug_print_list(const char *prefix, o_string *o, int n)
        char **list = (char**)o->data;
        int string_start = ((n + 0xf) & ~0xf) * sizeof(list[0]);
        int i = 0;
+
+       indent();
        fprintf(stderr, "%s: list:%p n:%d string_start:%d length:%d maxlen:%d\n",
                        prefix, list, n, string_start, o->length, o->maxlen);
        while (i < n) {
+               indent();
                fprintf(stderr, " list[%d]=%d '%s' %p\n", i, (int)list[i],
                                o->data + (int)list[i] + string_start,
                                o->data + (int)list[i] + string_start);
@@ -1460,11 +1961,12 @@ static void debug_print_list(const char *prefix, o_string *o, int n)
        }
        if (n) {
                const char *p = o->data + (int)list[n - 1] + string_start;
+               indent();
                fprintf(stderr, " total_sz:%ld\n", (long)((p + strlen(p) + 1) - o->data));
        }
 }
 #else
-#define debug_print_list(prefix, o, n) ((void)0)
+# define debug_print_list(prefix, o, n) ((void)0)
 #endif
 
 /* n = o_save_ptr_helper(str, n) "starts new string" by storing an index value
@@ -1512,8 +2014,223 @@ static int o_get_last_ptr(o_string *o, int n)
        return ((int)(ptrdiff_t)list[n-1]) + string_start;
 }
 
-/* o_glob performs globbing on last list[], saving each result
- * as a new list[]. */
+#ifdef HUSH_BRACE_EXP
+/* There in a GNU extension, GLOB_BRACE, but it is not usable:
+ * first, it processes even {a} (no commas), second,
+ * I didn't manage to make it return strings when they don't match
+ * existing files. Need to re-implement it.
+ */
+
+/* Helper */
+static int glob_needed(const char *s)
+{
+       while (*s) {
+               if (*s == '\\') {
+                       if (!s[1])
+                               return 0;
+                       s += 2;
+                       continue;
+               }
+               if (*s == '*' || *s == '[' || *s == '?' || *s == '{')
+                       return 1;
+               s++;
+       }
+       return 0;
+}
+/* Return pointer to next closing brace or to comma */
+static const char *next_brace_sub(const char *cp)
+{
+       unsigned depth = 0;
+       cp++;
+       while (*cp != '\0') {
+               if (*cp == '\\') {
+                       if (*++cp == '\0')
+                               break;
+                       cp++;
+                       continue;
+               }
+                /*{*/ if ((*cp == '}' && depth-- == 0) || (*cp == ',' && depth == 0))
+                       break;
+               if (*cp++ == '{') /*}*/
+                       depth++;
+       }
+
+       return *cp != '\0' ? cp : NULL;
+}
+/* Recursive brace globber. Note: may garble pattern[]. */
+static int glob_brace(char *pattern, o_string *o, int n)
+{
+       char *new_pattern_buf;
+       const char *begin;
+       const char *next;
+       const char *rest;
+       const char *p;
+       size_t rest_len;
+
+       debug_printf_glob("glob_brace('%s')\n", pattern);
+
+       begin = pattern;
+       while (1) {
+               if (*begin == '\0')
+                       goto simple_glob;
+               if (*begin == '{') /*}*/ {
+                       /* Find the first sub-pattern and at the same time
+                        * find the rest after the closing brace */
+                       next = next_brace_sub(begin);
+                       if (next == NULL) {
+                               /* An illegal expression */
+                               goto simple_glob;
+                       }
+                       /*{*/ if (*next == '}') {
+                               /* "{abc}" with no commas - illegal
+                                * brace expr, disregard and skip it */
+                               begin = next + 1;
+                               continue;
+                       }
+                       break;
+               }
+               if (*begin == '\\' && begin[1] != '\0')
+                       begin++;
+               begin++;
+       }
+       debug_printf_glob("begin:%s\n", begin);
+       debug_printf_glob("next:%s\n", next);
+
+       /* Now find the end of the whole brace expression */
+       rest = next;
+       /*{*/ while (*rest != '}') {
+               rest = next_brace_sub(rest);
+               if (rest == NULL) {
+                       /* An illegal expression */
+                       goto simple_glob;
+               }
+               debug_printf_glob("rest:%s\n", rest);
+       }
+       rest_len = strlen(++rest) + 1;
+
+       /* We are sure the brace expression is well-formed */
+
+       /* Allocate working buffer large enough for our work */
+       new_pattern_buf = xmalloc(strlen(pattern));
+
+       /* We have a brace expression.  BEGIN points to the opening {,
+        * NEXT points past the terminator of the first element, and REST
+        * points past the final }.  We will accumulate result names from
+        * recursive runs for each brace alternative in the buffer using
+        * GLOB_APPEND.  */
+
+       p = begin + 1;
+       while (1) {
+               /* Construct the new glob expression */
+               memcpy(
+                       mempcpy(
+                               mempcpy(new_pattern_buf,
+                                       /* We know the prefix for all sub-patterns */
+                                       pattern, begin - pattern),
+                               p, next - p),
+                       rest, rest_len);
+
+               /* Note: glob_brace() may garble new_pattern_buf[].
+                * That's why we re-copy prefix every time (1st memcpy above).
+                */
+               n = glob_brace(new_pattern_buf, o, n);
+               /*{*/ if (*next == '}') {
+                       /* We saw the last entry */
+                       break;
+               }
+               p = next + 1;
+               next = next_brace_sub(next);
+       }
+       free(new_pattern_buf);
+       return n;
+
+ simple_glob:
+       {
+               int gr;
+               glob_t globdata;
+
+               memset(&globdata, 0, sizeof(globdata));
+               gr = glob(pattern, 0, NULL, &globdata);
+               debug_printf_glob("glob('%s'):%d\n", pattern, gr);
+               if (gr != 0) {
+                       if (gr == GLOB_NOMATCH) {
+                               globfree(&globdata);
+                               /* NB: garbles parameter */
+                               unbackslash(pattern);
+                               o_addstr_with_NUL(o, pattern);
+                               debug_printf_glob("glob pattern '%s' is literal\n", pattern);
+                               return o_save_ptr_helper(o, n);
+                       }
+                       if (gr == GLOB_NOSPACE)
+                               bb_error_msg_and_die(bb_msg_memory_exhausted);
+                       /* GLOB_ABORTED? Only happens with GLOB_ERR flag,
+                        * but we didn't specify it. Paranoia again. */
+                       bb_error_msg_and_die("glob error %d on '%s'", gr, pattern);
+               }
+               if (globdata.gl_pathv && globdata.gl_pathv[0]) {
+                       char **argv = globdata.gl_pathv;
+                       while (1) {
+                               o_addstr_with_NUL(o, *argv);
+                               n = o_save_ptr_helper(o, n);
+                               argv++;
+                               if (!*argv)
+                                       break;
+                       }
+               }
+               globfree(&globdata);
+       }
+       return n;
+}
+/* Performs globbing on last list[],
+ * saving each result as a new list[].
+ */
+static int o_glob(o_string *o, int n)
+{
+       char *pattern, *copy;
+
+       debug_printf_glob("start o_glob: n:%d o->data:%p\n", n, o->data);
+       if (!o->data)
+               return o_save_ptr_helper(o, n);
+       pattern = o->data + o_get_last_ptr(o, n);
+       debug_printf_glob("glob pattern '%s'\n", pattern);
+       if (!glob_needed(pattern)) {
+               /* unbackslash last string in o in place, fix length */
+               o->length = unbackslash(pattern) - o->data;
+               debug_printf_glob("glob pattern '%s' is literal\n", pattern);
+               return o_save_ptr_helper(o, n);
+       }
+
+       copy = xstrdup(pattern);
+       /* "forget" pattern in o */
+       o->length = pattern - o->data;
+       n = glob_brace(copy, o, n);
+       free(copy);
+       if (DEBUG_GLOB)
+               debug_print_list("o_glob returning", o, n);
+       return n;
+}
+
+#else
+
+/* Helper */
+static int glob_needed(const char *s)
+{
+       while (*s) {
+               if (*s == '\\') {
+                       if (!s[1])
+                               return 0;
+                       s += 2;
+                       continue;
+               }
+               if (*s == '*' || *s == '[' || *s == '?')
+                       return 1;
+               s++;
+       }
+       return 0;
+}
+/* Performs globbing on last list[],
+ * saving each result as a new list[].
+ */
 static int o_glob(o_string *o, int n)
 {
        glob_t globdata;
@@ -1527,27 +2244,35 @@ static int o_glob(o_string *o, int n)
        debug_printf_glob("glob pattern '%s'\n", pattern);
        if (!glob_needed(pattern)) {
  literal:
+               /* unbackslash last string in o in place, fix length */
                o->length = unbackslash(pattern) - o->data;
                debug_printf_glob("glob pattern '%s' is literal\n", pattern);
                return o_save_ptr_helper(o, n);
        }
 
        memset(&globdata, 0, sizeof(globdata));
+       /* Can't use GLOB_NOCHECK: it does not unescape the string.
+        * If we glob "*.\*" and don't find anything, we need
+        * to fall back to using literal "*.*", but GLOB_NOCHECK
+        * will return "*.\*"!
+        */
        gr = glob(pattern, 0, NULL, &globdata);
        debug_printf_glob("glob('%s'):%d\n", pattern, gr);
-       if (gr == GLOB_NOSPACE)
-               bb_error_msg_and_die("out of memory during glob");
-       if (gr == GLOB_NOMATCH) {
-               globfree(&globdata);
-               goto literal;
-       }
-       if (gr != 0) { /* GLOB_ABORTED ? */
-//TODO: testcase for bad glob pattern behavior
-               bb_error_msg("glob(3) error %d on '%s'", gr, pattern);
+       if (gr != 0) {
+               if (gr == GLOB_NOMATCH) {
+                       globfree(&globdata);
+                       goto literal;
+               }
+               if (gr == GLOB_NOSPACE)
+                       bb_error_msg_and_die(bb_msg_memory_exhausted);
+               /* GLOB_ABORTED? Only happens with GLOB_ERR flag,
+                * but we didn't specify it. Paranoia again. */
+               bb_error_msg_and_die("glob error %d on '%s'", gr, pattern);
        }
        if (globdata.gl_pathv && globdata.gl_pathv[0]) {
                char **argv = globdata.gl_pathv;
-               o->length = pattern - o->data; /* "forget" pattern */
+               /* "forget" pattern in o */
+               o->length = pattern - o->data;
                while (1) {
                        o_addstr_with_NUL(o, *argv);
                        n = o_save_ptr_helper(o, n);
@@ -1562,6 +2287,8 @@ static int o_glob(o_string *o, int n)
        return n;
 }
 
+#endif
+
 /* If o->o_glob == 1, glob the string so far remembered.
  * Otherwise, just finish current list[] and start new */
 static int o_save_ptr(o_string *o, int n)
@@ -1645,30 +2372,82 @@ static int expand_on_ifs(o_string *output, int n, const char *str)
        return n;
 }
 
+/* Helper to expand $((...)) and heredoc body. These act as if
+ * they are in double quotes, with the exception that they are not :).
+ * Just the rules are similar: "expand only $var and `cmd`"
+ *
+ * Returns malloced string.
+ * As an optimization, we return NULL if expansion is not needed.
+ */
+static char *expand_pseudo_dquoted(const char *str)
+{
+       char *exp_str;
+       struct in_str input;
+       o_string dest = NULL_O_STRING;
+
+       if (strchr(str, '$') == NULL
+#if ENABLE_HUSH_TICK
+        && strchr(str, '`') == NULL
+#endif
+       ) {
+               return NULL;
+       }
+
+       /* We need to expand. Example:
+        * echo $(($a + `echo 1`)) $((1 + $((2)) ))
+        */
+       setup_string_in_str(&input, str);
+       parse_stream_dquoted(NULL, &dest, &input, EOF);
+       //bb_error_msg("'%s' -> '%s'", str, dest.data);
+       exp_str = expand_string_to_string(dest.data);
+       //bb_error_msg("'%s' -> '%s'", dest.data, exp_str);
+       o_free_unsafe(&dest);
+       return exp_str;
+}
+
+#if ENABLE_SH_MATH_SUPPORT
+static arith_t expand_and_evaluate_arith(const char *arg, int *errcode_p)
+{
+       arith_eval_hooks_t hooks;
+       arith_t res;
+       char *exp_str;
+
+       hooks.lookupvar = get_local_var_value;
+       hooks.setvar = set_local_var_from_halves;
+       hooks.endofname = endofname;
+       exp_str = expand_pseudo_dquoted(arg);
+       res = arith(exp_str ? exp_str : arg, errcode_p, &hooks);
+       free(exp_str);
+       return res;
+}
+#endif
+
 /* Expand all variable references in given string, adding words to list[]
  * at n, n+1,... positions. Return updated n (so that list[n] is next one
  * to be filled). This routine is extremely tricky: has to deal with
  * variables/parameters with whitespace, $* and $@, and constructs like
  * 'echo -$*-'. If you play here, you must run testsuite afterwards! */
-static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
+static NOINLINE int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
 {
-       /* or_mask is either 0 (normal case) or 0x80
-        * (expansion of right-hand side of assignment == 1-element expand.
-        * It will also do no globbing, and thus we must not backslash-quote!) */
-
-       char first_ch, ored_ch;
-       int i;
-       const char *val;
+       /* or_mask is either 0 (normal case) or 0x80 -
+        * expansion of right-hand side of assignment == 1-element expand.
+        * It will also do no globbing, and thus we must not backslash-quote!
+        */
+       char ored_ch;
        char *p;
 
        ored_ch = 0;
 
-       debug_printf_expand("expand_vars_to_list: arg '%s'\n", arg);
+       debug_printf_expand("expand_vars_to_list: arg:'%s' or_mask:%x\n", arg, or_mask);
        debug_print_list("expand_vars_to_list", output, n);
        n = o_save_ptr(output, n);
        debug_print_list("expand_vars_to_list[0]", output, n);
 
        while ((p = strchr(arg, SPECIAL_VAR_SYMBOL)) != NULL) {
+               char first_ch;
+               int i;
+               char *to_be_freed = NULL;
+               const char *val = NULL;
 #if ENABLE_HUSH_TICK
                o_string subst_result = NULL_O_STRING;
 #endif
@@ -1686,7 +2465,6 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
                if ((first_ch & 0x7f) != '@')
                        ored_ch |= first_ch;
 
-               val = NULL;
                switch (first_ch & 0x7f) {
                /* Highest bit in first_ch indicates that var is double-quoted */
                case '$': /* pid */
@@ -1696,7 +2474,7 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
                        val = G.last_bg_pid ? utoa(G.last_bg_pid) : (char*)"";
                        break;
                case '?': /* exitcode */
-                       val = utoa(G.last_return_code);
+                       val = utoa(G.last_exitcode);
                        break;
                case '#': /* argc */
                        if (arg[1] != SPECIAL_VAR_SYMBOL)
@@ -1758,67 +2536,39 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
                case '`': /* <SPECIAL_VAR_SYMBOL>`cmd<SPECIAL_VAR_SYMBOL> */
                        *p = '\0';
                        arg++;
-//TODO: can we just stuff it into "output" directly?
+                       /* Can't just stuff it into output o_string,
+                        * expanded result may need to be globbed
+                        * and $IFS-splitted */
                        debug_printf_subst("SUBST '%s' first_ch %x\n", arg, first_ch);
-                       process_command_subs(&subst_result, arg);
-                       debug_printf_subst("SUBST RES '%s'\n", subst_result.data);
+                       G.last_exitcode = process_command_subs(&subst_result, arg);
+                       debug_printf_subst("SUBST RES:%d '%s'\n", G.last_exitcode, subst_result.data);
                        val = subst_result.data;
                        goto store_val;
 #endif
 #if ENABLE_SH_MATH_SUPPORT
                case '+': { /* <SPECIAL_VAR_SYMBOL>+cmd<SPECIAL_VAR_SYMBOL> */
-                       arith_eval_hooks_t hooks;
                        arith_t res;
                        int errcode;
-                       char *exp_str;
 
                        arg++; /* skip '+' */
                        *p = '\0'; /* replace trailing <SPECIAL_VAR_SYMBOL> */
                        debug_printf_subst("ARITH '%s' first_ch %x\n", arg, first_ch);
-
-                       /* Optional: skip expansion if expr is simple ("a + 3", "i++" etc) */
-                       exp_str = arg;
-                       while (1) {
-                               unsigned char c = *exp_str++;
-                               if (c == '\0') {
-                                       exp_str = NULL;
-                                       goto skip_expand;
-                               }
-                               if (isdigit(c))
-                                       continue;
-                               if (strchr(" \t+-*/%_", c) != NULL)
-                                       continue;
-                               c |= 0x20; /* tolower */
-                               if (c >= 'a' && c <= 'z')
-                                       continue;
-                               break;
-                       }
-                       /* We need to expand. Example: "echo $(($a + 1)) $((1 + $((2)) ))" */
-                       {
-                               struct in_str input;
-                               o_string dest = NULL_O_STRING;
-
-                               setup_string_in_str(&input, arg);
-                               parse_stream_dquoted(NULL, &dest, &input, EOF);
-                               //bb_error_msg("'%s' -> '%s'", arg, dest.data);
-                               exp_str = expand_string_to_string(dest.data);
-                               //bb_error_msg("'%s' -> '%s'", dest.data, exp_str);
-                               o_free(&dest);
-                       }
- skip_expand:
-                       hooks.lookupvar = get_local_var_value;
-                       hooks.setvar = arith_set_local_var;
-                       hooks.endofname = endofname;
-                       res = arith(exp_str ? exp_str : arg, &errcode, &hooks);
-                       free(exp_str);
+                       res = expand_and_evaluate_arith(arg, &errcode);
 
                        if (errcode < 0) {
+                               const char *msg = "error in arithmetic";
                                switch (errcode) {
-                               case -3: maybe_die("arith", "exponent less than 0"); break;
-                               case -2: maybe_die("arith", "divide by zero"); break;
-                               case -5: maybe_die("arith", "expression recursion loop detected"); break;
-                               default: maybe_die("arith", "syntax error"); break;
+                               case -3:
+                                       msg = "exponent less than 0";
+                                       break;
+                               case -2:
+                                       msg = "divide by 0";
+                                       break;
+                               case -5:
+                                       msg = "expression recursion loop detected";
+                                       break;
                                }
+                               die_if_script(msg);
                        }
                        debug_printf_subst("ARITH RES '"arith_t_fmt"'\n", res);
                        sprintf(arith_buf, arith_t_fmt, res);
@@ -1828,34 +2578,32 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
 #endif
                default: /* <SPECIAL_VAR_SYMBOL>varname<SPECIAL_VAR_SYMBOL> */
                case_default: {
-                       bool exp_len = false;
-                       bool exp_null = false;
                        char *var = arg;
+                       char exp_len; /* '#' if it's ${#var} */
+                       char exp_op;
                        char exp_save = exp_save; /* for compiler */
-                       char exp_op = exp_op; /* for compiler */
+                       char *exp_saveptr = exp_saveptr; /* points to expansion operator */
                        char *exp_word = exp_word; /* for compiler */
-                       size_t exp_off = 0;
 
                        *p = '\0';
                        arg[0] = first_ch & 0x7f;
 
                        /* prepare for expansions */
-                       if (var[0] == '#') {
+                       exp_op = 0;
+                       exp_len = var[0];
+                       if (exp_len == '#') {
                                /* handle length expansion ${#var} */
-                               exp_len = true;
-                               ++var;
+                               var++;
                        } else {
                                /* maybe handle parameter expansion */
-                               exp_off = strcspn(var, ":-=+?");
-                               if (!var[exp_off])
-                                       exp_off = 0;
-                               if (exp_off) {
-                                       exp_save = var[exp_off];
-                                       exp_null = exp_save == ':';
-                                       exp_word = var + exp_off;
-                                       if (exp_null) ++exp_word;
+                               exp_saveptr = var + strcspn(var, "%#:-=+?");
+                               exp_save = *exp_saveptr;
+                               if (exp_save) {
+                                       exp_word = exp_saveptr;
+                                       if (exp_save == ':')
+                                               exp_word++;
                                        exp_op = *exp_word++;
-                                       var[exp_off] = '\0';
+                                       *exp_saveptr = '\0';
                                }
                        }
 
@@ -1870,36 +2618,138 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
                                val = get_local_var_value(var);
 
                        /* handle any expansions */
-                       if (exp_len) {
-                               debug_printf_expand("expand: length of '%s' = ", val);
+                       if (exp_len == '#') {
+                               debug_printf_expand("expand: length(%s)=", val);
                                val = utoa(val ? strlen(val) : 0);
                                debug_printf_expand("%s\n", val);
-                       } else if (exp_off) {
-                               /* we need to do an expansion */
-                               int exp_test = (!val || (exp_null && !val[0]));
-                               if (exp_op == '+')
-                                       exp_test = !exp_test;
-                               debug_printf_expand("expand: op:%c (null:%s) test:%i\n", exp_op,
-                                       exp_null ? "true" : "false", exp_test);
-                               if (exp_test) {
-                                       if (exp_op == '?')
-                                               maybe_die(var, *exp_word ? exp_word : "parameter null or not set");
-                                       else
-                                               val = exp_word;
-
-                                       if (exp_op == '=') {
-                                               if (isdigit(var[0]) || var[0] == '#') {
-                                                       maybe_die(var, "special vars cannot assign in this way");
-                                                       val = NULL;
+                       } else if (exp_op) {
+                               if (exp_op == '%' || exp_op == '#') {
+       /* Standard-mandated substring removal ops:
+        * ${parameter%word} - remove smallest suffix pattern
+        * ${parameter%%word} - remove largest suffix pattern
+        * ${parameter#word} - remove smallest prefix pattern
+        * ${parameter##word} - remove largest prefix pattern
+        *
+        * Word is expanded to produce a glob pattern.
+        * Then var's value is matched to it and matching part removed.
+        */
+                                       if (val) {
+                                               bool match_at_left;
+                                               char *loc;
+                                               scan_t scan = pick_scan(exp_op, *exp_word, &match_at_left);
+                                               if (exp_op == *exp_word)        /* ## or %% */
+                                                       exp_word++;
+                                               val = to_be_freed = xstrdup(val);
+                                               {
+                                                       char *exp_exp_word = expand_pseudo_dquoted(exp_word);
+                                                       if (exp_exp_word)
+                                                               exp_word = exp_exp_word;
+                                                       loc = scan(to_be_freed, exp_word, match_at_left);
+                                                       //bb_error_msg("op:%c str:'%s' pat:'%s' res:'%s'",
+                                                       //              exp_op, to_be_freed, exp_word, loc);
+                                                       free(exp_exp_word);
+                                               }
+                                               if (loc) { /* match was found */
+                                                       if (match_at_left) /* # or ## */
+                                                               val = loc;
+                                                       else /* % or %% */
+                                                               *loc = '\0';
+                                               }
+                                       }
+                               } else if (!strchr("%#:-=+?"+3, exp_op)) {
+#if ENABLE_HUSH_BASH_COMPAT
+       /* exp_op is ':' and next char isn't a subst operator.
+        * Assuming it's ${var:[N][:M]} bashism.
+        * TODO: N, M can be expressions similar to $((EXPR)): 2+2, 2+var etc
+        */
+                                       char *end;
+                                       unsigned len = INT_MAX;
+                                       unsigned beg = 0;
+                                       end = --exp_word;
+                                       if (*exp_word != ':') /* not ${var::...} */
+                                               beg = bb_strtou(exp_word, &end, 0);
+                                       //bb_error_msg("beg:'%s'=%u end:'%s'", exp_word, beg, end);
+                                       if (*end == ':') {
+                                               if (end[1] != '\0') /* not ${var:NUM:} */
+                                                       len = bb_strtou(end + 1, &end, 0);
+                                               else {
+                                                       len = 0;
+                                                       end++;
+                                               }
+                                               //bb_error_msg("len:%u end:'%s'", len, end);
+                                       }
+                                       if (*end == '\0') {
+                                               //bb_error_msg("from val:'%s'", val);
+                                               if (len == 0 || !val || beg >= strlen(val))
+                                                       val = "";
+                                               else
+                                                       val = to_be_freed = xstrndup(val + beg, len);
+                                               //bb_error_msg("val:'%s'", val);
+                                       } else
+#endif
+                                       {
+                                               die_if_script("malformed ${%s...}", var);
+                                               val = "";
+                                       }
+                               } else { /* one of "-=+?" */
+       /* Standard-mandated substitution ops:
+        * ${var?word} - indicate error if unset
+        *      If var is unset, word (or a message indicating it is unset
+        *      if word is null) is written to standard error
+        *      and the shell exits with a non-zero exit status.
+        *      Otherwise, the value of var is substituted.
+        * ${var-word} - use default value
+        *      If var is unset, word is substituted.
+        * ${var=word} - assign and use default value
+        *      If var is unset, word is assigned to var.
+        *      In all cases, final value of var is substituted.
+        * ${var+word} - use alternative value
+        *      If var is unset, null is substituted.
+        *      Otherwise, word is substituted.
+        *
+        * Word is subjected to tilde expansion, parameter expansion,
+        * command substitution, and arithmetic expansion.
+        * If word is not needed, it is not expanded.
+        *
+        * Colon forms (${var:-word}, ${var:=word} etc) do the same,
+        * but also treat null var as if it is unset.
+        */
+                                       int use_word = (!val || ((exp_save == ':') && !val[0]));
+                                       if (exp_op == '+')
+                                               use_word = !use_word;
+                                       debug_printf_expand("expand: op:%c (null:%s) test:%i\n", exp_op,
+                                               (exp_save == ':') ? "true" : "false", use_word);
+                                       if (use_word) {
+                                               to_be_freed = expand_pseudo_dquoted(exp_word);
+                                               if (to_be_freed)
+                                                       exp_word = to_be_freed;
+                                               if (exp_op == '?') {
+                                                       /* mimic bash message */
+                                                       die_if_script("%s: %s",
+                                                               var,
+                                                               exp_word[0] ? exp_word : "parameter null or not set"
+                                                       );
+//TODO: how interactive bash aborts expansion mid-command?
                                                } else {
-                                                       char *new_var = xmalloc(strlen(var) + strlen(val) + 2);
-                                                       sprintf(new_var, "%s=%s", var, val);
-                                                       set_local_var(new_var, -1, 0);
+                                                       val = exp_word;
+                                               }
+
+                                               if (exp_op == '=') {
+                                                       /* ${var=[word]} or ${var:=[word]} */
+                                                       if (isdigit(var[0]) || var[0] == '#') {
+                                                               /* mimic bash message */
+                                                               die_if_script("$%s: cannot assign in this way", var);
+                                                               val = NULL;
+                                                       } else {
+                                                               char *new_var = xasprintf("%s=%s", var, val);
+                                                               set_local_var(new_var, /*exp:*/ 0, /*lvl:*/ 0, /*ro:*/ 0);
+                                                       }
                                                }
                                        }
                                }
-                               var[exp_off] = exp_save;
-                       }
+
+                               *exp_saveptr = exp_save;
+                       } /* if (exp_op) */
 
                        arg[0] = first_ch;
 #if ENABLE_HUSH_TICK
@@ -1920,9 +2770,11 @@ static int expand_vars_to_list(o_string *output, int n, char *arg, char or_mask)
                        }
                } /* default: */
                } /* switch (char after <SPECIAL_VAR_SYMBOL>) */
+
                if (val) {
                        o_addQstr(output, val, strlen(val));
                }
+               free(to_be_freed);
                /* Do the check to avoid writing to a const string */
                if (*p != SPECIAL_VAR_SYMBOL)
                        *p = SPECIAL_VAR_SYMBOL;
@@ -1967,7 +2819,7 @@ static char **expand_variables(char **argv, int or_mask)
        n = 0;
        v = argv;
        while (*v) {
-               n = expand_vars_to_list(&output, n, *v, (char)or_mask);
+               n = expand_vars_to_list(&output, n, *v, (unsigned char)or_mask);
                v++;
        }
        debug_print_list("expand_variables", &output, n);
@@ -1983,6 +2835,48 @@ static char **expand_strvec_to_strvec(char **argv)
        return expand_variables(argv, 0x100);
 }
 
+#if ENABLE_HUSH_BASH_COMPAT
+static char **expand_strvec_to_strvec_singleword_noglob(char **argv)
+{
+       return expand_variables(argv, 0x80);
+}
+#endif
+
+#ifdef CMD_SINGLEWORD_NOGLOB_COND
+static char **expand_strvec_to_strvec_singleword_noglob_cond(char **argv)
+{
+       int n;
+       char **list;
+       char **v;
+       o_string output = NULL_O_STRING;
+
+       n = 0;
+       v = argv;
+       while (*v) {
+               int is_var = is_well_formed_var_name(*v, '=');
+               /* is_var * 0x80: singleword expansion for vars */
+               n = expand_vars_to_list(&output, n, *v, is_var * 0x80);
+
+               /* Subtle! expand_vars_to_list did not glob last word yet.
+                * It does this only when fed with further data.
+                * Therefore we set globbing flags AFTER it, not before:
+                */
+
+               /* if it is not recognizably abc=...; then: */
+               output.o_escape = !is_var; /* protect against globbing for "$var" */
+               /* (unquoted $var will temporarily switch it off) */
+               output.o_glob = !is_var; /* and indeed do globbing */
+               v++;
+       }
+       debug_print_list("expand_cond", &output, n);
+
+       /* output.data (malloced in one block) gets returned in "list" */
+       list = o_finalize_list(&output, n);
+       debug_print_strings("expand_cond[1]", list);
+       return list;
+}
+#endif
+
 /* Used for expansion of right hand of assignments */
 /* NB: should NOT do globbing! "export v=/bin/c*; env | grep ^v=" outputs
  * "v=/bin/c*" */
@@ -1992,12 +2886,13 @@ static char *expand_string_to_string(const char *str)
 
        argv[0] = (char*)str;
        argv[1] = NULL;
-       list = expand_variables(argv, 0x80); /* 0x80: make one-element expansion */
+       list = expand_variables(argv, 0x80); /* 0x80: singleword expansion */
        if (HUSH_DEBUG)
                if (!list[0] || list[1])
                        bb_error_msg_and_die("BUG in varexp2");
        /* actually, just move string 2*sizeof(char*) bytes back */
        overlapping_strcpy((char*)list, list[0]);
+       unbackslash((char*)list);
        debug_printf_expand("string_to_string='%s'\n", (char*)list);
        return (char*)list;
 }
@@ -2015,7 +2910,8 @@ static char* expand_strvec_to_string(char **argv)
                        if (HUSH_DEBUG)
                                if (list[n-1] + strlen(list[n-1]) + 1 != list[n])
                                        bb_error_msg_and_die("BUG in varexp3");
-                       list[n][-1] = ' '; /* TODO: or to G.ifs[0]? */
+                       /* bash uses ' ' regardless of $IFS contents */
+                       list[n][-1] = ' ';
                        n++;
                }
        }
@@ -2036,6 +2932,291 @@ static char **expand_assignments(char **argv, int count)
 }
 
 
+#if BB_MMU
+/* never called */
+void re_execute_shell(char ***to_free, const char *s,
+               char *g_argv0, char **g_argv,
+               char **builtin_argv) NORETURN;
+
+static void reset_traps_to_defaults(void)
+{
+       /* This function is always called in a child shell
+        * after fork (not vfork, NOMMU doesn't use this function).
+        */
+       unsigned sig;
+       unsigned mask;
+
+       /* Child shells are not interactive.
+        * SIGTTIN/SIGTTOU/SIGTSTP should not have special handling.
+        * Testcase: (while :; do :; done) + ^Z should background.
+        * Same goes for SIGTERM, SIGHUP, SIGINT.
+        */
+       if (!G.traps && !(G.non_DFL_mask & SPECIAL_INTERACTIVE_SIGS))
+               return; /* already no traps and no SPECIAL_INTERACTIVE_SIGS */
+
+       /* Switching off SPECIAL_INTERACTIVE_SIGS.
+        * Stupid. It can be done with *single* &= op, but we can't use
+        * the fact that G.blocked_set is implemented as a bitmask
+        * in libc... */
+       mask = (SPECIAL_INTERACTIVE_SIGS >> 1);
+       sig = 1;
+       while (1) {
+               if (mask & 1) {
+                       /* Careful. Only if no trap or trap is not "" */
+                       if (!G.traps || !G.traps[sig] || G.traps[sig][0])
+                               sigdelset(&G.blocked_set, sig);
+               }
+               mask >>= 1;
+               if (!mask)
+                       break;
+               sig++;
+       }
+       /* Our homegrown sig mask is saner to work with :) */
+       G.non_DFL_mask &= ~SPECIAL_INTERACTIVE_SIGS;
+
+       /* Resetting all traps to default except empty ones */
+       mask = G.non_DFL_mask;
+       if (G.traps) for (sig = 0; sig < NSIG; sig++, mask >>= 1) {
+               if (!G.traps[sig] || !G.traps[sig][0])
+                       continue;
+               free(G.traps[sig]);
+               G.traps[sig] = NULL;
+               /* There is no signal for 0 (EXIT) */
+               if (sig == 0)
+                       continue;
+               /* There was a trap handler, we just removed it.
+                * But if sig still has non-DFL handling,
+                * we should not unblock the sig. */
+               if (mask & 1)
+                       continue;
+               sigdelset(&G.blocked_set, sig);
+       }
+       sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
+}
+
+#else /* !BB_MMU */
+
+static void re_execute_shell(char ***to_free, const char *s,
+               char *g_argv0, char **g_argv,
+               char **builtin_argv) NORETURN;
+static void re_execute_shell(char ***to_free, const char *s,
+               char *g_argv0, char **g_argv,
+               char **builtin_argv)
+{
+#define NOMMU_HACK_FMT ("-$%x:%x:%x:%x:%x:%llx" IF_HUSH_LOOPS(":%x"))
+       /* delims + 2 * (number of bytes in printed hex numbers) */
+       char param_buf[sizeof(NOMMU_HACK_FMT) + 2 * (sizeof(int)*6 + sizeof(long long)*1)];
+       char *heredoc_argv[4];
+       struct variable *cur;
+# if ENABLE_HUSH_FUNCTIONS
+       struct function *funcp;
+# endif
+       char **argv, **pp;
+       unsigned cnt;
+       unsigned long long empty_trap_mask;
+
+       if (!g_argv0) { /* heredoc */
+               argv = heredoc_argv;
+               argv[0] = (char *) G.argv0_for_re_execing;
+               argv[1] = (char *) "-<";
+               argv[2] = (char *) s;
+               argv[3] = NULL;
+               pp = &argv[3]; /* used as pointer to empty environment */
+               goto do_exec;
+       }
+
+       cnt = 0;
+       pp = builtin_argv;
+       if (pp) while (*pp++)
+               cnt++;
+
+       empty_trap_mask = 0;
+       if (G.traps) {
+               int sig;
+               for (sig = 1; sig < NSIG; sig++) {
+                       if (G.traps[sig] && !G.traps[sig][0])
+                               empty_trap_mask |= 1LL << sig;
+               }
+       }
+
+       sprintf(param_buf, NOMMU_HACK_FMT
+                       , (unsigned) G.root_pid
+                       , (unsigned) G.root_ppid
+                       , (unsigned) G.last_bg_pid
+                       , (unsigned) G.last_exitcode
+                       , cnt
+                       , empty_trap_mask
+                       IF_HUSH_LOOPS(, G.depth_of_loop)
+                       );
+#undef NOMMU_HACK_FMT
+       /* 1:hush 2:-$<pid>:<pid>:<exitcode>:<etc...> <vars...> <funcs...>
+        * 3:-c 4:<cmd> 5:<arg0> <argN...> 6:NULL
+        */
+       cnt += 6;
+       for (cur = G.top_var; cur; cur = cur->next) {
+               if (!cur->flg_export || cur->flg_read_only)
+                       cnt += 2;
+       }
+# if ENABLE_HUSH_FUNCTIONS
+       for (funcp = G.top_func; funcp; funcp = funcp->next)
+               cnt += 3;
+# endif
+       pp = g_argv;
+       while (*pp++)
+               cnt++;
+       *to_free = argv = pp = xzalloc(sizeof(argv[0]) * cnt);
+       *pp++ = (char *) G.argv0_for_re_execing;
+       *pp++ = param_buf;
+       for (cur = G.top_var; cur; cur = cur->next) {
+               if (cur->varstr == hush_version_str)
+                       continue;
+               if (cur->flg_read_only) {
+                       *pp++ = (char *) "-R";
+                       *pp++ = cur->varstr;
+               } else if (!cur->flg_export) {
+                       *pp++ = (char *) "-V";
+                       *pp++ = cur->varstr;
+               }
+       }
+# if ENABLE_HUSH_FUNCTIONS
+       for (funcp = G.top_func; funcp; funcp = funcp->next) {
+               *pp++ = (char *) "-F";
+               *pp++ = funcp->name;
+               *pp++ = funcp->body_as_string;
+       }
+# endif
+       /* We can pass activated traps here. Say, -Tnn:trap_string
+        *
+        * However, POSIX says that subshells reset signals with traps
+        * to SIG_DFL.
+        * I tested bash-3.2 and it not only does that with true subshells
+        * of the form ( list ), but with any forked children shells.
+        * I set trap "echo W" WINCH; and then tried:
+        *
+        * { echo 1; sleep 20; echo 2; } &
+        * while true; do echo 1; sleep 20; echo 2; break; done &
+        * true | { echo 1; sleep 20; echo 2; } | cat
+        *
+        * In all these cases sending SIGWINCH to the child shell
+        * did not run the trap. If I add trap "echo V" WINCH;
+        * _inside_ group (just before echo 1), it works.
+        *
+        * I conclude it means we don't need to pass active traps here.
+        * Even if we would use signal handlers instead of signal masking
+        * in order to implement trap handling,
+        * exec syscall below resets signals to SIG_DFL for us.
+        */
+       *pp++ = (char *) "-c";
+       *pp++ = (char *) s;
+       if (builtin_argv) {
+               while (*++builtin_argv)
+                       *pp++ = *builtin_argv;
+               *pp++ = (char *) "";
+       }
+       *pp++ = g_argv0;
+       while (*g_argv)
+               *pp++ = *g_argv++;
+       /* *pp = NULL; - is already there */
+       pp = environ;
+
+ do_exec:
+       debug_printf_exec("re_execute_shell pid:%d cmd:'%s'\n", getpid(), s);
+       sigprocmask(SIG_SETMASK, &G.inherited_set, NULL);
+       execve(bb_busybox_exec_path, argv, pp);
+       /* Fallback. Useful for init=/bin/hush usage etc */
+       if (argv[0][0] == '/')
+               execve(argv[0], argv, pp);
+       xfunc_error_retval = 127;
+       bb_error_msg_and_die("can't re-execute the shell");
+}
+#endif  /* !BB_MMU */
+
+
+static void setup_heredoc(struct redir_struct *redir)
+{
+       struct fd_pair pair;
+       pid_t pid;
+       int len, written;
+       /* the _body_ of heredoc (misleading field name) */
+       const char *heredoc = redir->rd_filename;
+       char *expanded;
+#if !BB_MMU
+       char **to_free;
+#endif
+
+       expanded = NULL;
+       if (!(redir->rd_dup & HEREDOC_QUOTED)) {
+               expanded = expand_pseudo_dquoted(heredoc);
+               if (expanded)
+                       heredoc = expanded;
+       }
+       len = strlen(heredoc);
+
+       close(redir->rd_fd); /* often saves dup2+close in xmove_fd */
+       xpiped_pair(pair);
+       xmove_fd(pair.rd, redir->rd_fd);
+
+       /* Try writing without forking. Newer kernels have
+        * dynamically growing pipes. Must use non-blocking write! */
+       ndelay_on(pair.wr);
+       while (1) {
+               written = write(pair.wr, heredoc, len);
+               if (written <= 0)
+                       break;
+               len -= written;
+               if (len == 0) {
+                       close(pair.wr);
+                       free(expanded);
+                       return;
+               }
+               heredoc += written;
+       }
+       ndelay_off(pair.wr);
+
+       /* Okay, pipe buffer was not big enough */
+       /* Note: we must not create a stray child (bastard? :)
+        * for the unsuspecting parent process. Child creates a grandchild
+        * and exits before parent execs the process which consumes heredoc
+        * (that exec happens after we return from this function) */
+#if !BB_MMU
+       to_free = NULL;
+#endif
+       pid = vfork();
+       if (pid < 0)
+               bb_perror_msg_and_die("vfork");
+       if (pid == 0) {
+               /* child */
+               disable_restore_tty_pgrp_on_exit();
+               pid = BB_MMU ? fork() : vfork();
+               if (pid < 0)
+                       bb_perror_msg_and_die(BB_MMU ? "fork" : "vfork");
+               if (pid != 0)
+                       _exit(0);
+               /* grandchild */
+               close(redir->rd_fd); /* read side of the pipe */
+#if BB_MMU
+               full_write(pair.wr, heredoc, len); /* may loop or block */
+               _exit(0);
+#else
+               /* Delegate blocking writes to another process */
+               xmove_fd(pair.wr, STDOUT_FILENO);
+               re_execute_shell(&to_free, heredoc, NULL, NULL, NULL);
+#endif
+       }
+       /* parent */
+#if ENABLE_HUSH_FAST
+       G.count_SIGCHLD++;
+//bb_error_msg("[%d] fork in setup_heredoc: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
+#endif
+       enable_restore_tty_pgrp_on_exit();
+#if !BB_MMU
+       free(to_free);
+#endif
+       close(pair.wr);
+       free(expanded);
+       wait(NULL); /* wait till child has died */
+}
+
 /* squirrel != NULL means we squirrel away copies of stdin, stdout,
  * and stderr if they are redirected. */
 static int setup_redirects(struct command *prog, int squirrel[])
@@ -2044,35 +3225,57 @@ static int setup_redirects(struct command *prog, int squirrel[])
        struct redir_struct *redir;
 
        for (redir = prog->redirects; redir; redir = redir->next) {
-               if (redir->dup == -1 && redir->rd_filename == NULL) {
-                       /* something went wrong in the parse.  Pretend it didn't happen */
+               if (redir->rd_type == REDIRECT_HEREDOC2) {
+                       /* rd_fd<<HERE case */
+                       if (squirrel && redir->rd_fd < 3
+                        && squirrel[redir->rd_fd] < 0
+                       ) {
+                               squirrel[redir->rd_fd] = dup(redir->rd_fd);
+                       }
+                       /* for REDIRECT_HEREDOC2, rd_filename holds _contents_
+                        * of the heredoc */
+                       debug_printf_parse("set heredoc '%s'\n",
+                                       redir->rd_filename);
+                       setup_heredoc(redir);
                        continue;
                }
-               if (redir->dup == -1) {
+
+               if (redir->rd_dup == REDIRFD_TO_FILE) {
+                       /* rd_fd<*>file case (<*> is <,>,>>,<>) */
                        char *p;
+                       if (redir->rd_filename == NULL) {
+                               /* Something went wrong in the parse.
+                                * Pretend it didn't happen */
+                               bb_error_msg("bug in redirect parse");
+                               continue;
+                       }
                        mode = redir_table[redir->rd_type].mode;
-//TODO: check redir for names like '\\'
                        p = expand_string_to_string(redir->rd_filename);
                        openfd = open_or_warn(p, mode);
                        free(p);
                        if (openfd < 0) {
                        /* this could get lost if stderr has been redirected, but
-                          bash and ash both lose it as well (though zsh doesn't!) */
+                        * bash and ash both lose it as well (though zsh doesn't!) */
+//what the above comment tries to say?
                                return 1;
                        }
                } else {
-                       openfd = redir->dup;
+                       /* rd_fd<*>rd_dup or rd_fd<*>- cases */
+                       openfd = redir->rd_dup;
                }
 
-               if (openfd != redir->fd) {
-                       if (squirrel && redir->fd < 3) {
-                               squirrel[redir->fd] = dup(redir->fd);
+               if (openfd != redir->rd_fd) {
+                       if (squirrel && redir->rd_fd < 3
+                        && squirrel[redir->rd_fd] < 0
+                       ) {
+                               squirrel[redir->rd_fd] = dup(redir->rd_fd);
                        }
-                       if (openfd == -3) {
-                               //close(openfd); // close(-3) ??!
+                       if (openfd == REDIRFD_CLOSE) {
+                               /* "n>-" means "close me" */
+                               close(redir->rd_fd);
                        } else {
-                               dup2(openfd, redir->fd);
-                               if (redir->dup == -1)
+                               xdup2(openfd, redir->rd_fd);
+                               if (redir->rd_dup == REDIRFD_TO_FILE)
                                        close(openfd);
                        }
                }
@@ -2093,14 +3296,10 @@ static void restore_redirects(int squirrel[])
 }
 
 
-#if !defined(DEBUG_CLEAN)
-#define free_pipe_list(head, indent) free_pipe_list(head)
-#define free_pipe(pi, indent)        free_pipe(pi)
-#endif
-static void free_pipe_list(struct pipe *head, int indent);
+static void free_pipe_list(struct pipe *head);
 
 /* Return code is the exit status of the pipe */
-static void free_pipe(struct pipe *pi, int indent)
+static void free_pipe(struct pipe *pi)
 {
        char **p;
        struct command *command;
@@ -2109,92 +3308,379 @@ static void free_pipe(struct pipe *pi, int indent)
 
        if (pi->stopped_cmds > 0) /* why? */
                return;
-       debug_printf_clean("%s run pipe: (pid %d)\n", indenter(indent), getpid());
+       debug_printf_clean("run pipe: (pid %d)\n", getpid());
        for (i = 0; i < pi->num_cmds; i++) {
                command = &pi->cmds[i];
-               debug_printf_clean("%s  command %d:\n", indenter(indent), i);
+               debug_printf_clean("  command %d:\n", i);
                if (command->argv) {
                        for (a = 0, p = command->argv; *p; a++, p++) {
-                               debug_printf_clean("%s   argv[%d] = %s\n", indenter(indent), a, *p);
+                               debug_printf_clean("   argv[%d] = %s\n", a, *p);
                        }
                        free_strings(command->argv);
                        command->argv = NULL;
                }
                /* not "else if": on syntax error, we may have both! */
                if (command->group) {
-                       debug_printf_clean("%s   begin group (grp_type:%d)\n", indenter(indent), command->grp_type);
-                       free_pipe_list(command->group, indent+3);
-                       debug_printf_clean("%s   end group\n", indenter(indent));
+                       debug_printf_clean("   begin group (cmd_type:%d)\n",
+                                       command->cmd_type);
+                       free_pipe_list(command->group);
+                       debug_printf_clean("   end group\n");
                        command->group = NULL;
                }
+               /* else is crucial here.
+                * If group != NULL, child_func is meaningless */
+#if ENABLE_HUSH_FUNCTIONS
+               else if (command->child_func) {
+                       debug_printf_exec("cmd %p releases child func at %p\n", command, command->child_func);
+                       command->child_func->parent_cmd = NULL;
+               }
+#endif
 #if !BB_MMU
                free(command->group_as_string);
                command->group_as_string = NULL;
 #endif
                for (r = command->redirects; r; r = rnext) {
-                       debug_printf_clean("%s   redirect %d%s", indenter(indent), r->fd, redir_table[r->rd_type].descrip);
-                       if (r->dup == -1) {
-                               /* guard against the case >$FOO, where foo is unset or blank */
-                               if (r->rd_filename) {
-                                       debug_printf_clean(" %s\n", r->rd_filename);
-                                       free(r->rd_filename);
-                                       r->rd_filename = NULL;
-                               }
-                       } else {
-                               debug_printf_clean("&%d\n", r->dup);
+                       debug_printf_clean("   redirect %d%s",
+                                       r->rd_fd, redir_table[r->rd_type].descrip);
+                       /* guard against the case >$FOO, where foo is unset or blank */
+                       if (r->rd_filename) {
+                               debug_printf_clean(" fname:'%s'\n", r->rd_filename);
+                               free(r->rd_filename);
+                               r->rd_filename = NULL;
+                       }
+                       debug_printf_clean(" rd_dup:%d\n", r->rd_dup);
+                       rnext = r->next;
+                       free(r);
+               }
+               command->redirects = NULL;
+       }
+       free(pi->cmds);   /* children are an array, they get freed all at once */
+       pi->cmds = NULL;
+#if ENABLE_HUSH_JOB
+       free(pi->cmdtext);
+       pi->cmdtext = NULL;
+#endif
+}
+
+static void free_pipe_list(struct pipe *head)
+{
+       struct pipe *pi, *next;
+
+       for (pi = head; pi; pi = next) {
+#if HAS_KEYWORDS
+               debug_printf_clean(" pipe reserved word %d\n", pi->res_word);
+#endif
+               free_pipe(pi);
+               debug_printf_clean("pipe followup code %d\n", pi->followup);
+               next = pi->next;
+               /*pi->next = NULL;*/
+               free(pi);
+       }
+}
+
+
+static int run_list(struct pipe *pi);
+#if BB_MMU
+#define parse_stream(pstring, input, end_trigger) \
+       parse_stream(input, end_trigger)
+#endif
+static struct pipe *parse_stream(char **pstring,
+               struct in_str *input,
+               int end_trigger);
+static void parse_and_run_string(const char *s);
+
+
+static char *find_in_path(const char *arg)
+{
+       char *ret = NULL;
+       const char *PATH = get_local_var_value("PATH");
+
+       if (!PATH)
+               return NULL;
+
+       while (1) {
+               const char *end = strchrnul(PATH, ':');
+               int sz = end - PATH; /* must be int! */
+
+               free(ret);
+               if (sz != 0) {
+                       ret = xasprintf("%.*s/%s", sz, PATH, arg);
+               } else {
+                       /* We have xxx::yyyy in $PATH,
+                        * it means "use current dir" */
+                       ret = xstrdup(arg);
+               }
+               if (access(ret, F_OK) == 0)
+                       break;
+
+               if (*end == '\0') {
+                       free(ret);
+                       return NULL;
+               }
+               PATH = end + 1;
+       }
+
+       return ret;
+}
+
+static const struct built_in_command* find_builtin_helper(const char *name,
+               const struct built_in_command *x,
+               const struct built_in_command *end)
+{
+       while (x != end) {
+               if (strcmp(name, x->b_cmd) != 0) {
+                       x++;
+                       continue;
+               }
+               debug_printf_exec("found builtin '%s'\n", name);
+               return x;
+       }
+       return NULL;
+}
+static const struct built_in_command* find_builtin1(const char *name)
+{
+       return find_builtin_helper(name, bltins1, &bltins1[ARRAY_SIZE(bltins1)]);
+}
+static const struct built_in_command* find_builtin(const char *name)
+{
+       const struct built_in_command *x = find_builtin1(name);
+       if (x)
+               return x;
+       return find_builtin_helper(name, bltins2, &bltins2[ARRAY_SIZE(bltins2)]);
+}
+
+#if ENABLE_HUSH_FUNCTIONS
+static struct function **find_function_slot(const char *name)
+{
+       struct function **funcpp = &G.top_func;
+       while (*funcpp) {
+               if (strcmp(name, (*funcpp)->name) == 0) {
+                       break;
+               }
+               funcpp = &(*funcpp)->next;
+       }
+       return funcpp;
+}
+
+static const struct function *find_function(const char *name)
+{
+       const struct function *funcp = *find_function_slot(name);
+       if (funcp)
+               debug_printf_exec("found function '%s'\n", name);
+       return funcp;
+}
+
+/* Note: takes ownership on name ptr */
+static struct function *new_function(char *name)
+{
+       struct function **funcpp = find_function_slot(name);
+       struct function *funcp = *funcpp;
+
+       if (funcp != NULL) {
+               struct command *cmd = funcp->parent_cmd;
+               debug_printf_exec("func %p parent_cmd %p\n", funcp, cmd);
+               if (!cmd) {
+                       debug_printf_exec("freeing & replacing function '%s'\n", funcp->name);
+                       free(funcp->name);
+                       /* Note: if !funcp->body, do not free body_as_string!
+                        * This is a special case of "-F name body" function:
+                        * body_as_string was not malloced! */
+                       if (funcp->body) {
+                               free_pipe_list(funcp->body);
+# if !BB_MMU
+                               free(funcp->body_as_string);
+# endif
+                       }
+               } else {
+                       debug_printf_exec("reinserting in tree & replacing function '%s'\n", funcp->name);
+                       cmd->argv[0] = funcp->name;
+                       cmd->group = funcp->body;
+# if !BB_MMU
+                       cmd->group_as_string = funcp->body_as_string;
+# endif
+               }
+       } else {
+               debug_printf_exec("remembering new function '%s'\n", name);
+               funcp = *funcpp = xzalloc(sizeof(*funcp));
+               /*funcp->next = NULL;*/
+       }
+
+       funcp->name = name;
+       return funcp;
+}
+
+static void unset_func(const char *name)
+{
+       struct function **funcpp = find_function_slot(name);
+       struct function *funcp = *funcpp;
+
+       if (funcp != NULL) {
+               debug_printf_exec("freeing function '%s'\n", funcp->name);
+               *funcpp = funcp->next;
+               /* funcp is unlinked now, deleting it.
+                * Note: if !funcp->body, the function was created by
+                * "-F name body", do not free ->body_as_string
+                * and ->name as they were not malloced. */
+               if (funcp->body) {
+                       free_pipe_list(funcp->body);
+                       free(funcp->name);
+# if !BB_MMU
+                       free(funcp->body_as_string);
+# endif
+               }
+               free(funcp);
+       }
+}
+
+# if BB_MMU
+#define exec_function(to_free, funcp, argv) \
+       exec_function(funcp, argv)
+# endif
+static void exec_function(char ***to_free,
+               const struct function *funcp,
+               char **argv) NORETURN;
+static void exec_function(char ***to_free,
+               const struct function *funcp,
+               char **argv)
+{
+# if BB_MMU
+       int n = 1;
+
+       argv[0] = G.global_argv[0];
+       G.global_argv = argv;
+       while (*++argv)
+               n++;
+       G.global_argc = n;
+       /* On MMU, funcp->body is always non-NULL */
+       n = run_list(funcp->body);
+       fflush_all();
+       _exit(n);
+# else
+       re_execute_shell(to_free,
+                       funcp->body_as_string,
+                       G.global_argv[0],
+                       argv + 1,
+                       NULL);
+# endif
+}
+
+static int run_function(const struct function *funcp, char **argv)
+{
+       int rc;
+       save_arg_t sv;
+       smallint sv_flg;
+
+       save_and_replace_G_args(&sv, argv);
+
+       /* "we are in function, ok to use return" */
+       sv_flg = G.flag_return_in_progress;
+       G.flag_return_in_progress = -1;
+# if ENABLE_HUSH_LOCAL
+       G.func_nest_level++;
+# endif
+
+       /* On MMU, funcp->body is always non-NULL */
+# if !BB_MMU
+       if (!funcp->body) {
+               /* Function defined by -F */
+               parse_and_run_string(funcp->body_as_string);
+               rc = G.last_exitcode;
+       } else
+# endif
+       {
+               rc = run_list(funcp->body);
+       }
+
+# if ENABLE_HUSH_LOCAL
+       {
+               struct variable *var;
+               struct variable **var_pp;
+
+               var_pp = &G.top_var;
+               while ((var = *var_pp) != NULL) {
+                       if (var->func_nest_level < G.func_nest_level) {
+                               var_pp = &var->next;
+                               continue;
                        }
-                       rnext = r->next;
-                       free(r);
+                       /* Unexport */
+                       if (var->flg_export)
+                               bb_unsetenv(var->varstr);
+                       /* Remove from global list */
+                       *var_pp = var->next;
+                       /* Free */
+                       if (!var->max_len)
+                               free(var->varstr);
+                       free(var);
                }
-               command->redirects = NULL;
+               G.func_nest_level--;
        }
-       free(pi->cmds);   /* children are an array, they get freed all at once */
-       pi->cmds = NULL;
-#if ENABLE_HUSH_JOB
-       free(pi->cmdtext);
-       pi->cmdtext = NULL;
-#endif
+# endif
+       G.flag_return_in_progress = sv_flg;
+
+       restore_G_args(&sv, argv);
+
+       return rc;
 }
+#endif /* ENABLE_HUSH_FUNCTIONS */
 
-static void free_pipe_list(struct pipe *head, int indent)
-{
-       struct pipe *pi, *next;
 
-       for (pi = head; pi; pi = next) {
-#if HAS_KEYWORDS
-               debug_printf_clean("%s pipe reserved mode %d\n", indenter(indent), pi->res_word);
+#if BB_MMU
+#define exec_builtin(to_free, x, argv) \
+       exec_builtin(x, argv)
+#else
+#define exec_builtin(to_free, x, argv) \
+       exec_builtin(to_free, argv)
+#endif
+static void exec_builtin(char ***to_free,
+               const struct built_in_command *x,
+               char **argv) NORETURN;
+static void exec_builtin(char ***to_free,
+               const struct built_in_command *x,
+               char **argv)
+{
+#if BB_MMU
+       int rcode = x->b_function(argv);
+       fflush_all();
+       _exit(rcode);
+#else
+       /* On NOMMU, we must never block!
+        * Example: { sleep 99 | read line; } & echo Ok
+        */
+       re_execute_shell(to_free,
+                       argv[0],
+                       G.global_argv[0],
+                       G.global_argv + 1,
+                       argv);
 #endif
-               free_pipe(pi, indent);
-               debug_printf_clean("%s pipe followup code %d\n", indenter(indent), pi->followup);
-               next = pi->next;
-               /*pi->next = NULL;*/
-               free(pi);
-       }
 }
 
 
-#if !BB_MMU
-typedef struct nommu_save_t {
-       char **new_env;
-       char **old_env;
-       char **argv;
-} nommu_save_t;
-#else
+static void execvp_or_die(char **argv) NORETURN;
+static void execvp_or_die(char **argv)
+{
+       debug_printf_exec("execing '%s'\n", argv[0]);
+       sigprocmask(SIG_SETMASK, &G.inherited_set, NULL);
+       execvp(argv[0], argv);
+       bb_perror_msg("can't execute '%s'", argv[0]);
+       _exit(127); /* bash compat */
+}
+
+#if BB_MMU
 #define pseudo_exec_argv(nommu_save, argv, assignment_cnt, argv_expanded) \
        pseudo_exec_argv(argv, assignment_cnt, argv_expanded)
 #define pseudo_exec(nommu_save, command, argv_expanded) \
        pseudo_exec(command, argv_expanded)
 #endif
 
-/* Called after [v]fork() in run_pipe(), or from builtin_exec().
+/* Called after [v]fork() in run_pipe, or from builtin_exec.
  * Never returns.
- * XXX no exit() here.  If you don't exec, use _exit instead.
+ * Don't exit() here.  If you don't exec, use _exit instead.
  * The at_exit handlers apparently confuse the calling process,
  * in particular stdin handling.  Not sure why? -- because of vfork! (vda) */
 static void pseudo_exec_argv(nommu_save_t *nommu_save,
                char **argv, int assignment_cnt,
                char **argv_expanded) NORETURN;
-static void pseudo_exec_argv(nommu_save_t *nommu_save,
+static NOINLINE void pseudo_exec_argv(nommu_save_t *nommu_save,
                char **argv, int assignment_cnt,
                char **argv_expanded)
 {
@@ -2206,11 +3692,13 @@ static void pseudo_exec_argv(nommu_save_t *nommu_save,
 
        new_env = expand_assignments(argv, assignment_cnt);
 #if BB_MMU
-       putenv_all(new_env);
+       set_vars_and_save_old(new_env);
        free(new_env); /* optional */
+       /* we can also destroy set_vars_and_save_old's return value,
+        * to save memory */
 #else
        nommu_save->new_env = new_env;
-       nommu_save->old_env = putenv_all_and_save_old(new_env);
+       nommu_save->old_vars = set_vars_and_save_old(new_env);
 #endif
        if (argv_expanded) {
                argv = argv_expanded;
@@ -2221,43 +3709,48 @@ static void pseudo_exec_argv(nommu_save_t *nommu_save,
 #endif
        }
 
-       /* On NOMMU, we must never block!
-        * Example: { sleep 99999 | read line } & echo Ok
-        * read builtin will block on read syscall, leaving parent blocked
-        * in vfork. Therefore we can't do this:
-        */
-#if BB_MMU
+#if ENABLE_FEATURE_SH_STANDALONE || BB_MMU
+       if (strchr(argv[0], '/') != NULL)
+               goto skip;
+#endif
+
        /* Check if the command matches any of the builtins.
         * Depending on context, this might be redundant.  But it's
         * easier to waste a few CPU cycles than it is to figure out
         * if this is one of those cases.
         */
        {
-               int rcode;
+               /* On NOMMU, it is more expensive to re-execute shell
+                * just in order to run echo or test builtin.
+                * It's better to skip it here and run corresponding
+                * non-builtin later. */
                const struct built_in_command *x;
-               for (x = bltins; x != &bltins[ARRAY_SIZE(bltins)]; x++) {
-                       if (strcmp(argv[0], x->cmd) == 0) {
-                               debug_printf_exec("running builtin '%s'\n",
-                                               argv[0]);
-                               rcode = x->function(argv);
-                               fflush(NULL);
-                               _exit(rcode);
-                       }
+               x = BB_MMU ? find_builtin(argv[0]) : find_builtin1(argv[0]);
+               if (x) {
+                       exec_builtin(&nommu_save->argv_from_re_execing, x, argv);
+               }
+       }
+#if ENABLE_HUSH_FUNCTIONS
+       /* Check if the command matches any functions */
+       {
+               const struct function *funcp = find_function(argv[0]);
+               if (funcp) {
+                       exec_function(&nommu_save->argv_from_re_execing, funcp, argv);
                }
        }
 #endif
 
 #if ENABLE_FEATURE_SH_STANDALONE
        /* Check if the command matches any busybox applets */
-       if (strchr(argv[0], '/') == NULL) {
+       {
                int a = find_applet_by_name(argv[0]);
                if (a >= 0) {
-#if BB_MMU /* see above why on NOMMU it is not allowed */
+# if BB_MMU /* see above why on NOMMU it is not allowed */
                        if (APPLET_IS_NOEXEC(a)) {
                                debug_printf_exec("running applet '%s'\n", argv[0]);
                                run_applet_no_and_exit(a, argv);
                        }
-#endif
+# endif
                        /* Re-exec ourselves */
                        debug_printf_exec("re-execing applet '%s'\n", argv[0]);
                        sigprocmask(SIG_SETMASK, &G.inherited_set, NULL);
@@ -2268,136 +3761,13 @@ static void pseudo_exec_argv(nommu_save_t *nommu_save,
        }
 #endif
 
-       debug_printf_exec("execing '%s'\n", argv[0]);
-       sigprocmask(SIG_SETMASK, &G.inherited_set, NULL);
-       execvp(argv[0], argv);
-       bb_perror_msg("can't exec '%s'", argv[0]);
-       _exit(EXIT_FAILURE);
-}
-
-#if BB_MMU
-static void reset_traps_to_defaults(void)
-{
-       unsigned sig;
-       int dirty;
-
-       if (!G.traps)
-               return;
-       dirty = 0;
-       for (sig = 0; sig < NSIG; sig++) {
-               if (!G.traps[sig])
-                       continue;
-               free(G.traps[sig]);
-               G.traps[sig] = NULL;
-               /* There is no signal for 0 (EXIT) */
-               if (sig == 0)
-                       continue;
-               /* there was a trap handler, we are removing it
-                * (if sig has non-DFL handling,
-                * we don't need to do anything) */
-               if (sig < 32 && (G.non_DFL_mask & (1 << sig)))
-                       continue;
-               sigdelset(&G.blocked_set, sig);
-               dirty = 1;
-       }
-       if (dirty)
-               sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
-}
-#define clean_up_after_re_execute() ((void)0)
-
-#else /* !BB_MMU */
-
-static void re_execute_shell(const char *s) NORETURN;
-static void re_execute_shell(const char *s)
-{
-       struct variable *cur;
-       char **argv, **pp, **pp2;
-       unsigned cnt;
-
-       /* 1:hush 2:-$<pid> 3:-!<pid> 4:-?<exitcode> 5:-D<depth> <vars...>
-        * 6:-c 7:<cmd> <argN...> 8:NULL
-        */
-       cnt = 8 + G.global_argc;
-       for (cur = G.top_var; cur; cur = cur->next) {
-               if (!cur->flg_export || cur->flg_read_only)
-                       cnt += 2;
-       }
-       G.argv_from_re_execing = pp = xzalloc(sizeof(argv[0]) * cnt);
-       *pp++ = (char *) G.argv0_for_re_execing;
-       *pp++ = xasprintf("-$%u", (unsigned) G.root_pid);
-       *pp++ = xasprintf("-!%u", (unsigned) G.last_bg_pid);
-       *pp++ = xasprintf("-?%u", (unsigned) G.last_return_code);
-#if ENABLE_HUSH_LOOPS
-       *pp++ = xasprintf("-D%u", G.depth_of_loop);
-#endif
-       for (cur = G.top_var; cur; cur = cur->next) {
-               if (cur->varstr == hush_version_str)
-                       continue;
-               if (cur->flg_read_only) {
-                       *pp++ = (char *) "-R";
-                       *pp++ = cur->varstr;
-               } else if (!cur->flg_export) {
-                       *pp++ = (char *) "-V";
-                       *pp++ = cur->varstr;
-               }
-       }
-//TODO: pass functions
-       /* We can pass activated traps here. Say, -Tnn:trap_string
-        *
-        * However, POSIX says that subshells reset signals with traps
-        * to SIG_DFL.
-        * I tested bash-3.2 and it not only does that with true subshells
-        * of the form ( list ), but with any forked children shells.
-        * I set trap "echo W" WINCH; and then tried:
-        *
-        * { echo 1; sleep 20; echo 2; } &
-        * while true; do echo 1; sleep 20; echo 2; break; done &
-        * true | { echo 1; sleep 20; echo 2; } | cat
-        *
-        * In all these cases sending SIGWINCH to the child shell
-        * did not run the trap. If I add trap "echo V" WINCH;
-        * _inside_ group (just before echo 1), it works.
-        *
-        * I conclude it means we don't need to pass active traps here.
-        * exec syscall below resets them to SIG_DFL for us.
-        */
-       *pp++ = (char *) "-c";
-       *pp++ = (char *) s;
-       pp2 = G.global_argv;
-       while (*pp2)
-               *pp++ = *pp2++;
-       /* *pp = NULL; - is already there */
-
-       debug_printf_exec("re_execute_shell pid:%d cmd:'%s'\n", getpid(), s);
-       sigprocmask(SIG_SETMASK, &G.inherited_set, NULL);
-       execv(bb_busybox_exec_path, G.argv_from_re_execing);
-       /* Fallback. Useful for init=/bin/hush usage etc */
-       if (G.argv0_for_re_execing[0] == '/')
-               execv(G.argv0_for_re_execing, G.argv_from_re_execing);
-       xfunc_error_retval = 127;
-       bb_error_msg_and_die("can't re-execute the shell");
-}
-
-static void clean_up_after_re_execute(void)
-{
-       char **pp = G.argv_from_re_execing;
-       if (pp) {
-               /* Must match re_execute_shell's allocations */
-               free(pp[1]);
-               free(pp[2]);
-               free(pp[3]);
-#if ENABLE_HUSH_LOOPS
-               free(pp[4]);
+#if ENABLE_FEATURE_SH_STANDALONE || BB_MMU
+ skip:
 #endif
-               free(pp);
-               G.argv_from_re_execing = NULL;
-       }
+       execvp_or_die(argv);
 }
-#endif
-
-static int run_list(struct pipe *pi);
 
-/* Called after [v]fork() in run_pipe()
+/* Called after [v]fork() in run_pipe
  */
 static void pseudo_exec(nommu_save_t *nommu_save,
                struct command *command,
@@ -2427,7 +3797,11 @@ static void pseudo_exec(nommu_save_t *nommu_save,
                 * since this process is about to exit */
                _exit(rcode);
 #else
-               re_execute_shell(command->group_as_string);
+               re_execute_shell(&nommu_save->argv_from_re_execing,
+                               command->group_as_string,
+                               G.global_argv[0],
+                               G.global_argv + 1,
+                               NULL);
 #endif
        }
 
@@ -2455,8 +3829,11 @@ static const char *get_cmdtext(struct pipe *pi)
        }
 
        len = 0;
-       do len += strlen(*argv) + 1; while (*++argv);
-       pi->cmdtext = p = xmalloc(len);
+       do {
+               len += strlen(*argv) + 1;
+       } while (*++argv);
+       p = xmalloc(len);
+       pi->cmdtext = p;
        argv = pi->cmds[0].argv;
        do {
                len = strlen(*argv);
@@ -2470,44 +3847,36 @@ static const char *get_cmdtext(struct pipe *pi)
 
 static void insert_bg_job(struct pipe *pi)
 {
-       struct pipe *thejob;
+       struct pipe *job, **jobp;
        int i;
 
        /* Linear search for the ID of the job to use */
        pi->jobid = 1;
-       for (thejob = G.job_list; thejob; thejob = thejob->next)
-               if (thejob->jobid >= pi->jobid)
-                       pi->jobid = thejob->jobid + 1;
-
-       /* Add thejob to the list of running jobs */
-       if (!G.job_list) {
-               thejob = G.job_list = xmalloc(sizeof(*thejob));
-       } else {
-               for (thejob = G.job_list; thejob->next; thejob = thejob->next)
-                       continue;
-               thejob->next = xmalloc(sizeof(*thejob));
-               thejob = thejob->next;
-       }
-
-       /* Physically copy the struct job */
-       memcpy(thejob, pi, sizeof(struct pipe));
-       thejob->cmds = xzalloc(sizeof(pi->cmds[0]) * pi->num_cmds);
-       /* We cannot copy entire pi->cmds[] vector! Double free()s will happen */
+       for (job = G.job_list; job; job = job->next)
+               if (job->jobid >= pi->jobid)
+                       pi->jobid = job->jobid + 1;
+
+       /* Add job to the list of running jobs */
+       jobp = &G.job_list;
+       while ((job = *jobp) != NULL)
+               jobp = &job->next;
+       job = *jobp = xmalloc(sizeof(*job));
+
+       *job = *pi; /* physical copy */
+       job->next = NULL;
+       job->cmds = xzalloc(sizeof(pi->cmds[0]) * pi->num_cmds);
+       /* Cannot copy entire pi->cmds[] vector! This causes double frees */
        for (i = 0; i < pi->num_cmds; i++) {
-// TODO: do we really need to have so many fields which are just dead weight
-// at execution stage?
-               thejob->cmds[i].pid = pi->cmds[i].pid;
+               job->cmds[i].pid = pi->cmds[i].pid;
                /* all other fields are not used and stay zero */
        }
-       thejob->next = NULL;
-       thejob->cmdtext = xstrdup(get_cmdtext(pi));
+       job->cmdtext = xstrdup(get_cmdtext(pi));
 
-       /* We don't wait for background thejobs to return -- append it
-          to the list of backgrounded thejobs and leave it alone */
        if (G_interactive_fd)
-               printf("[%d] %d %s\n", thejob->jobid, thejob->cmds[0].pid, thejob->cmdtext);
-       G.last_bg_pid = thejob->cmds[0].pid;
-       G.last_jobid = thejob->jobid;
+               printf("[%d] %d %s\n", job->jobid, job->cmds[0].pid, job->cmdtext);
+       /* Last command's pid goes to $! */
+       G.last_bg_pid = job->cmds[job->num_cmds - 1].pid;
+       G.last_jobid = job->jobid;
 }
 
 static void remove_bg_job(struct pipe *pi)
@@ -2533,7 +3902,7 @@ static void delete_finished_bg_job(struct pipe *pi)
 {
        remove_bg_job(pi);
        pi->stopped_cmds = 0;
-       free_pipe(pi, 0);
+       free_pipe(pi);
        free(pi);
 }
 #endif /* JOB */
@@ -2552,39 +3921,57 @@ static int checkjobs(struct pipe* fg_pipe)
 
        debug_printf_jobs("checkjobs %p\n", fg_pipe);
 
-       errno = 0;
-//     if (G.handled_SIGCHLD == G.count_SIGCHLD)
-//             /* avoid doing syscall, nothing there anyway */
-//             return rcode;
-
        attributes = WUNTRACED;
        if (fg_pipe == NULL)
                attributes |= WNOHANG;
 
+       errno = 0;
+#if ENABLE_HUSH_FAST
+       if (G.handled_SIGCHLD == G.count_SIGCHLD) {
+//bb_error_msg("[%d] checkjobs: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d children?:%d fg_pipe:%p",
+//getpid(), G.count_SIGCHLD, G.handled_SIGCHLD, G.we_have_children, fg_pipe);
+               /* There was neither fork nor SIGCHLD since last waitpid */
+               /* Avoid doing waitpid syscall if possible */
+               if (!G.we_have_children) {
+                       errno = ECHILD;
+                       return -1;
+               }
+               if (fg_pipe == NULL) { /* is WNOHANG set? */
+                       /* We have children, but they did not exit
+                        * or stop yet (we saw no SIGCHLD) */
+                       return 0;
+               }
+               /* else: !WNOHANG, waitpid will block, can't short-circuit */
+       }
+#endif
+
 /* Do we do this right?
  * bash-3.00# sleep 20 | false
  * <ctrl-Z pressed>
  * [3]+  Stopped          sleep 20 | false
  * bash-3.00# echo $?
  * 1   <========== bg pipe is not fully done, but exitcode is already known!
+ * [hush 1.14.0: yes we do it right]
  */
-
-//FIXME: non-interactive bash does not continue even if all processes in fg pipe
-//are stopped. Testcase: "cat | cat" in a script (not on command line)
-// + killall -STOP cat
-
  wait_more:
        while (1) {
                int i;
                int dead;
 
-//             i = G.count_SIGCHLD;
+#if ENABLE_HUSH_FAST
+               i = G.count_SIGCHLD;
+#endif
                childpid = waitpid(-1, &status, attributes);
                if (childpid <= 0) {
                        if (childpid && errno != ECHILD)
                                bb_perror_msg("waitpid");
-//                     else /* Until next SIGCHLD, waitpid's are useless */
-//                             G.handled_SIGCHLD = i;
+#if ENABLE_HUSH_FAST
+                       else { /* Until next SIGCHLD, waitpid's are useless */
+                               G.we_have_children = (childpid == 0);
+                               G.handled_SIGCHLD = i;
+//bb_error_msg("[%d] checkjobs: waitpid returned <= 0, G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
+                       }
+#endif
                        break;
                }
                dead = WIFEXITED(status) || WIFSIGNALED(status);
@@ -2606,13 +3993,23 @@ static int checkjobs(struct pipe* fg_pipe)
                                debug_printf_jobs("check pid %d\n", fg_pipe->cmds[i].pid);
                                if (fg_pipe->cmds[i].pid != childpid)
                                        continue;
-                               /* printf("process %d exit %d\n", i, WEXITSTATUS(status)); */
                                if (dead) {
                                        fg_pipe->cmds[i].pid = 0;
                                        fg_pipe->alive_cmds--;
                                        if (i == fg_pipe->num_cmds - 1) {
                                                /* last process gives overall exitstatus */
                                                rcode = WEXITSTATUS(status);
+                                               /* bash prints killer signal's name for *last*
+                                                * process in pipe (prints just newline for SIGINT).
+                                                * Mimic this. Example: "sleep 5" + (^\ or kill -QUIT)
+                                                */
+                                               if (WIFSIGNALED(status)) {
+                                                       int sig = WTERMSIG(status);
+                                                       printf("%s\n", sig == SIGINT ? "" : get_signame(sig));
+                                                       /* TODO: MIPS has 128 sigs (1..128), what if sig==128 here?
+                                                        * Maybe we need to use sig | 128? */
+                                                       rcode = sig + 128;
+                                               }
                                                IF_HAS_KEYWORDS(if (fg_pipe->pi_inverted) rcode = !rcode;)
                                        }
                                } else {
@@ -2622,12 +4019,19 @@ static int checkjobs(struct pipe* fg_pipe)
                                debug_printf_jobs("fg_pipe: alive_cmds %d stopped_cmds %d\n",
                                                fg_pipe->alive_cmds, fg_pipe->stopped_cmds);
                                if (fg_pipe->alive_cmds - fg_pipe->stopped_cmds <= 0) {
-                                       /* All processes in fg pipe have exited/stopped */
+                                       /* All processes in fg pipe have exited or stopped */
+/* Note: *non-interactive* bash does not continue if all processes in fg pipe
+ * are stopped. Testcase: "cat | cat" in a script (not on command line!)
+ * and "killall -STOP cat" */
+                                       if (G_interactive_fd) {
 #if ENABLE_HUSH_JOB
-                                       if (fg_pipe->alive_cmds)
-                                               insert_bg_job(fg_pipe);
+                                               if (fg_pipe->alive_cmds)
+                                                       insert_bg_job(fg_pipe);
 #endif
-                                       return rcode;
+                                               return rcode;
+                                       }
+                                       if (!fg_pipe->alive_cmds)
+                                               return rcode;
                                }
                                /* There are still running processes in the fg pipe */
                                goto wait_more; /* do waitpid again */
@@ -2675,10 +4079,12 @@ static int checkjobs_and_fg_shell(struct pipe* fg_pipe)
 {
        pid_t p;
        int rcode = checkjobs(fg_pipe);
-       /* Job finished, move the shell to the foreground */
-       p = getpgid(0); /* pgid of our process */
-       debug_printf_jobs("fg'ing ourself: getpgid(0)=%d\n", (int)p);
-       tcsetpgrp(G_interactive_fd, p);
+       if (G_saved_tty_pgrp) {
+               /* Job finished, move the shell to the foreground */
+               p = getpgrp(); /* our process group id */
+               debug_printf_jobs("fg'ing ourself: getpgrp()=%d\n", (int)p);
+               tcsetpgrp(G_interactive_fd, p);
+       }
        return rcode;
 }
 #endif
@@ -2702,19 +4108,18 @@ static int checkjobs_and_fg_shell(struct pipe* fg_pipe)
  * cmd || ...  { list } || ...
  * If it is, then we can run cmd as a builtin, NOFORK [do we do this?],
  * or (if SH_STANDALONE) an applet, and we can run the { list }
- * with run_list(). If it isn't one of these, we fork and exec cmd.
+ * with run_list. If it isn't one of these, we fork and exec cmd.
  *
  * Cases when we must fork:
  * non-single:   cmd | cmd
  * backgrounded: cmd &     { list } &
  * subshell:     ( list ) [&]
  */
-static int run_pipe(struct pipe *pi)
+static NOINLINE int run_pipe(struct pipe *pi)
 {
        static const char *const null_ptr = NULL;
        int i;
        int nextin;
-       int pipefds[2];         /* pipefds[0] is for reading */
        struct command *command;
        char **argv_expanded;
        char **argv;
@@ -2724,15 +4129,16 @@ static int run_pipe(struct pipe *pi)
        int rcode;
 
        debug_printf_exec("run_pipe start: members:%d\n", pi->num_cmds);
+       debug_enter();
 
-       USE_HUSH_JOB(pi->pgrp = -1;)
+       IF_HUSH_JOB(pi->pgrp = -1;)
        pi->stopped_cmds = 0;
        command = &(pi->cmds[0]);
        argv_expanded = NULL;
 
        if (pi->num_cmds != 1
         || pi->followup == PIPE_BG
-        || command->grp_type == GRP_SUBSHELL
+        || command->cmd_type == CMD_SUBSHELL
        ) {
                goto must_fork;
        }
@@ -2744,94 +4150,174 @@ static int run_pipe(struct pipe *pi)
 
        if (command->group) {
 #if ENABLE_HUSH_FUNCTIONS
-               if (command->grp_type == GRP_FUNCTION) {
-                       /* func () { list } */
-                       bb_error_msg("here we ought to remember function definition, and go on");
+               if (command->cmd_type == CMD_FUNCDEF) {
+                       /* "executing" func () { list } */
+                       struct function *funcp;
+
+                       funcp = new_function(command->argv[0]);
+                       /* funcp->name is already set to argv[0] */
+                       funcp->body = command->group;
+# if !BB_MMU
+                       funcp->body_as_string = command->group_as_string;
+                       command->group_as_string = NULL;
+# endif
+                       command->group = NULL;
+                       command->argv[0] = NULL;
+                       debug_printf_exec("cmd %p has child func at %p\n", command, funcp);
+                       funcp->parent_cmd = command;
+                       command->child_func = funcp;
+
+                       debug_printf_exec("run_pipe: return EXIT_SUCCESS\n");
+                       debug_leave();
                        return EXIT_SUCCESS;
                }
 #endif
                /* { list } */
                debug_printf("non-subshell group\n");
-               setup_redirects(command, squirrel);
-               debug_printf_exec(": run_list\n");
-               rcode = run_list(command->group) & 0xff;
+               rcode = 1; /* exitcode if redir failed */
+               if (setup_redirects(command, squirrel) == 0) {
+                       debug_printf_exec(": run_list\n");
+                       rcode = run_list(command->group) & 0xff;
+               }
                restore_redirects(squirrel);
-               debug_printf_exec("run_pipe return %d\n", rcode);
                IF_HAS_KEYWORDS(if (pi->pi_inverted) rcode = !rcode;)
+               debug_leave();
+               debug_printf_exec("run_pipe: return %d\n", rcode);
                return rcode;
        }
 
        argv = command->argv ? command->argv : (char **) &null_ptr;
        {
                const struct built_in_command *x;
+#if ENABLE_HUSH_FUNCTIONS
+               const struct function *funcp;
+#else
+               enum { funcp = 0 };
+#endif
                char **new_env = NULL;
-               char **old_env = NULL;
+               struct variable *old_vars = NULL;
 
                if (argv[command->assignment_cnt] == NULL) {
                        /* Assignments, but no command */
-                       /* Ensure redirects take effect. Try "a=t >file" */
-                       setup_redirects(command, squirrel);
+                       /* Ensure redirects take effect (that is, create files).
+                        * Try "a=t >file": */
+                       rcode = setup_redirects(command, squirrel);
                        restore_redirects(squirrel);
                        /* Set shell variables */
                        while (*argv) {
                                p = expand_string_to_string(*argv);
                                debug_printf_exec("set shell var:'%s'->'%s'\n",
                                                *argv, p);
-                               set_local_var(p, 0, 0);
+                               set_local_var(p, /*exp:*/ 0, /*lvl:*/ 0, /*ro:*/ 0);
                                argv++;
                        }
+                       /* Redirect error sets $? to 1. Othervise,
+                        * if evaluating assignment value set $?, retain it.
+                        * Try "false; q=`exit 2`; echo $?" - should print 2: */
+                       if (rcode == 0)
+                               rcode = G.last_exitcode;
                        /* Do we need to flag set_local_var() errors?
                         * "assignment to readonly var" and "putenv error"
                         */
-                       return EXIT_SUCCESS;
+                       IF_HAS_KEYWORDS(if (pi->pi_inverted) rcode = !rcode;)
+                       debug_leave();
+                       debug_printf_exec("run_pipe: return %d\n", rcode);
+                       return rcode;
                }
 
                /* Expand the rest into (possibly) many strings each */
-               argv_expanded = expand_strvec_to_strvec(argv + command->assignment_cnt);
+               if (0) {}
+#if ENABLE_HUSH_BASH_COMPAT
+               else if (command->cmd_type == CMD_SINGLEWORD_NOGLOB) {
+                       argv_expanded = expand_strvec_to_strvec_singleword_noglob(argv + command->assignment_cnt);
+               }
+#endif
+#ifdef CMD_SINGLEWORD_NOGLOB_COND
+               else if (command->cmd_type == CMD_SINGLEWORD_NOGLOB_COND) {
+                       argv_expanded = expand_strvec_to_strvec_singleword_noglob_cond(argv + command->assignment_cnt);
 
-               for (x = bltins; x != &bltins[ARRAY_SIZE(bltins)]; x++) {
-                       if (strcmp(argv_expanded[0], x->cmd) != 0)
-                               continue;
-                       if (x->function == builtin_exec && argv_expanded[1] == NULL) {
-                               debug_printf("exec with redirects only\n");
-                               setup_redirects(command, NULL);
-                               rcode = EXIT_SUCCESS;
-                               goto clean_up_and_ret1;
+               }
+#endif
+               else {
+                       argv_expanded = expand_strvec_to_strvec(argv + command->assignment_cnt);
+               }
+
+               /* if someone gives us an empty string: `cmd with empty output` */
+               if (!argv_expanded[0]) {
+                       free(argv_expanded);
+                       debug_leave();
+                       return G.last_exitcode;
+               }
+
+               x = find_builtin(argv_expanded[0]);
+#if ENABLE_HUSH_FUNCTIONS
+               funcp = NULL;
+               if (!x)
+                       funcp = find_function(argv_expanded[0]);
+#endif
+               if (x || funcp) {
+                       if (!funcp) {
+                               if (x->b_function == builtin_exec && argv_expanded[1] == NULL) {
+                                       debug_printf("exec with redirects only\n");
+                                       rcode = setup_redirects(command, NULL);
+                                       goto clean_up_and_ret1;
+                               }
                        }
-                       debug_printf("builtin inline %s\n", argv_expanded[0]);
-                       /* XXX setup_redirects acts on file descriptors, not FILEs.
+                       /* setup_redirects acts on file descriptors, not FILEs.
                         * This is perfect for work that comes after exec().
                         * Is it really safe for inline use?  Experimentally,
-                        * things seem to work with glibc. */
-                       setup_redirects(command, squirrel);
-                       new_env = expand_assignments(argv, command->assignment_cnt);
-                       old_env = putenv_all_and_save_old(new_env);
-                       debug_printf_exec(": builtin '%s' '%s'...\n",
-                                   x->cmd, argv_expanded[1]);
-                       rcode = x->function(argv_expanded) & 0xff;
+                        * things seem to work. */
+                       rcode = setup_redirects(command, squirrel);
+                       if (rcode == 0) {
+                               new_env = expand_assignments(argv, command->assignment_cnt);
+                               old_vars = set_vars_and_save_old(new_env);
+                               if (!funcp) {
+                                       debug_printf_exec(": builtin '%s' '%s'...\n",
+                                               x->b_cmd, argv_expanded[1]);
+                                       rcode = x->b_function(argv_expanded) & 0xff;
+                                       fflush_all();
+                               }
+#if ENABLE_HUSH_FUNCTIONS
+                               else {
+# if ENABLE_HUSH_LOCAL
+                                       struct variable **sv;
+                                       sv = G.shadowed_vars_pp;
+                                       G.shadowed_vars_pp = &old_vars;
+# endif
+                                       debug_printf_exec(": function '%s' '%s'...\n",
+                                               funcp->name, argv_expanded[1]);
+                                       rcode = run_function(funcp, argv_expanded) & 0xff;
+# if ENABLE_HUSH_LOCAL
+                                       G.shadowed_vars_pp = sv;
+# endif
+                               }
+#endif
+                       }
 #if ENABLE_FEATURE_SH_STANDALONE
  clean_up_and_ret:
 #endif
                        restore_redirects(squirrel);
-                       free_strings_and_unsetenv(new_env, 1);
-                       putenv_all(old_env);
-                       free(old_env); /* not free_strings()! */
+                       unset_vars(new_env);
+                       add_vars(old_vars);
  clean_up_and_ret1:
                        free(argv_expanded);
                        IF_HAS_KEYWORDS(if (pi->pi_inverted) rcode = !rcode;)
+                       debug_leave();
                        debug_printf_exec("run_pipe return %d\n", rcode);
                        return rcode;
                }
+
 #if ENABLE_FEATURE_SH_STANDALONE
                i = find_applet_by_name(argv_expanded[0]);
                if (i >= 0 && APPLET_IS_NOFORK(i)) {
-                       setup_redirects(command, squirrel);
-                       save_nofork_data(&G.nofork_save);
-                       new_env = expand_assignments(argv, command->assignment_cnt);
-                       old_env = putenv_all_and_save_old(new_env);
-                       debug_printf_exec(": run_nofork_applet '%s' '%s'...\n",
+                       rcode = setup_redirects(command, squirrel);
+                       if (rcode == 0) {
+                               new_env = expand_assignments(argv, command->assignment_cnt);
+                               old_vars = set_vars_and_save_old(new_env);
+                               debug_printf_exec(": run_nofork_applet '%s' '%s'...\n",
                                        argv_expanded[0], argv_expanded[1]);
-                       rcode = run_nofork_applet_prime(&G.nofork_save, i, argv_expanded);
+                               rcode = run_nofork_applet(i, argv_expanded);
+                       }
                        goto clean_up_and_ret;
                }
 #endif
@@ -2848,11 +4334,13 @@ static int run_pipe(struct pipe *pi)
        nextin = 0;
 
        for (i = 0; i < pi->num_cmds; i++) {
+               struct fd_pair pipefds;
 #if !BB_MMU
                volatile nommu_save_t nommu_save;
                nommu_save.new_env = NULL;
-               nommu_save.old_env = NULL;
+               nommu_save.old_vars = NULL;
                nommu_save.argv = NULL;
+               nommu_save.argv_from_re_execing = NULL;
 #endif
                command = &(pi->cmds[i]);
                if (command->argv) {
@@ -2863,15 +4351,16 @@ static int run_pipe(struct pipe *pi)
                }
 
                /* pipes are inserted between pairs of commands */
-               pipefds[0] = 0;
-               pipefds[1] = 1;
+               pipefds.rd = 0;
+               pipefds.wr = 1;
                if ((i + 1) < pi->num_cmds)
-                       xpipe(pipefds);
+                       xpiped_pair(pipefds);
 
                command->pid = BB_MMU ? fork() : vfork();
                if (!command->pid) { /* child */
 #if ENABLE_HUSH_JOB
-                       die_sleep = 0; /* do not restore tty pgrp on xfunc death */
+                       disable_restore_tty_pgrp_on_exit();
+                       CLEAR_RANDOM_T(&G.random_gen); /* or else $RANDOM repeats in child */
 
                        /* Every child adds itself to new process group
                         * with pgid == pid_of_first_child_in_pipe */
@@ -2880,20 +4369,32 @@ static int run_pipe(struct pipe *pi)
                                pgrp = pi->pgrp;
                                if (pgrp < 0) /* true for 1st process only */
                                        pgrp = getpid();
-                               if (setpgid(0, pgrp) == 0 && pi->followup != PIPE_BG) {
+                               if (setpgid(0, pgrp) == 0
+                                && pi->followup != PIPE_BG
+                                && G_saved_tty_pgrp /* we have ctty */
+                               ) {
                                        /* We do it in *every* child, not just first,
                                         * to avoid races */
                                        tcsetpgrp(G_interactive_fd, pgrp);
                                }
                        }
 #endif
-                       xmove_fd(nextin, 0);
-                       xmove_fd(pipefds[1], 1); /* write end */
-                       if (pipefds[0] > 1)
-                               close(pipefds[0]); /* read end */
+                       if (pi->alive_cmds == 0 && pi->followup == PIPE_BG) {
+                               /* 1st cmd in backgrounded pipe
+                                * should have its stdin /dev/null'ed */
+                               close(0);
+                               if (open(bb_dev_null, O_RDONLY))
+                                       xopen("/", O_RDONLY);
+                       } else {
+                               xmove_fd(nextin, 0);
+                       }
+                       xmove_fd(pipefds.wr, 1);
+                       if (pipefds.rd > 1)
+                               close(pipefds.rd);
                        /* Like bash, explicit redirects override pipes,
                         * and the pipe fd is available for dup'ing. */
-                       setup_redirects(command, NULL);
+                       if (setup_redirects(command, NULL))
+                               _exit(1);
 
                        /* Restore default handlers just prior to exec */
                        /*signal(SIGCHLD, SIG_DFL); - so far we don't have any handlers */
@@ -2906,15 +4407,17 @@ static int run_pipe(struct pipe *pi)
                }
 
                /* parent or error */
-#if ENABLE_HUSH_JOB
-               die_sleep = -1; /* restore tty pgrp on xfunc death */
+#if ENABLE_HUSH_FAST
+               G.count_SIGCHLD++;
+//bb_error_msg("[%d] fork in run_pipe: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
 #endif
+               enable_restore_tty_pgrp_on_exit();
 #if !BB_MMU
                /* Clean up after vforked child */
-               clean_up_after_re_execute();
                free(nommu_save.argv);
-               free_strings_and_unsetenv(nommu_save.new_env, 1);
-               putenv_all(nommu_save.old_env);
+               free(nommu_save.argv_from_re_execing);
+               unset_vars(nommu_save.new_env);
+               add_vars(nommu_save.old_vars);
 #endif
                free(argv_expanded);
                argv_expanded = NULL;
@@ -2933,16 +4436,18 @@ static int run_pipe(struct pipe *pi)
                if (i)
                        close(nextin);
                if ((i + 1) < pi->num_cmds)
-                       close(pipefds[1]); /* write end */
+                       close(pipefds.wr);
                /* Pass read (output) pipe end to next iteration */
-               nextin = pipefds[0];
+               nextin = pipefds.rd;
        }
 
        if (!pi->alive_cmds) {
+               debug_leave();
                debug_printf_exec("run_pipe return 1 (all forks failed, no children)\n");
                return 1;
        }
 
+       debug_leave();
        debug_printf_exec("run_pipe return -1 (%u children started)\n", pi->alive_cmds);
        return -1;
 }
@@ -2958,38 +4463,40 @@ static void debug_print_tree(struct pipe *pi, int lvl)
        };
        static const char *RES[] = {
                [RES_NONE ] = "NONE" ,
-#if ENABLE_HUSH_IF
+# if ENABLE_HUSH_IF
                [RES_IF   ] = "IF"   ,
                [RES_THEN ] = "THEN" ,
                [RES_ELIF ] = "ELIF" ,
                [RES_ELSE ] = "ELSE" ,
                [RES_FI   ] = "FI"   ,
-#endif
-#if ENABLE_HUSH_LOOPS
+# endif
+# if ENABLE_HUSH_LOOPS
                [RES_FOR  ] = "FOR"  ,
                [RES_WHILE] = "WHILE",
                [RES_UNTIL] = "UNTIL",
                [RES_DO   ] = "DO"   ,
                [RES_DONE ] = "DONE" ,
-#endif
-#if ENABLE_HUSH_LOOPS || ENABLE_HUSH_CASE
+# endif
+# if ENABLE_HUSH_LOOPS || ENABLE_HUSH_CASE
                [RES_IN   ] = "IN"   ,
-#endif
-#if ENABLE_HUSH_CASE
+# endif
+# if ENABLE_HUSH_CASE
                [RES_CASE ] = "CASE" ,
+               [RES_CASE_IN ] = "CASE_IN" ,
                [RES_MATCH] = "MATCH",
-               [RES_CASEI] = "CASEI",
+               [RES_CASE_BODY] = "CASE_BODY",
                [RES_ESAC ] = "ESAC" ,
-#endif
+# endif
                [RES_XXXX ] = "XXXX" ,
                [RES_SNTX ] = "SNTX" ,
        };
-       static const char *const GRPTYPE[] = {
+       static const char *const CMDTYPE[] = {
                "{}",
                "()",
-#if ENABLE_HUSH_FUNCTIONS
+               "[noglob]",
+# if ENABLE_HUSH_FUNCTIONS
                "func()",
-#endif
+# endif
        };
 
        int pin, prn;
@@ -3003,13 +4510,19 @@ static void debug_print_tree(struct pipe *pi, int lvl)
                        struct command *command = &pi->cmds[prn];
                        char **argv = command->argv;
 
-                       fprintf(stderr, "%*s prog %d assignment_cnt:%d",
+                       fprintf(stderr, "%*s cmd %d assignment_cnt:%d",
                                        lvl*2, "", prn,
                                        command->assignment_cnt);
                        if (command->group) {
-                               fprintf(stderr, " group %s: (argv=%p)\n",
-                                               GRPTYPE[command->grp_type],
-                                               argv);
+                               fprintf(stderr, " group %s: (argv=%p)%s%s\n",
+                                               CMDTYPE[command->cmd_type],
+                                               argv
+#if !BB_MMU
+                                               , " group_as_string:", command->group_as_string
+#else
+                                               , "", ""
+#endif
+                               );
                                debug_print_tree(command->group, lvl+1);
                                prn++;
                                continue;
@@ -3025,7 +4538,7 @@ static void debug_print_tree(struct pipe *pi, int lvl)
                pin++;
        }
 }
-#endif
+#endif /* debug_print_tree */
 
 /* NB: called by pseudo_exec, and therefore must not modify any
  * global data until exec/_exit (we can be a child after vfork!) */
@@ -3036,21 +4549,23 @@ static int run_list(struct pipe *pi)
 #endif
 #if ENABLE_HUSH_LOOPS
        struct pipe *loop_top = NULL;
-       char *for_varname = NULL;
        char **for_lcur = NULL;
        char **for_list = NULL;
 #endif
-       smallint flag_skip = 1;
-       smalluint rcode = 0; /* probably just for compiler */
+       smallint last_followup;
+       smalluint rcode;
 #if ENABLE_HUSH_IF || ENABLE_HUSH_CASE
        smalluint cond_code = 0;
 #else
-       enum { cond_code = 0, };
+       enum { cond_code = 0 };
+#endif
+#if HAS_KEYWORDS
+       smallint rword; /* enum reserved_style */
+       smallint last_rword; /* ditto */
 #endif
-       /*enum reserved_style*/ smallint rword = RES_NONE;
-       /*enum reserved_style*/ smallint skip_more_for_this_rword = RES_XXXX;
 
-       debug_printf_exec("run_list start lvl %d\n", G.run_list_level + 1);
+       debug_printf_exec("run_list start lvl %d\n", G.run_list_level);
+       debug_enter();
 
 #if ENABLE_HUSH_LOOPS
        /* Check syntax for "for" */
@@ -3059,7 +4574,8 @@ static int run_list(struct pipe *pi)
                        continue;
                /* current word is FOR or IN (BOLD in comments below) */
                if (cpipe->next == NULL) {
-                       syntax("malformed for");
+                       syntax_error("malformed for");
+                       debug_leave();
                        debug_printf_exec("run_list lvl %d return 1\n", G.run_list_level);
                        return 1;
                }
@@ -3070,7 +4586,8 @@ static int run_list(struct pipe *pi)
                if (cpipe->res_word == RES_IN /* "for v IN a b; not_do..."? */
                 || cpipe->next->res_word != RES_IN /* FOR v not_do_and_not_in..."? */
                ) {
-                       syntax("malformed for");
+                       syntax_error("malformed for");
+                       debug_leave();
                        debug_printf_exec("run_list lvl %d return 1\n", G.run_list_level);
                        return 1;
                }
@@ -3081,61 +4598,25 @@ static int run_list(struct pipe *pi)
         * in order to return, no direct "return" statements please.
         * This helps to ensure that no memory is leaked. */
 
-////TODO: ctrl-Z handling needs re-thinking and re-testing
-
 #if ENABLE_HUSH_JOB
-       /* Example of nested list: "while true; do { sleep 1 | exit 2; } done".
-        * We are saving state before entering outermost list ("while...done")
-        * so that ctrl-Z will correctly background _entire_ outermost list,
-        * not just a part of it (like "sleep 1 | exit 2") */
-       if (++G.run_list_level == 1 && G_interactive_fd) {
-               if (sigsetjmp(G.toplevel_jb, 1)) {
-                       /* ctrl-Z forked and we are parent; or ctrl-C.
-                        * Sighandler has longjmped us here */
-                       signal(SIGINT, SIG_IGN);
-                       signal(SIGTSTP, SIG_IGN);
-                       /* Restore level (we can be coming from deep inside
-                        * nested levels) */
-                       G.run_list_level = 1;
-#if ENABLE_FEATURE_SH_STANDALONE
-                       if (G.nofork_save.saved) { /* if save area is valid */
-                               debug_printf_jobs("exiting nofork early\n");
-                               restore_nofork_data(&G.nofork_save);
-                       }
+       G.run_list_level++;
 #endif
-////                   if (G.ctrl_z_flag) {
-////                           /* ctrl-Z has forked and stored pid of the child in pi->pid.
-////                            * Remember this child as background job */
-////                           insert_bg_job(pi);
-////                   } else {
-                               /* ctrl-C. We just stop doing whatever we were doing */
-                               bb_putchar('\n');
-////                   }
-                       USE_HUSH_LOOPS(loop_top = NULL;)
-                       USE_HUSH_LOOPS(G.depth_of_loop = 0;)
-                       rcode = 0;
-                       goto ret;
-               }
-////           /* ctrl-Z handler will store pid etc in pi */
-////           G.toplevel_list = pi;
-////           G.ctrl_z_flag = 0;
-////#if ENABLE_FEATURE_SH_STANDALONE
-////           G.nofork_save.saved = 0; /* in case we will run a nofork later */
-////#endif
-////           signal_SA_RESTART_empty_mask(SIGTSTP, handler_ctrl_z);
-////           signal(SIGINT, handler_ctrl_c);
-       }
-#endif /* JOB */
+
+#if HAS_KEYWORDS
+       rword = RES_NONE;
+       last_rword = RES_XXXX;
+#endif
+       last_followup = PIPE_SEQ;
+       rcode = G.last_exitcode;
 
        /* Go through list of pipes, (maybe) executing them. */
-       for (; pi; pi = USE_HUSH_LOOPS(rword == RES_DONE ? loop_top : ) pi->next) {
+       for (; pi; pi = IF_HUSH_LOOPS(rword == RES_DONE ? loop_top : ) pi->next) {
                if (G.flag_SIGINT)
                        break;
 
                IF_HAS_KEYWORDS(rword = pi->res_word;)
-               IF_HAS_NO_KEYWORDS(rword = RES_NONE;)
-               debug_printf_exec(": rword=%d cond_code=%d skip_more=%d\n",
-                               rword, cond_code, skip_more_for_this_rword);
+               debug_printf_exec(": rword=%d cond_code=%d last_rword=%d\n",
+                               rword, cond_code, last_rword);
 #if ENABLE_HUSH_LOOPS
                if ((rword == RES_WHILE || rword == RES_UNTIL || rword == RES_FOR)
                 && loop_top == NULL /* avoid bumping G.depth_of_loop twice */
@@ -3145,18 +4626,25 @@ static int run_list(struct pipe *pi)
                        G.depth_of_loop++;
                }
 #endif
-               if (rword == skip_more_for_this_rword && flag_skip) {
-                       if (pi->followup == PIPE_SEQ)
-                               flag_skip = 0;
-                       /* it is "<false> && CMD" or "<true> || CMD"
-                        * and we should not execute CMD */
-                       continue;
+               /* Still in the same "if...", "then..." or "do..." branch? */
+               if (IF_HAS_KEYWORDS(rword == last_rword &&) 1) {
+                       if ((rcode == 0 && last_followup == PIPE_OR)
+                        || (rcode != 0 && last_followup == PIPE_AND)
+                       ) {
+                               /* It is "<true> || CMD" or "<false> && CMD"
+                                * and we should not execute CMD */
+                               debug_printf_exec("skipped cmd because of || or &&\n");
+                               last_followup = pi->followup;
+                               continue;
+                       }
                }
-               flag_skip = 1;
-               skip_more_for_this_rword = RES_XXXX;
+               last_followup = pi->followup;
+               IF_HAS_KEYWORDS(last_rword = rword;)
 #if ENABLE_HUSH_IF
                if (cond_code) {
                        if (rword == RES_THEN) {
+                               /* if false; then ... fi has exitcode 0! */
+                               G.last_exitcode = rcode = EXIT_SUCCESS;
                                /* "if <false> THEN cmd": skip cmd */
                                continue;
                        }
@@ -3184,8 +4672,11 @@ static int run_list(struct pipe *pi)
                                vals = (char**)encoded_dollar_at_argv;
                                if (pi->next->res_word == RES_IN) {
                                        /* if no variable values after "in" we skip "for" */
-                                       if (!pi->next->cmds[0].argv)
+                                       if (!pi->next->cmds[0].argv) {
+                                               G.last_exitcode = rcode = EXIT_SUCCESS;
+                                               debug_printf_exec(": null FOR: exitcode EXIT_SUCCESS\n");
                                                break;
+                                       }
                                        vals = pi->next->cmds[0].argv;
                                } /* else: "for var; do..." -> assume "$@" list */
                                /* create list of variable values */
@@ -3193,22 +4684,18 @@ static int run_list(struct pipe *pi)
                                for_list = expand_strvec_to_strvec(vals);
                                for_lcur = for_list;
                                debug_print_strings("for_list", for_list);
-                               for_varname = pi->cmds[0].argv[0];
-                               pi->cmds[0].argv[0] = NULL;
                        }
-                       free(pi->cmds[0].argv[0]);
                        if (!*for_lcur) {
                                /* "for" loop is over, clean up */
                                free(for_list);
                                for_list = NULL;
                                for_lcur = NULL;
-                               pi->cmds[0].argv[0] = for_varname;
                                break;
                        }
-                       /* insert next value from for_lcur */
-//TODO: does it need escaping?
-                       pi->cmds[0].argv[0] = xasprintf("%s=%s", for_varname, *for_lcur++);
-                       pi->cmds[0].assignment_cnt = 1;
+                       /* Insert next value from for_lcur */
+                       /* note: *for_lcur already has quotes removed, $var expanded, etc */
+                       set_local_var(xasprintf("%s=%s", pi->cmds[0].argv[0], *for_lcur++), /*exp:*/ 0, /*lvl:*/ 0, /*ro:*/ 0);
+                       continue;
                }
                if (rword == RES_IN) {
                        continue; /* "for v IN list;..." - "in" has no cmds anyway */
@@ -3243,7 +4730,7 @@ static int run_list(struct pipe *pi)
                        }
                        continue;
                }
-               if (rword == RES_CASEI) { /* inside of a case branch */
+               if (rword == RES_CASE_BODY) { /* inside of a case branch */
                        if (cond_code != 0)
                                continue; /* not matched yet, skip this pipe */
                }
@@ -3259,7 +4746,7 @@ static int run_list(struct pipe *pi)
 
                /* After analyzing all keywords and conditions, we decided
                 * to execute this pipe. NB: have to do checkjobs(NULL)
-                * after run_pipe() to collect any background children,
+                * after run_pipe to collect any background children,
                 * even if list execution is to be stopped. */
                debug_printf_exec(": run_pipe with %d members\n", pi->num_cmds);
                {
@@ -3269,14 +4756,17 @@ static int run_list(struct pipe *pi)
 #endif
                        rcode = r = run_pipe(pi); /* NB: rcode is a smallint */
                        if (r != -1) {
-                               /* we only ran a builtin: rcode is already known
+                               /* We ran a builtin, function, or group.
+                                * rcode is already known
                                 * and we don't need to wait for anything. */
+                               G.last_exitcode = rcode;
+                               debug_printf_exec(": builtin/func exitcode %d\n", rcode);
                                check_and_run_traps(0);
 #if ENABLE_HUSH_LOOPS
-                               /* was it "break" or "continue"? */
+                               /* Was it "break" or "continue"? */
                                if (G.flag_break_continue) {
                                        smallint fbc = G.flag_break_continue;
-                                       /* we might fall into outer *loop*,
+                                       /* We might fall into outer *loop*,
                                         * don't want to break it too */
                                        if (loop_top) {
                                                G.depth_break_continue--;
@@ -3290,9 +4780,16 @@ static int run_list(struct pipe *pi)
                                        rword = RES_DONE;
                                        continue;
                                }
+#endif
+#if ENABLE_HUSH_FUNCTIONS
+                               if (G.flag_return_in_progress == 1) {
+                                       /* same as "goto check_jobs_and_break" */
+                                       checkjobs(NULL);
+                                       break;
+                               }
 #endif
                        } else if (pi->followup == PIPE_BG) {
-                               /* what does bash do with attempts to background builtins? */
+                               /* What does bash do with attempts to background builtins? */
                                /* even bash 3.2 doesn't do that well with nested bg:
                                 * try "{ { sleep 10; echo DEEP; } & echo HERE; } &".
                                 * I'm NOT treating inner &'s as jobs */
@@ -3301,25 +4798,25 @@ static int run_list(struct pipe *pi)
                                if (G.run_list_level == 1)
                                        insert_bg_job(pi);
 #endif
-                               rcode = 0; /* EXIT_SUCCESS */
+                               G.last_exitcode = rcode = EXIT_SUCCESS;
+                               debug_printf_exec(": cmd&: exitcode EXIT_SUCCESS\n");
                        } else {
 #if ENABLE_HUSH_JOB
                                if (G.run_list_level == 1 && G_interactive_fd) {
-                                       /* waits for completion, then fg's main shell */
+                                       /* Waits for completion, then fg's main shell */
                                        rcode = checkjobs_and_fg_shell(pi);
+                                       debug_printf_exec(": checkjobs_and_fg_shell exitcode %d\n", rcode);
                                        check_and_run_traps(0);
-                                       debug_printf_exec(": checkjobs_and_fg_shell returned %d\n", rcode);
                                } else
 #endif
-                               { /* this one just waits for completion */
+                               { /* This one just waits for completion */
                                        rcode = checkjobs(pi);
+                                       debug_printf_exec(": checkjobs exitcode %d\n", rcode);
                                        check_and_run_traps(0);
-                                       debug_printf_exec(": checkjobs returned %d\n", rcode);
                                }
+                               G.last_exitcode = rcode;
                        }
                }
-               debug_printf_exec(": setting last_return_code=%d\n", rcode);
-               G.last_return_code = rcode;
 
                /* Analyze how result affects subsequent commands */
 #if ENABLE_HUSH_IF
@@ -3327,45 +4824,34 @@ static int run_list(struct pipe *pi)
                        cond_code = rcode;
 #endif
 #if ENABLE_HUSH_LOOPS
-               if (rword == RES_WHILE) {
-                       if (rcode) {
-                               rcode = 0; /* "while false; do...done" - exitcode 0 */
-                               goto check_jobs_and_break;
+               /* Beware of "while false; true; do ..."! */
+               if (pi->next && pi->next->res_word == RES_DO) {
+                       if (rword == RES_WHILE) {
+                               if (rcode) {
+                                       /* "while false; do...done" - exitcode 0 */
+                                       G.last_exitcode = rcode = EXIT_SUCCESS;
+                                       debug_printf_exec(": while expr is false: breaking (exitcode:EXIT_SUCCESS)\n");
+                                       goto check_jobs_and_break;
+                               }
                        }
-               }
-               if (rword == RES_UNTIL) {
-                       if (!rcode) {
+                       if (rword == RES_UNTIL) {
+                               if (!rcode) {
+                                       debug_printf_exec(": until expr is true: breaking\n");
  check_jobs_and_break:
-                               checkjobs(NULL);
-                               break;
+                                       checkjobs(NULL);
+                                       break;
+                               }
                        }
                }
 #endif
-               if ((rcode == 0 && pi->followup == PIPE_OR)
-                || (rcode != 0 && pi->followup == PIPE_AND)
-               ) {
-                       skip_more_for_this_rword = rword;
-               }
 
  check_jobs_and_continue:
                checkjobs(NULL);
        } /* for (pi) */
 
 #if ENABLE_HUSH_JOB
-////   if (G.ctrl_z_flag) {
-////           /* ctrl-Z forked somewhere in the past, we are the child,
-////            * and now we completed running the list. Exit. */
-//////TODO: _exit?
-////           exit(rcode);
-////   }
- ret:
        G.run_list_level--;
-////   if (!G.run_list_level && G_interactive_fd) {
-////           signal(SIGTSTP, SIG_IGN);
-////           signal(SIGINT, SIG_IGN);
-////   }
 #endif
-       debug_printf_exec("run_list lvl %d return %d\n", G.run_list_level + 1, rcode);
 #if ENABLE_HUSH_LOOPS
        if (loop_top)
                G.depth_of_loop--;
@@ -3374,6 +4860,8 @@ static int run_list(struct pipe *pi)
 #if ENABLE_HUSH_CASE
        free(case_word);
 #endif
+       debug_leave();
+       debug_printf_exec("run_list lvl %d return %d\n", G.run_list_level + 1, rcode);
        return rcode;
 }
 
@@ -3383,95 +4871,18 @@ static int run_and_free_list(struct pipe *pi)
        int rcode = 0;
        debug_printf_exec("run_and_free_list entered\n");
        if (!G.fake_mode) {
-               debug_printf_exec(": run_list with %d members\n", pi->num_cmds);
+               debug_printf_exec(": run_list: 1st pipe with %d cmds\n", pi->num_cmds);
                rcode = run_list(pi);
        }
        /* free_pipe_list has the side effect of clearing memory.
         * In the long run that function can be merged with run_list,
         * but doing that now would hobble the debugging effort. */
-       free_pipe_list(pi, /* indent: */ 0);
+       free_pipe_list(pi);
        debug_printf_exec("run_and_free_list return %d\n", rcode);
        return rcode;
 }
 
 
-/* Peek ahead in the in_str to find out if we have a "&n" construct,
- * as in "2>&1", that represents duplicating a file descriptor.
- * Return either -2 (syntax error), -1 (no &), or the number found.
- */
-static int redirect_dup_num(struct in_str *input)
-{
-       int ch, d = 0, ok = 0;
-       ch = i_peek(input);
-       if (ch != '&') return -1;
-
-       i_getch(input);  /* get the & */
-       ch = i_peek(input);
-       if (ch == '-') {
-               i_getch(input);
-               return -3;  /* "-" represents "close me" */
-       }
-       while (isdigit(ch)) {
-               d = d*10 + (ch-'0');
-               ok = 1;
-               i_getch(input);
-               ch = i_peek(input);
-       }
-       if (ok) return d;
-
-       bb_error_msg("ambiguous redirect");
-       return -2;
-}
-
-/* The src parameter allows us to peek forward to a possible &n syntax
- * for file descriptor duplication, e.g., "2>&1".
- * Return code is 0 normally, 1 if a syntax error is detected in src.
- * Resource errors (in xmalloc) cause the process to exit */
-static int setup_redirect(struct parse_context *ctx,
-               int fd,
-               redir_type style,
-               struct in_str *input)
-{
-       struct command *command = ctx->command;
-       struct redir_struct *redir;
-       struct redir_struct **redirp;
-       int dup_num;
-
-       /* Check for a '2>&1' type redirect */
-       dup_num = redirect_dup_num(input);
-       if (dup_num == -2)
-               return 1;  /* syntax error */
-
-       /* Create a new redir_struct and drop it onto the end of the linked list */
-       redirp = &command->redirects;
-       while ((redir = *redirp) != NULL) {
-               redirp = &(redir->next);
-       }
-       *redirp = redir = xzalloc(sizeof(*redir));
-       /* redir->next = NULL; */
-       /* redir->rd_filename = NULL; */
-       redir->rd_type = style;
-       redir->fd = (fd == -1) ? redir_table[style].default_fd : fd;
-
-       debug_printf("Redirect type %d%s\n", redir->fd, redir_table[style].descrip);
-
-       redir->dup = dup_num;
-       if (dup_num != -1) {
-               /* Erik had a check here that the file descriptor in question
-                * is legit; I postpone that to "run time"
-                * A "-" representation of "close me" shows up as a -3 here */
-               debug_printf("Duplicating redirect '%d>&%d'\n", redir->fd, redir->dup);
-       } else {
-               /* We do _not_ try to open the file that src points to,
-                * since we need to return and let src be expanded first.
-                * Set ctx->pending_redirect, so we know what to do at the
-                * end of the next parsed word. */
-               ctx->pending_redirect = redir;
-       }
-       return 0;
-}
-
-
 static struct pipe *new_pipe(void)
 {
        struct pipe *pi;
@@ -3481,8 +4892,10 @@ static struct pipe *new_pipe(void)
        return pi;
 }
 
-/* Command (member of a pipe) is complete. The only possible error here
- * is out of memory, in which case xmalloc exits. */
+/* Command (member of a pipe) is complete, or we start a new pipe
+ * if ctx->command is NULL.
+ * No errors possible here.
+ */
 static int done_command(struct parse_context *ctx)
 {
        /* The command is really already in the pipe structure, so
@@ -3491,15 +4904,13 @@ static int done_command(struct parse_context *ctx)
        struct command *command = ctx->command;
 
        if (command) {
-               if (command->group == NULL
-                && command->argv == NULL
-                && command->redirects == NULL
-               ) {
+               if (IS_NULL_CMD(command)) {
                        debug_printf_parse("done_command: skipping null cmd, num_cmds=%d\n", pi->num_cmds);
-                       return pi->num_cmds;
+                       goto clear_and_ret;
                }
                pi->num_cmds++;
                debug_printf_parse("done_command: ++num_cmds=%d\n", pi->num_cmds);
+               //debug_print_tree(ctx->list_head, 20);
        } else {
                debug_printf_parse("done_command: initializing, num_cmds=%d\n", pi->num_cmds);
        }
@@ -3507,12 +4918,9 @@ static int done_command(struct parse_context *ctx)
        /* Only real trickiness here is that the uncommitted
         * command structure is not counted in pi->num_cmds. */
        pi->cmds = xrealloc(pi->cmds, sizeof(*pi->cmds) * (pi->num_cmds+1));
-       command = &pi->cmds[pi->num_cmds];
+       ctx->command = command = &pi->cmds[pi->num_cmds];
+ clear_and_ret:
        memset(command, 0, sizeof(*command));
-
-       ctx->command = command;
-       /* but ctx->pipe and ctx->list_head remain unchanged */
-
        return pi->num_cmds; /* used only for 0/nonzero check */
 }
 
@@ -3524,16 +4932,28 @@ static void done_pipe(struct parse_context *ctx, pipe_style type)
        /* Close previous command */
        not_null = done_command(ctx);
        ctx->pipe->followup = type;
-       IF_HAS_KEYWORDS(ctx->pipe->pi_inverted = ctx->ctx_inverted;)
-       IF_HAS_KEYWORDS(ctx->ctx_inverted = 0;)
-       IF_HAS_KEYWORDS(ctx->pipe->res_word = ctx->ctx_res_w;)
+#if HAS_KEYWORDS
+       ctx->pipe->pi_inverted = ctx->ctx_inverted;
+       ctx->ctx_inverted = 0;
+       ctx->pipe->res_word = ctx->ctx_res_w;
+#endif
 
        /* Without this check, even just <enter> on command line generates
         * tree of three NOPs (!). Which is harmless but annoying.
-        * IOW: it is safe to do it unconditionally.
-        * RES_NONE case is for "for a in; do ..." (empty IN set)
-        * to work, possibly other cases too. */
-       if (not_null IF_HAS_KEYWORDS(|| ctx->ctx_res_w != RES_NONE)) {
+        * IOW: it is safe to do it unconditionally. */
+       if (not_null
+#if ENABLE_HUSH_IF
+        || ctx->ctx_res_w == RES_FI
+#endif
+#if ENABLE_HUSH_LOOPS
+        || ctx->ctx_res_w == RES_DONE
+        || ctx->ctx_res_w == RES_FOR
+        || ctx->ctx_res_w == RES_IN
+#endif
+#if ENABLE_HUSH_CASE
+        || ctx->ctx_res_w == RES_ESAC
+#endif
+       ) {
                struct pipe *new_p;
                debug_printf_parse("done_pipe: adding new pipe: "
                                "not_null:%d ctx->ctx_res_w:%d\n",
@@ -3542,7 +4962,7 @@ static void done_pipe(struct parse_context *ctx, pipe_style type)
                ctx->pipe->next = new_p;
                ctx->pipe = new_p;
                /* RES_THEN, RES_DO etc are "sticky" -
-                * they remain set for commands inside if/while.
+                * they remain set for pipes inside if/while.
                 * This is used to control execution.
                 * RES_FOR and RES_IN are NOT sticky (needed to support
                 * cases where variable or value happens to match a keyword):
@@ -3554,7 +4974,9 @@ static void done_pipe(struct parse_context *ctx, pipe_style type)
 #endif
 #if ENABLE_HUSH_CASE
                if (ctx->ctx_res_w == RES_MATCH)
-                       ctx->ctx_res_w = RES_CASEI;
+                       ctx->ctx_res_w = RES_CASE_BODY;
+               if (ctx->ctx_res_w == RES_CASE)
+                       ctx->ctx_res_w = RES_CASE_IN;
 #endif
                ctx->command = NULL; /* trick done_command below */
                /* Create the memory for command, roughly:
@@ -3562,6 +4984,7 @@ static void done_pipe(struct parse_context *ctx, pipe_style type)
                 * ctx->command = &ctx->pipe->cmds[0];
                 */
                done_command(ctx);
+               //debug_print_tree(ctx->list_head, 10);
        }
        debug_printf_parse("done_pipe return\n");
 }
@@ -3577,7 +5000,6 @@ static void initialize_context(struct parse_context *ctx)
        done_command(ctx);
 }
 
-
 /* If a reserved word is found and processed, parse context is modified
  * and 1 is returned.
  */
@@ -3590,25 +5012,25 @@ struct reserved_combo {
 };
 enum {
        FLAG_END   = (1 << RES_NONE ),
-#if ENABLE_HUSH_IF
+# if ENABLE_HUSH_IF
        FLAG_IF    = (1 << RES_IF   ),
        FLAG_THEN  = (1 << RES_THEN ),
        FLAG_ELIF  = (1 << RES_ELIF ),
        FLAG_ELSE  = (1 << RES_ELSE ),
        FLAG_FI    = (1 << RES_FI   ),
-#endif
-#if ENABLE_HUSH_LOOPS
+# endif
+# if ENABLE_HUSH_LOOPS
        FLAG_FOR   = (1 << RES_FOR  ),
        FLAG_WHILE = (1 << RES_WHILE),
        FLAG_UNTIL = (1 << RES_UNTIL),
        FLAG_DO    = (1 << RES_DO   ),
        FLAG_DONE  = (1 << RES_DONE ),
        FLAG_IN    = (1 << RES_IN   ),
-#endif
-#if ENABLE_HUSH_CASE
+# endif
+# if ENABLE_HUSH_CASE
        FLAG_MATCH = (1 << RES_MATCH),
        FLAG_ESAC  = (1 << RES_ESAC ),
-#endif
+# endif
        FLAG_START = (1 << RES_XXXX ),
 };
 
@@ -3620,26 +5042,26 @@ static const struct reserved_combo* match_reserved_word(o_string *word)
         * FLAG_START means the word must start a new compound list.
         */
        static const struct reserved_combo reserved_list[] = {
-#if ENABLE_HUSH_IF
+# if ENABLE_HUSH_IF
                { "!",     RES_NONE,  NOT_ASSIGNMENT , 0 },
                { "if",    RES_IF,    WORD_IS_KEYWORD, FLAG_THEN | FLAG_START },
                { "then",  RES_THEN,  WORD_IS_KEYWORD, FLAG_ELIF | FLAG_ELSE | FLAG_FI },
                { "elif",  RES_ELIF,  WORD_IS_KEYWORD, FLAG_THEN },
                { "else",  RES_ELSE,  WORD_IS_KEYWORD, FLAG_FI   },
                { "fi",    RES_FI,    NOT_ASSIGNMENT , FLAG_END  },
-#endif
-#if ENABLE_HUSH_LOOPS
+# endif
+# if ENABLE_HUSH_LOOPS
                { "for",   RES_FOR,   NOT_ASSIGNMENT , FLAG_IN | FLAG_DO | FLAG_START },
                { "while", RES_WHILE, WORD_IS_KEYWORD, FLAG_DO | FLAG_START },
                { "until", RES_UNTIL, WORD_IS_KEYWORD, FLAG_DO | FLAG_START },
                { "in",    RES_IN,    NOT_ASSIGNMENT , FLAG_DO   },
                { "do",    RES_DO,    WORD_IS_KEYWORD, FLAG_DONE },
                { "done",  RES_DONE,  NOT_ASSIGNMENT , FLAG_END  },
-#endif
-#if ENABLE_HUSH_CASE
+# endif
+# if ENABLE_HUSH_CASE
                { "case",  RES_CASE,  NOT_ASSIGNMENT , FLAG_MATCH | FLAG_START },
                { "esac",  RES_ESAC,  NOT_ASSIGNMENT , FLAG_END  },
-#endif
+# endif
        };
        const struct reserved_combo *r;
 
@@ -3649,69 +5071,83 @@ static const struct reserved_combo* match_reserved_word(o_string *word)
        }
        return NULL;
 }
+/* Return 0: not a keyword, 1: keyword
+ */
 static int reserved_word(o_string *word, struct parse_context *ctx)
 {
-#if ENABLE_HUSH_CASE
+# if ENABLE_HUSH_CASE
        static const struct reserved_combo reserved_match = {
                "",        RES_MATCH, NOT_ASSIGNMENT , FLAG_MATCH | FLAG_ESAC
        };
-#endif
+# endif
        const struct reserved_combo *r;
 
+       if (word->o_quoted)
+               return 0;
        r = match_reserved_word(word);
        if (!r)
                return 0;
 
        debug_printf("found reserved word %s, res %d\n", r->literal, r->res);
-#if ENABLE_HUSH_CASE
-       if (r->res == RES_IN && ctx->ctx_res_w == RES_CASE)
-               /* "case word IN ..." - IN part starts first match part */
+# if ENABLE_HUSH_CASE
+       if (r->res == RES_IN && ctx->ctx_res_w == RES_CASE_IN) {
+               /* "case word IN ..." - IN part starts first MATCH part */
                r = &reserved_match;
-       else
-#endif
+       else
+# endif
        if (r->flag == 0) { /* '!' */
                if (ctx->ctx_inverted) { /* bash doesn't accept '! ! true' */
-                       syntax("! ! command");
-                       IF_HAS_KEYWORDS(ctx->ctx_res_w = RES_SNTX;)
+                       syntax_error("! ! command");
+                       ctx->ctx_res_w = RES_SNTX;
                }
                ctx->ctx_inverted = 1;
                return 1;
        }
        if (r->flag & FLAG_START) {
                struct parse_context *old;
+
                old = xmalloc(sizeof(*old));
                debug_printf_parse("push stack %p\n", old);
                *old = *ctx;   /* physical copy */
                initialize_context(ctx);
                ctx->stack = old;
        } else if (/*ctx->ctx_res_w == RES_NONE ||*/ !(ctx->old_flag & (1 << r->res))) {
-               syntax(word->data);
+               syntax_error_at(word->data);
                ctx->ctx_res_w = RES_SNTX;
                return 1;
+       } else {
+               /* "{...} fi" is ok. "{...} if" is not
+                * Example:
+                * if { echo foo; } then { echo bar; } fi */
+               if (ctx->command->group)
+                       done_pipe(ctx, PIPE_SEQ);
        }
+
        ctx->ctx_res_w = r->res;
        ctx->old_flag = r->flag;
+       word->o_assignment = r->assignment_flag;
+
        if (ctx->old_flag & FLAG_END) {
                struct parse_context *old;
+
                done_pipe(ctx, PIPE_SEQ);
                debug_printf_parse("pop stack %p\n", ctx->stack);
                old = ctx->stack;
                old->command->group = ctx->list_head;
-               old->command->grp_type = GRP_NORMAL;
-#if !BB_MMU
+               old->command->cmd_type = CMD_NORMAL;
+# if !BB_MMU
                o_addstr(&old->as_string, ctx->as_string.data);
                o_free_unsafe(&ctx->as_string);
                old->command->group_as_string = xstrdup(old->as_string.data);
                debug_printf_parse("pop, remembering as:'%s'\n",
                                old->command->group_as_string);
-#endif
+# endif
                *ctx = *old;   /* physical copy */
                free(old);
        }
-       word->o_assignment = r->assignment_flag;
        return 1;
 }
-#endif
+#endif /* HAS_KEYWORDS */
 
 /* Word is complete, look at it and update parsing context.
  * Normal return is 0. Syntax errors return 1.
@@ -3722,42 +5158,54 @@ static int done_word(o_string *word, struct parse_context *ctx)
        struct command *command = ctx->command;
 
        debug_printf_parse("done_word entered: '%s' %p\n", word->data, command);
-       if (word->length == 0 && word->nonnull == 0) {
+       if (word->length == 0 && word->o_quoted == 0) {
                debug_printf_parse("done_word return 0: true null, ignored\n");
                return 0;
        }
-       /* If this word wasn't an assignment, next ones definitely
-        * can't be assignments. Even if they look like ones. */
-       if (word->o_assignment != DEFINITELY_ASSIGNMENT
-        && word->o_assignment != WORD_IS_KEYWORD
-       ) {
-               word->o_assignment = NOT_ASSIGNMENT;
-       } else {
-               if (word->o_assignment == DEFINITELY_ASSIGNMENT)
-                       command->assignment_cnt++;
-               word->o_assignment = MAYBE_ASSIGNMENT;
-       }
 
        if (ctx->pending_redirect) {
                /* We do not glob in e.g. >*.tmp case. bash seems to glob here
                 * only if run as "bash", not "sh" */
+               /* http://www.opengroup.org/onlinepubs/009695399/utilities/xcu_chap02.html
+                * "2.7 Redirection
+                * ...the word that follows the redirection operator
+                * shall be subjected to tilde expansion, parameter expansion,
+                * command substitution, arithmetic expansion, and quote
+                * removal. Pathname expansion shall not be performed
+                * on the word by a non-interactive shell; an interactive
+                * shell may perform it, but shall do so only when
+                * the expansion would result in one word."
+                */
                ctx->pending_redirect->rd_filename = xstrdup(word->data);
-               word->o_assignment = NOT_ASSIGNMENT;
-               debug_printf("word stored in rd_filename: '%s'\n", word->data);
+               /* Cater for >\file case:
+                * >\a creates file a; >\\a, >"\a", >"\\a" create file \a
+                * Same with heredocs:
+                * for <<\H delim is H; <<\\H, <<"\H", <<"\\H" - \H
+                */
+               if (ctx->pending_redirect->rd_type == REDIRECT_HEREDOC) {
+                       unbackslash(ctx->pending_redirect->rd_filename);
+                       /* Is it <<"HEREDOC"? */
+                       if (word->o_quoted) {
+                               ctx->pending_redirect->rd_dup |= HEREDOC_QUOTED;
+                       }
+               }
+               debug_printf_parse("word stored in rd_filename: '%s'\n", word->data);
+               ctx->pending_redirect = NULL;
        } else {
-               /* "{ echo foo; } echo bar" - bad */
-               /* NB: bash allows e.g.:
-                * if true; then { echo foo; } fi
-                * while if false; then false; fi do break; done
-                * TODO? */
-               if (command->group) {
-                       syntax(word->data);
-                       debug_printf_parse("done_word return 1: syntax error, "
-                                       "groups and arglists don't mix\n");
-                       return 1;
+               /* If this word wasn't an assignment, next ones definitely
+                * can't be assignments. Even if they look like ones. */
+               if (word->o_assignment != DEFINITELY_ASSIGNMENT
+                && word->o_assignment != WORD_IS_KEYWORD
+               ) {
+                       word->o_assignment = NOT_ASSIGNMENT;
+               } else {
+                       if (word->o_assignment == DEFINITELY_ASSIGNMENT)
+                               command->assignment_cnt++;
+                       word->o_assignment = MAYBE_ASSIGNMENT;
                }
+
 #if HAS_KEYWORDS
-#if ENABLE_HUSH_CASE
+# if ENABLE_HUSH_CASE
                if (ctx->ctx_dsemicolon
                 && strcmp(word->data, "esac") != 0 /* not "... pattern) cmd;; esac" */
                ) {
@@ -3765,23 +5213,48 @@ static int done_word(o_string *word, struct parse_context *ctx)
                        /* ctx->ctx_res_w = RES_MATCH; */
                        ctx->ctx_dsemicolon = 0;
                } else
-#endif
+# endif
                if (!command->argv /* if it's the first word... */
-#if ENABLE_HUSH_LOOPS
+# if ENABLE_HUSH_LOOPS
                 && ctx->ctx_res_w != RES_FOR /* ...not after FOR or IN */
                 && ctx->ctx_res_w != RES_IN
-#endif
+# endif
+# if ENABLE_HUSH_CASE
+                && ctx->ctx_res_w != RES_CASE
+# endif
                ) {
-                       debug_printf_parse("checking '%s' for reserved-ness\n", word->data);
+                       debug_printf_parse("checking '%s' for reserved-ness\n", word->data);
                        if (reserved_word(word, ctx)) {
-                               o_reset(word);
+                               o_reset_to_empty_unquoted(word);
                                debug_printf_parse("done_word return %d\n",
                                                (ctx->ctx_res_w == RES_SNTX));
                                return (ctx->ctx_res_w == RES_SNTX);
                        }
+# ifdef CMD_SINGLEWORD_NOGLOB_COND
+                       if (strcmp(word->data, "export") == 0
+#  if ENABLE_HUSH_LOCAL
+                        || strcmp(word->data, "local") == 0
+#  endif
+                       ) {
+                               command->cmd_type = CMD_SINGLEWORD_NOGLOB_COND;
+                       } else
+# endif
+# if ENABLE_HUSH_BASH_COMPAT
+                       if (strcmp(word->data, "[[") == 0) {
+                               command->cmd_type = CMD_SINGLEWORD_NOGLOB;
+                       }
+                       /* fall through */
+# endif
                }
 #endif
-               if (word->nonnull /* word had "xx" or 'xx' at least as part of it. */
+               if (command->group) {
+                       /* "{ echo foo; } echo bar" - bad */
+                       syntax_error_at(word->data);
+                       debug_printf_parse("done_word return 1: syntax error, "
+                                       "groups and arglists don't mix\n");
+                       return 1;
+               }
+               if (word->o_quoted /* word had "xx" or 'xx' at least as part of it. */
                 /* optimization: and if it's ("" or '') or ($v... or `cmd`...): */
                 && (word->data[0] == '\0' || word->data[0] == SPECIAL_VAR_SYMBOL)
                 /* (otherwise it's known to be not empty and is already safe) */
@@ -3807,16 +5280,19 @@ static int done_word(o_string *word, struct parse_context *ctx)
                debug_print_strings("word appended to argv", command->argv);
        }
 
-       o_reset(word);
-       ctx->pending_redirect = NULL;
-
 #if ENABLE_HUSH_LOOPS
-       /* Force FOR to have just one word (variable name) */
-       /* NB: basically, this makes hush see "for v in ..." syntax as if
-        * as it is "for v; in ...". FOR and IN become two pipe structs
-        * in parse tree. */
        if (ctx->ctx_res_w == RES_FOR) {
-//TODO: check that command->argv[0] is a valid variable name!
+               if (word->o_quoted
+                || !is_well_formed_var_name(command->argv[0], '\0')
+               ) {
+                       /* bash says just "not a valid identifier" */
+                       syntax_error("not a valid identifier in for");
+                       return 1;
+               }
+               /* Force FOR to have just one word (variable name) */
+               /* NB: basically, this makes hush see "for v in ..."
+                * syntax as if it is "for v; in ...". FOR and IN become
+                * two pipe structs in parse tree. */
                done_pipe(ctx, PIPE_SEQ);
        }
 #endif
@@ -3826,10 +5302,128 @@ static int done_word(o_string *word, struct parse_context *ctx)
                done_pipe(ctx, PIPE_SEQ);
        }
 #endif
+
+       o_reset_to_empty_unquoted(word);
+
        debug_printf_parse("done_word return 0\n");
        return 0;
 }
 
+
+/* Peek ahead in the input to find out if we have a "&n" construct,
+ * as in "2>&1", that represents duplicating a file descriptor.
+ * Return:
+ * REDIRFD_CLOSE if >&- "close fd" construct is seen,
+ * REDIRFD_SYNTAX_ERR if syntax error,
+ * REDIRFD_TO_FILE if no & was seen,
+ * or the number found.
+ */
+#if BB_MMU
+#define parse_redir_right_fd(as_string, input) \
+       parse_redir_right_fd(input)
+#endif
+static int parse_redir_right_fd(o_string *as_string, struct in_str *input)
+{
+       int ch, d, ok;
+
+       ch = i_peek(input);
+       if (ch != '&')
+               return REDIRFD_TO_FILE;
+
+       ch = i_getch(input);  /* get the & */
+       nommu_addchr(as_string, ch);
+       ch = i_peek(input);
+       if (ch == '-') {
+               ch = i_getch(input);
+               nommu_addchr(as_string, ch);
+               return REDIRFD_CLOSE;
+       }
+       d = 0;
+       ok = 0;
+       while (ch != EOF && isdigit(ch)) {
+               d = d*10 + (ch-'0');
+               ok = 1;
+               ch = i_getch(input);
+               nommu_addchr(as_string, ch);
+               ch = i_peek(input);
+       }
+       if (ok) return d;
+
+//TODO: this is the place to catch ">&file" bashism (redirect both fd 1 and 2)
+
+       bb_error_msg("ambiguous redirect");
+       return REDIRFD_SYNTAX_ERR;
+}
+
+/* Return code is 0 normal, 1 if a syntax error is detected
+ */
+static int parse_redirect(struct parse_context *ctx,
+               int fd,
+               redir_type style,
+               struct in_str *input)
+{
+       struct command *command = ctx->command;
+       struct redir_struct *redir;
+       struct redir_struct **redirp;
+       int dup_num;
+
+       dup_num = REDIRFD_TO_FILE;
+       if (style != REDIRECT_HEREDOC) {
+               /* Check for a '>&1' type redirect */
+               dup_num = parse_redir_right_fd(&ctx->as_string, input);
+               if (dup_num == REDIRFD_SYNTAX_ERR)
+                       return 1;
+       } else {
+               int ch = i_peek(input);
+               dup_num = (ch == '-'); /* HEREDOC_SKIPTABS bit is 1 */
+               if (dup_num) { /* <<-... */
+                       ch = i_getch(input);
+                       nommu_addchr(&ctx->as_string, ch);
+                       ch = i_peek(input);
+               }
+       }
+
+       if (style == REDIRECT_OVERWRITE && dup_num == REDIRFD_TO_FILE) {
+               int ch = i_peek(input);
+               if (ch == '|') {
+                       /* >|FILE redirect ("clobbering" >).
+                        * Since we do not support "set -o noclobber" yet,
+                        * >| and > are the same for now. Just eat |.
+                        */
+                       ch = i_getch(input);
+                       nommu_addchr(&ctx->as_string, ch);
+               }
+       }
+
+       /* Create a new redir_struct and append it to the linked list */
+       redirp = &command->redirects;
+       while ((redir = *redirp) != NULL) {
+               redirp = &(redir->next);
+       }
+       *redirp = redir = xzalloc(sizeof(*redir));
+       /* redir->next = NULL; */
+       /* redir->rd_filename = NULL; */
+       redir->rd_type = style;
+       redir->rd_fd = (fd == -1) ? redir_table[style].default_fd : fd;
+
+       debug_printf_parse("redirect type %d %s\n", redir->rd_fd,
+                               redir_table[style].descrip);
+
+       redir->rd_dup = dup_num;
+       if (style != REDIRECT_HEREDOC && dup_num != REDIRFD_TO_FILE) {
+               /* Erik had a check here that the file descriptor in question
+                * is legit; I postpone that to "run time"
+                * A "-" representation of "close me" shows up as a -3 here */
+               debug_printf_parse("duplicating redirect '%d>&%d'\n",
+                               redir->rd_fd, redir->rd_dup);
+       } else {
+               /* Set ctx->pending_redirect, so we know what to do at the
+                * end of the next parsed word. */
+               ctx->pending_redirect = redir;
+       }
+       return 0;
+}
+
 /* If a redirect is immediately preceded by a number, that number is
  * supposed to tell which file descriptor to redirect.  This routine
  * looks for such preceding numbers.  In an ideal world this routine
@@ -3838,39 +5432,131 @@ static int done_word(o_string *word, struct parse_context *ctx)
  *     echo 49>foo    # redirects fd 49 to file "foo", nothing passed to echo
  *     echo -2>foo    # redirects fd  1 to file "foo",    "-2" passed to echo
  *     echo 49x>foo   # redirects fd  1 to file "foo",   "49x" passed to echo
- * A -1 output from this program means no valid number was found, so the
- * caller should use the appropriate default for this redirection.
+ *
+ * http://www.opengroup.org/onlinepubs/009695399/utilities/xcu_chap02.html
+ * "2.7 Redirection
+ * ... If n is quoted, the number shall not be recognized as part of
+ * the redirection expression. For example:
+ * echo \2>a
+ * writes the character 2 into file a"
+ * We are getting it right by setting ->o_quoted on any \<char>
+ *
+ * A -1 return means no valid number was found,
+ * the caller should use the appropriate default for this redirection.
  */
 static int redirect_opt_num(o_string *o)
 {
        int num;
 
-       if (o->length == 0)
+       if (o->data == NULL)
                return -1;
-       for (num = 0; num < o->length; num++) {
-               if (!isdigit(o->data[num])) {
-                       return -1;
-               }
-       }
-       num = atoi(o->data);
-       o_reset(o);
+       num = bb_strtou(o->data, NULL, 10);
+       if (errno || num < 0)
+               return -1;
+       o_reset_to_empty_unquoted(o);
        return num;
 }
 
 #if BB_MMU
-#define parse_stream(pstring, input, end_trigger) \
-       parse_stream(input, end_trigger)
+#define fetch_till_str(as_string, input, word, skip_tabs) \
+       fetch_till_str(input, word, skip_tabs)
 #endif
-static struct pipe *parse_stream(char **pstring,
+static char *fetch_till_str(o_string *as_string,
                struct in_str *input,
-               int end_trigger);
-static void parse_and_run_string(const char *s);
+               const char *word,
+               int skip_tabs)
+{
+       o_string heredoc = NULL_O_STRING;
+       int past_EOL = 0;
+       int ch;
+
+       goto jump_in;
+       while (1) {
+               ch = i_getch(input);
+               nommu_addchr(as_string, ch);
+               if (ch == '\n') {
+                       if (strcmp(heredoc.data + past_EOL, word) == 0) {
+                               heredoc.data[past_EOL] = '\0';
+                               debug_printf_parse("parsed heredoc '%s'\n", heredoc.data);
+                               return heredoc.data;
+                       }
+                       do {
+                               o_addchr(&heredoc, ch);
+                               past_EOL = heredoc.length;
+ jump_in:
+                               do {
+                                       ch = i_getch(input);
+                                       nommu_addchr(as_string, ch);
+                               } while (skip_tabs && ch == '\t');
+                       } while (ch == '\n');
+               }
+               if (ch == EOF) {
+                       o_free_unsafe(&heredoc);
+                       return NULL;
+               }
+               o_addchr(&heredoc, ch);
+               nommu_addchr(as_string, ch);
+       }
+}
+
+/* Look at entire parse tree for not-yet-loaded REDIRECT_HEREDOCs
+ * and load them all. There should be exactly heredoc_cnt of them.
+ */
+static int fetch_heredocs(int heredoc_cnt, struct parse_context *ctx, struct in_str *input)
+{
+       struct pipe *pi = ctx->list_head;
+
+       while (pi && heredoc_cnt) {
+               int i;
+               struct command *cmd = pi->cmds;
+
+               debug_printf_parse("fetch_heredocs: num_cmds:%d cmd argv0:'%s'\n",
+                               pi->num_cmds,
+                               cmd->argv ? cmd->argv[0] : "NONE");
+               for (i = 0; i < pi->num_cmds; i++) {
+                       struct redir_struct *redir = cmd->redirects;
+
+                       debug_printf_parse("fetch_heredocs: %d cmd argv0:'%s'\n",
+                                       i, cmd->argv ? cmd->argv[0] : "NONE");
+                       while (redir) {
+                               if (redir->rd_type == REDIRECT_HEREDOC) {
+                                       char *p;
+
+                                       redir->rd_type = REDIRECT_HEREDOC2;
+                                       /* redir->rd_dup is (ab)used to indicate <<- */
+                                       p = fetch_till_str(&ctx->as_string, input,
+                                               redir->rd_filename, redir->rd_dup & HEREDOC_SKIPTABS);
+                                       if (!p) {
+                                               syntax_error("unexpected EOF in here document");
+                                               return 1;
+                                       }
+                                       free(redir->rd_filename);
+                                       redir->rd_filename = p;
+                                       heredoc_cnt--;
+                               }
+                               redir = redir->next;
+                       }
+                       cmd++;
+               }
+               pi = pi->next;
+       }
+#if 0
+       /* Should be 0. If it isn't, it's a parse error */
+       if (heredoc_cnt)
+               bb_error_msg_and_die("heredoc BUG 2");
+#endif
+       return 0;
+}
+
 
 #if ENABLE_HUSH_TICK
-static FILE *generate_stream_from_string(const char *s)
+static FILE *generate_stream_from_string(const char *s, pid_t *pid_p)
 {
-       FILE *pf;
-       int pid, channel[2];
+       pid_t pid;
+       int channel[2];
+# if !BB_MMU
+       char **to_free = NULL;
+# endif
 
        xpipe(channel);
        pid = BB_MMU ? fork() : vfork();
@@ -3878,9 +5564,7 @@ static FILE *generate_stream_from_string(const char *s)
                bb_perror_msg_and_die(BB_MMU ? "fork" : "vfork");
 
        if (pid == 0) { /* child */
-#if ENABLE_HUSH_JOB
-               die_sleep = 0; /* do not restore tty pgrp on xfunc death */
-#endif
+               disable_restore_tty_pgrp_on_exit();
                /* Process substitution is not considered to be usual
                 * 'command execution'.
                 * SUSv3 says ctrl-Z should be ignored, ctrl-C should not.
@@ -3890,48 +5574,97 @@ static FILE *generate_stream_from_string(const char *s)
                        + (1 << SIGTTIN)
                        + (1 << SIGTTOU)
                        , SIG_IGN);
+               CLEAR_RANDOM_T(&G.random_gen); /* or else $RANDOM repeats in child */
                close(channel[0]); /* NB: close _first_, then move fd! */
                xmove_fd(channel[1], 1);
                /* Prevent it from trying to handle ctrl-z etc */
-               USE_HUSH_JOB(G.run_list_level = 1;)
-#if BB_MMU
+               IF_HUSH_JOB(G.run_list_level = 1;)
+               /* Awful hack for `trap` or $(trap).
+                *
+                * http://www.opengroup.org/onlinepubs/009695399/utilities/trap.html
+                * contains an example where "trap" is executed in a subshell:
+                *
+                * save_traps=$(trap)
+                * ...
+                * eval "$save_traps"
+                *
+                * Standard does not say that "trap" in subshell shall print
+                * parent shell's traps. It only says that its output
+                * must have suitable form, but then, in the above example
+                * (which is not supposed to be normative), it implies that.
+                *
+                * bash (and probably other shell) does implement it
+                * (traps are reset to defaults, but "trap" still shows them),
+                * but as a result, "trap" logic is hopelessly messed up:
+                *
+                * # trap
+                * trap -- 'echo Ho' SIGWINCH  <--- we have a handler
+                * # (trap)        <--- trap is in subshell - no output (correct, traps are reset)
+                * # true | trap   <--- trap is in subshell - no output (ditto)
+                * # echo `true | trap`    <--- in subshell - output (but traps are reset!)
+                * trap -- 'echo Ho' SIGWINCH
+                * # echo `(trap)`         <--- in subshell in subshell - output
+                * trap -- 'echo Ho' SIGWINCH
+                * # echo `true | (trap)`  <--- in subshell in subshell in subshell - output!
+                * trap -- 'echo Ho' SIGWINCH
+                *
+                * The rules when to forget and when to not forget traps
+                * get really complex and nonsensical.
+                *
+                * Our solution: ONLY bare $(trap) or `trap` is special.
+                */
+               s = skip_whitespace(s);
+               if (strncmp(s, "trap", 4) == 0 && (*skip_whitespace(s + 4) == '\0'))
+               {
+                       static const char *const argv[] = { NULL, NULL };
+                       builtin_trap((char**)argv);
+                       exit(0); /* not _exit() - we need to fflush */
+               }
+# if BB_MMU
                reset_traps_to_defaults();
                parse_and_run_string(s);
-               _exit(G.last_return_code);
-#else
+               _exit(G.last_exitcode);
+# else
        /* We re-execute after vfork on NOMMU. This makes this script safe:
         * yes "0123456789012345678901234567890" | dd bs=32 count=64k >BIG
         * huge=`cat BIG` # was blocking here forever
         * echo OK
         */
-               re_execute_shell(s);
-#endif
+               re_execute_shell(&to_free,
+                               s,
+                               G.global_argv[0],
+                               G.global_argv + 1,
+                               NULL);
+# endif
        }
 
        /* parent */
-#if ENABLE_HUSH_JOB
-       die_sleep = -1; /* restore tty pgrp on xfunc death */
-#endif
-       clean_up_after_re_execute();
+       *pid_p = pid;
+# if ENABLE_HUSH_FAST
+       G.count_SIGCHLD++;
+//bb_error_msg("[%d] fork in generate_stream_from_string: G.count_SIGCHLD:%d G.handled_SIGCHLD:%d", getpid(), G.count_SIGCHLD, G.handled_SIGCHLD);
+# endif
+       enable_restore_tty_pgrp_on_exit();
+# if !BB_MMU
+       free(to_free);
+# endif
        close(channel[1]);
-       pf = fdopen(channel[0], "r");
-       return pf;
+       close_on_exec_on(channel[0]);
+       return xfdopen_for_read(channel[0]);
 }
 
 /* Return code is exit status of the process that is run. */
 static int process_command_subs(o_string *dest, const char *s)
 {
-       FILE *pf;
+       FILE *fp;
        struct in_str pipe_str;
-       int ch, eol_cnt;
+       pid_t pid;
+       int status, ch, eol_cnt;
 
-       pf = generate_stream_from_string(s);
-       if (pf == NULL)
-               return 1;
-       close_on_exec_on(fileno(pf));
+       fp = generate_stream_from_string(s, &pid);
 
        /* Now send results of command back into original context */
-       setup_file_in_str(&pipe_str, pf);
+       setup_file_in_str(&pipe_str, fp);
        eol_cnt = 0;
        while ((ch = i_getch(&pipe_str)) != EOF) {
                if (ch == '\n') {
@@ -3945,19 +5678,21 @@ static int process_command_subs(o_string *dest, const char *s)
                o_addQchr(dest, ch);
        }
 
-       debug_printf("done reading from pipe, pclose()ing\n");
-       /* Note: we got EOF, and we just close the read end of the pipe.
-        * We do not wait for the `cmd` child to terminate. bash and ash do.
-        * Try these:
-        * echo `echo Hi; exec 1>&-; sleep 2` - bash waits 2 sec
-        * `false`; echo $? - bash outputs "1"
-        */
-       fclose(pf);
-       debug_printf("closed FILE from child. return 0\n");
-       return 0;
+       debug_printf("done reading from `cmd` pipe, closing it\n");
+       fclose(fp);
+       /* We need to extract exitcode. Test case
+        * "true; echo `sleep 1; false` $?"
+        * should print 1 */
+       safe_waitpid(pid, &status, 0);
+       debug_printf("child exited. returning its exitcode:%d\n", WEXITSTATUS(status));
+       return WEXITSTATUS(status);
 }
-#endif
+#endif /* ENABLE_HUSH_TICK */
 
+#if !ENABLE_HUSH_FUNCTIONS
+#define parse_group(dest, ctx, input, ch) \
+       parse_group(ctx, input, ch)
+#endif
 static int parse_group(o_string *dest, struct parse_context *ctx,
        struct in_str *input, int ch)
 {
@@ -3970,28 +5705,67 @@ static int parse_group(o_string *dest, struct parse_context *ctx,
 
        debug_printf_parse("parse_group entered\n");
 #if ENABLE_HUSH_FUNCTIONS
-       if (ch == 'F') { /* function definition? */
-               bb_error_msg("aha '%s' is a function, parsing it...", dest->data);
-               //command->fname = dest->data;
-               command->grp_type = GRP_FUNCTION;
-//TODO: review every o_reset() location... do they handle all o_string fields correctly?
-               memset(dest, 0, sizeof(*dest));
+       if (ch == '(' && !dest->o_quoted) {
+               if (dest->length)
+                       if (done_word(dest, ctx))
+                               return 1;
+               if (!command->argv)
+                       goto skip; /* (... */
+               if (command->argv[1]) { /* word word ... (... */
+                       syntax_error_unexpected_ch('(');
+                       return 1;
+               }
+               /* it is "word(..." or "word (..." */
+               do
+                       ch = i_getch(input);
+               while (ch == ' ' || ch == '\t');
+               if (ch != ')') {
+                       syntax_error_unexpected_ch(ch);
+                       return 1;
+               }
+               nommu_addchr(&ctx->as_string, ch);
+               do
+                       ch = i_getch(input);
+               while (ch == ' ' || ch == '\t' || ch == '\n');
+               if (ch != '{') {
+                       syntax_error_unexpected_ch(ch);
+                       return 1;
+               }
+               nommu_addchr(&ctx->as_string, ch);
+               command->cmd_type = CMD_FUNCDEF;
+               goto skip;
        }
 #endif
-       if (command->argv /* word [word](... */
-        || dest->length /* word(... */
-        || dest->nonnull /* ""(... */
+
+#if 0 /* Prevented by caller */
+       if (command->argv /* word [word]{... */
+        || dest->length /* word{... */
+        || dest->o_quoted /* ""{... */
        ) {
-               syntax(NULL);
+               syntax_error(NULL);
                debug_printf_parse("parse_group return 1: "
                        "syntax error, groups and arglists don't mix\n");
                return 1;
        }
+#endif
+
+#if ENABLE_HUSH_FUNCTIONS
+ skip:
+#endif
        endch = '}';
        if (ch == '(') {
                endch = ')';
-               command->grp_type = GRP_SUBSHELL;
+               command->cmd_type = CMD_SUBSHELL;
+       } else {
+               /* bash does not allow "{echo...", requires whitespace */
+               ch = i_getch(input);
+               if (ch != ' ' && ch != '\t' && ch != '\n') {
+                       syntax_error_unexpected_ch(ch);
+                       return 1;
+               }
+               nommu_addchr(&ctx->as_string, ch);
        }
+
        {
 #if !BB_MMU
                char *as_string = NULL;
@@ -4003,10 +5777,10 @@ static int parse_group(o_string *dest, struct parse_context *ctx,
 #endif
                /* empty ()/{} or parse error? */
                if (!pipe_list || pipe_list == ERR_PTR) {
+                       /* parse_stream already emitted error msg */
 #if !BB_MMU
                        free(as_string);
 #endif
-                       syntax(NULL);
                        debug_printf_parse("parse_group return 1: "
                                "parse_stream returned %p\n", pipe_list);
                        return 1;
@@ -4032,10 +5806,12 @@ static void add_till_single_quote(o_string *dest, struct in_str *input)
 {
        while (1) {
                int ch = i_getch(input);
-               if (ch == EOF)
-                       break;
+               if (ch == EOF) {
+                       syntax_error_unterm_ch('\'');
+                       /*xfunc_die(); - redundant */
+               }
                if (ch == '\'')
-                       break;
+                       return;
                o_addchr(dest, ch);
        }
 }
@@ -4044,14 +5820,16 @@ static void add_till_double_quote(o_string *dest, struct in_str *input)
 {
        while (1) {
                int ch = i_getch(input);
+               if (ch == EOF) {
+                       syntax_error_unterm_ch('"');
+                       /*xfunc_die(); - redundant */
+               }
                if (ch == '"')
-                       break;
+                       return;
                if (ch == '\\') {  /* \x. Copy both chars. */
                        o_addchr(dest, ch);
                        ch = i_getch(input);
                }
-               if (ch == EOF)
-                       break;
                o_addchr(dest, ch);
                if (ch == '`') {
                        add_till_backquote(dest, input);
@@ -4079,16 +5857,23 @@ static void add_till_backquote(o_string *dest, struct in_str *input)
 {
        while (1) {
                int ch = i_getch(input);
+               if (ch == EOF) {
+                       syntax_error_unterm_ch('`');
+                       /*xfunc_die(); - redundant */
+               }
                if (ch == '`')
-                       break;
-               if (ch == '\\') {  /* \x. Copy both chars unless it is \` */
+                       return;
+               if (ch == '\\') {
+                       /* \x. Copy both chars unless it is \` */
                        int ch2 = i_getch(input);
+                       if (ch2 == EOF) {
+                               syntax_error_unterm_ch('`');
+                               /*xfunc_die(); - redundant */
+                       }
                        if (ch2 != '`' && ch2 != '$' && ch2 != '\\')
                                o_addchr(dest, ch);
                        ch = ch2;
                }
-               if (ch == EOF)
-                       break;
                o_addchr(dest, ch);
        }
 }
@@ -4103,27 +5888,37 @@ static void add_till_backquote(o_string *dest, struct in_str *input)
  * echo $(echo '(TEST)' BEST)           (TEST) BEST
  * echo $(echo 'TEST)' BEST)            TEST) BEST
  * echo $(echo \(\(TEST\) BEST)         ((TEST) BEST
+ *
+ * Also adapted to eat ${var%...} constructs, since ... part
+ * can contain arbitrary constructs, just like $(cmd).
  */
-static void add_till_closing_paren(o_string *dest, struct in_str *input, bool dbl)
+#define DOUBLE_CLOSE_CHAR_FLAG 0x80
+static void add_till_closing_paren(o_string *dest, struct in_str *input, char end_ch)
 {
-       int count = 0;
+       char dbl = end_ch & DOUBLE_CLOSE_CHAR_FLAG;
+       end_ch &= (DOUBLE_CLOSE_CHAR_FLAG-1);
        while (1) {
                int ch = i_getch(input);
-               if (ch == EOF)
-                       break;
-               if (ch == '(')
-                       count++;
-               if (ch == ')') {
-                       if (--count < 0) {
-                               if (!dbl)
-                                       break;
-                               if (i_peek(input) == ')') {
-                                       i_getch(input);
-                                       break;
-                               }
+               if (ch == EOF) {
+                       syntax_error_unterm_ch(end_ch);
+                       /*xfunc_die(); - redundant */
+               }
+               if (ch == end_ch) {
+                       if (!dbl)
+                               break;
+                       /* we look for closing )) of $((EXPR)) */
+                       if (i_peek(input) == end_ch) {
+                               i_getch(input); /* eat second ')' */
+                               break;
                        }
                }
                o_addchr(dest, ch);
+               if (ch == '(' || ch == '{') {
+                       ch = (ch == '(' ? ')' : '}');
+                       add_till_closing_paren(dest, input, ch);
+                       o_addchr(dest, ch);
+                       continue;
+               }
                if (ch == '\'') {
                        add_till_single_quote(dest, input);
                        o_addchr(dest, ch);
@@ -4134,10 +5929,18 @@ static void add_till_closing_paren(o_string *dest, struct in_str *input, bool db
                        o_addchr(dest, ch);
                        continue;
                }
-               if (ch == '\\') { /* \x. Copy verbatim. Important for  \(, \) */
+               if (ch == '`') {
+                       add_till_backquote(dest, input);
+                       o_addchr(dest, ch);
+                       continue;
+               }
+               if (ch == '\\') {
+                       /* \x. Copy verbatim. Important for  \(, \) */
                        ch = i_getch(input);
-                       if (ch == EOF)
-                               break;
+                       if (ch == EOF) {
+                               syntax_error_unterm_ch(')');
+                               /*xfunc_die(); - redundant */
+                       }
                        o_addchr(dest, ch);
                        continue;
                }
@@ -4154,16 +5957,13 @@ static int handle_dollar(o_string *as_string,
                o_string *dest,
                struct in_str *input)
 {
-       int expansion;
        int ch = i_peek(input);  /* first character after the $ */
        unsigned char quote_mask = dest->o_escape ? 0x80 : 0;
 
        debug_printf_parse("handle_dollar entered: ch='%c'\n", ch);
        if (isalpha(ch)) {
                ch = i_getch(input);
-#if !BB_MMU
-               if (as_string) o_addchr(as_string, ch);
-#endif
+               nommu_addchr(as_string, ch);
  make_var:
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
                while (1) {
@@ -4174,17 +5974,13 @@ static int handle_dollar(o_string *as_string,
                        if (!isalnum(ch) && ch != '_')
                                break;
                        ch = i_getch(input);
-#if !BB_MMU
-                       if (as_string) o_addchr(as_string, ch);
-#endif
+                       nommu_addchr(as_string, ch);
                }
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
        } else if (isdigit(ch)) {
  make_one_char_var:
                ch = i_getch(input);
-#if !BB_MMU
-               if (as_string) o_addchr(as_string, ch);
-#endif
+               nommu_addchr(as_string, ch);
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
                debug_printf_parse(": '%c'\n", ch);
                o_addchr(dest, ch | quote_mask);
@@ -4198,107 +5994,72 @@ static int handle_dollar(o_string *as_string,
        case '@': /* args */
                goto make_one_char_var;
        case '{': {
-               bool first_char, all_digits;
-
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
-               ch = i_getch(input);
-#if !BB_MMU
-               if (as_string) o_addchr(as_string, ch);
-#endif
-               /* XXX maybe someone will try to escape the '}' */
-               expansion = 0;
-               first_char = true;
-               all_digits = false;
+
+               ch = i_getch(input); /* eat '{' */
+               nommu_addchr(as_string, ch);
+
+               ch = i_getch(input); /* first char after '{' */
+               nommu_addchr(as_string, ch);
+               /* It should be ${?}, or ${#var},
+                * or even ${?+subst} - operator acting on a special variable,
+                * or the beginning of variable name.
+                */
+               if (!strchr("$!?#*@_", ch) && !isalnum(ch)) { /* not one of those */
+ bad_dollar_syntax:
+                       syntax_error_unterm_str("${name}");
+                       debug_printf_parse("handle_dollar return 1: unterminated ${name}\n");
+                       return 1;
+               }
+               ch |= quote_mask;
+
+               /* It's possible to just call add_till_closing_paren() at this point.
+                * However, this regresses some of our testsuite cases
+                * which check invalid constructs like ${%}.
+                * Oh well... let's check that the var name part is fine... */
+
                while (1) {
+                       o_addchr(dest, ch);
+                       debug_printf_parse(": '%c'\n", ch);
+
                        ch = i_getch(input);
-#if !BB_MMU
-                       if (as_string) o_addchr(as_string, ch);
-#endif
+                       nommu_addchr(as_string, ch);
                        if (ch == '}')
                                break;
 
-                       if (first_char) {
-                               if (ch == '#')
-                                       /* ${#var}: length of var contents */
-                                       goto char_ok;
-                               else if (isdigit(ch)) {
-                                       all_digits = true;
-                                       goto char_ok;
-                               }
-                       }
-
-                       if (expansion < 2
-                        && (  (all_digits && !isdigit(ch))
-                           || (!all_digits && !isalnum(ch) && ch != '_')
-                           )
-                       ) {
+                       if (!isalnum(ch) && ch != '_') {
                                /* handle parameter expansions
                                 * http://www.opengroup.org/onlinepubs/009695399/utilities/xcu_chap02.html#tag_02_06_02
                                 */
-                               if (first_char)
-                                       goto case_default;
-                               switch (ch) {
-                               case ':': /* null modifier */
-                                       if (expansion == 0) {
-                                               debug_printf_parse(": null modifier\n");
-                                               ++expansion;
-                                               break;
-                                       }
-                                       goto case_default;
-#if 0 /* not implemented yet :( */
-                               case '#': /* remove prefix */
-                               case '%': /* remove suffix */
-                                       if (expansion == 0) {
-                                               debug_printf_parse(": remove suffix/prefix\n");
-                                               expansion = 2;
-                                               break;
-                                       }
-                                       goto case_default;
-#endif
-                               case '-': /* default value */
-                               case '=': /* assign default */
-                               case '+': /* alternative */
-                               case '?': /* error indicate */
-                                       debug_printf_parse(": parameter expansion\n");
-                                       expansion = 2;
-                                       break;
-                               default:
-                               case_default:
-                                       syntax("unterminated ${name}");
-                                       debug_printf_parse("handle_dollar return 1: unterminated ${name}\n");
-                                       return 1;
-                               }
+                               if (!strchr("%#:-=+?", ch)) /* ${var<bad_char>... */
+                                       goto bad_dollar_syntax;
+                               /* Eat everything until closing '}' */
+                               o_addchr(dest, ch);
+//TODO: add nommu_addchr hack here
+                               add_till_closing_paren(dest, input, '}');
+                               break;
                        }
- char_ok:
-                       debug_printf_parse(": '%c'\n", ch);
-                       o_addchr(dest, ch | quote_mask);
-                       quote_mask = 0;
-                       first_char = false;
                }
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
                break;
        }
-#if (ENABLE_SH_MATH_SUPPORT || ENABLE_HUSH_TICK)
+#if ENABLE_SH_MATH_SUPPORT || ENABLE_HUSH_TICK
        case '(': {
 # if !BB_MMU
                int pos;
 # endif
                ch = i_getch(input);
-# if !BB_MMU
-               if (as_string) o_addchr(as_string, ch);
-# endif
+               nommu_addchr(as_string, ch);
 # if ENABLE_SH_MATH_SUPPORT
                if (i_peek(input) == '(') {
                        ch = i_getch(input);
-#  if !BB_MMU
-                       if (as_string) o_addchr(as_string, ch);
-#  endif
+                       nommu_addchr(as_string, ch);
                        o_addchr(dest, SPECIAL_VAR_SYMBOL);
                        o_addchr(dest, /*quote_mask |*/ '+');
 #  if !BB_MMU
                        pos = dest->length;
 #  endif
-                       add_till_closing_paren(dest, input, true);
+                       add_till_closing_paren(dest, input, ')' | DOUBLE_CLOSE_CHAR_FLAG);
 #  if !BB_MMU
                        if (as_string) {
                                o_addstr(as_string, dest->data + pos);
@@ -4311,20 +6072,18 @@ static int handle_dollar(o_string *as_string,
                }
 # endif
 # if ENABLE_HUSH_TICK
-               //int pos = dest->length;
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
                o_addchr(dest, quote_mask | '`');
 #  if !BB_MMU
                pos = dest->length;
 #  endif
-               add_till_closing_paren(dest, input, false);
+               add_till_closing_paren(dest, input, ')');
 #  if !BB_MMU
                if (as_string) {
                        o_addstr(as_string, dest->data + pos);
-                       o_addchr(as_string, '`');
+                       o_addchr(as_string, ')');
                }
 #  endif
-               //debug_printf_subst("SUBST RES2 '%s'\n", dest->data + pos);
                o_addchr(dest, SPECIAL_VAR_SYMBOL);
 # endif
                break;
@@ -4332,17 +6091,17 @@ static int handle_dollar(o_string *as_string,
 #endif
        case '_':
                ch = i_getch(input);
-#if !BB_MMU
-               if (as_string) o_addchr(as_string, ch);
-#endif
+               nommu_addchr(as_string, ch);
                ch = i_peek(input);
                if (isalnum(ch)) { /* it's $_name or $_123 */
                        ch = '_';
                        goto make_var;
                }
                /* else: it's $_ */
-       /* TODO: */
-       /* $_ Shell or shell script name; or last cmd name */
+       /* TODO: $_ and $-: */
+       /* $_ Shell or shell script name; or last argument of last command
+        * (if last command wasn't a pipe; if it was, bash sets $_ to "");
+        * but in command's env, set to full pathname used to invoke it */
        /* $- Option flags set by set builtin or shell options (-i etc) */
        default:
                o_addQchr(dest, '$');
@@ -4365,47 +6124,45 @@ static int parse_stream_dquoted(o_string *as_string,
 
  again:
        ch = i_getch(input);
-#if !BB_MMU
-       if (as_string && ch != EOF)
-               o_addchr(as_string, ch);
-#endif
+       if (ch != EOF)
+               nommu_addchr(as_string, ch);
        if (ch == dquote_end) { /* may be only '"' or EOF */
-               dest->nonnull = 1;
                if (dest->o_assignment == NOT_ASSIGNMENT)
                        dest->o_escape ^= 1;
                debug_printf_parse("parse_stream_dquoted return 0\n");
                return 0;
        }
+       /* note: can't move it above ch == dquote_end check! */
        if (ch == EOF) {
-               syntax("unterminated \"");
-               debug_printf_parse("parse_stream_dquoted return 1: unterminated \"\n");
-               return 1;
+               syntax_error_unterm_ch('"');
+               /*xfunc_die(); - redundant */
        }
        next = '\0';
        if (ch != '\n') {
                next = i_peek(input);
        }
-       debug_printf_parse(": ch=%c (%d) escape=%d\n",
+       debug_printf_parse("\" ch=%c (%d) escape=%d\n",
                                        ch, ch, dest->o_escape);
        if (ch == '\\') {
                if (next == EOF) {
-                       syntax("\\<eof>");
-                       debug_printf_parse("parse_stream_dquoted return 1: \\<eof>\n");
-                       return 1;
+                       syntax_error("\\<eof>");
+                       xfunc_die();
                }
                /* bash:
                 * "The backslash retains its special meaning [in "..."]
                 * only when followed by one of the following characters:
                 * $, `, ", \, or <newline>.  A double quote may be quoted
-                * within double quotes by preceding it with a backslash.
-                * If enabled, history expansion will be performed unless
-                * an ! appearing in double quotes is escaped using
-                * a backslash. The backslash preceding the ! is not removed."
+                * within double quotes by preceding it with a backslash."
                 */
-               if (strchr("$`\"\\", next) != NULL) {
-                       o_addqchr(dest, i_getch(input));
+               if (strchr("$`\"\\\n", next) != NULL) {
+                       ch = i_getch(input);
+                       if (ch != '\n') {
+                               o_addqchr(dest, ch);
+                               nommu_addchr(as_string, ch);
+                       }
                } else {
                        o_addqchr(dest, '\\');
+                       nommu_addchr(as_string, '\\');
                }
                goto again;
        }
@@ -4432,7 +6189,7 @@ static int parse_stream_dquoted(o_string *as_string,
        if (ch == '='
         && (dest->o_assignment == MAYBE_ASSIGNMENT
            || dest->o_assignment == WORD_IS_KEYWORD)
-        && is_assignment(dest->data)
+        && is_well_formed_var_name(dest->data, '=')
        ) {
                dest->o_assignment = DEFINITELY_ASSIGNMENT;
        }
@@ -4454,17 +6211,24 @@ static struct pipe *parse_stream(char **pstring,
        struct parse_context ctx;
        o_string dest = NULL_O_STRING;
        int is_in_dquote;
+       int heredoc_cnt;
 
        /* Double-quote state is handled in the state variable is_in_dquote.
         * A single-quote triggers a bypass of the main loop until its mate is
         * found.  When recursing, quote state is passed in via dest->o_escape.
         */
        debug_printf_parse("parse_stream entered, end_trigger='%c'\n",
-                       end_trigger ? : 'X');
+                       end_trigger ? end_trigger : 'X');
+       debug_enter();
+
+       /* If very first arg is "" or '', dest.data may end up NULL.
+        * Preventing this: */
+       o_addchr(&dest, '\0');
+       dest.length = 0;
 
        G.ifs = get_local_var_value("IFS");
        if (G.ifs == NULL)
-               G.ifs = " \t\n";
+               G.ifs = defifs;
 
  reset:
 #if ENABLE_HUSH_INTERACTIVE
@@ -4473,6 +6237,7 @@ static struct pipe *parse_stream(char **pstring,
        /* dest.o_assignment = MAYBE_ASSIGNMENT; - already is */
        initialize_context(&ctx);
        is_in_dquote = 0;
+       heredoc_cnt = 0;
        while (1) {
                const char *is_ifs;
                const char *is_special;
@@ -4482,6 +6247,7 @@ static struct pipe *parse_stream(char **pstring,
                redir_type redir_style;
 
                if (is_in_dquote) {
+                       /* dest.o_quoted = 1; - already is (see below) */
                        if (parse_stream_dquoted(&ctx.as_string, &dest, input, '"')) {
                                goto parse_error;
                        }
@@ -4493,6 +6259,18 @@ static struct pipe *parse_stream(char **pstring,
                                                ch, ch, dest.o_escape);
                if (ch == EOF) {
                        struct pipe *pi;
+
+                       if (heredoc_cnt) {
+                               syntax_error_unterm_str("here document");
+                               goto parse_error;
+                       }
+                       /* end_trigger == '}' case errors out earlier,
+                        * checking only ')' */
+                       if (end_trigger == ')') {
+                               syntax_error_unterm_ch('('); /* exits */
+                               /* goto parse_error; */
+                       }
+
                        if (done_word(&dest, &ctx)) {
                                goto parse_error;
                        }
@@ -4500,14 +6278,14 @@ static struct pipe *parse_stream(char **pstring,
                        done_pipe(&ctx, PIPE_SEQ);
                        pi = ctx.list_head;
                        /* If we got nothing... */
-// TODO: test script consisting of just "&"
+                       /* (this makes bare "&" cmd a no-op.
+                        * bash says: "syntax error near unexpected token '&'") */
                        if (pi->num_cmds == 0
                            IF_HAS_KEYWORDS( && pi->res_word == RES_NONE)
                        ) {
-                               free_pipe_list(pi, 0);
+                               free_pipe_list(pi);
                                pi = NULL;
                        }
-                       debug_printf_parse("parse_stream return %p\n", pi);
 #if !BB_MMU
                        debug_printf_parse("as_string '%s'\n", ctx.as_string.data);
                        if (pstring)
@@ -4515,22 +6293,42 @@ static struct pipe *parse_stream(char **pstring,
                        else
                                o_free_unsafe(&ctx.as_string);
 #endif
+                       debug_leave();
+                       debug_printf_parse("parse_stream return %p\n", pi);
                        return pi;
                }
-#if !BB_MMU
-               o_addchr(&ctx.as_string, ch);
-#endif
+               nommu_addchr(&ctx.as_string, ch);
+
+               next = '\0';
+               if (ch != '\n')
+                       next = i_peek(input);
+
+               is_special = "{}<>;&|()#'" /* special outside of "str" */
+                               "\\$\"" IF_HUSH_TICK("`"); /* always special */
+               /* Are { and } special here? */
+               if (ctx.command->argv /* word [word]{... - non-special */
+                || dest.length       /* word{... - non-special */
+                || dest.o_quoted     /* ""{... - non-special */
+                || (next != ';'            /* }; - special */
+                   && next != ')'          /* }) - special */
+                   && next != '&'          /* }& and }&& ... - special */
+                   && next != '|'          /* }|| ... - special */
+                   && !strchr(G.ifs, next) /* {word - non-special */
+                   )
+               ) {
+                       /* They are not special, skip "{}" */
+                       is_special += 2;
+               }
+               is_special = strchr(is_special, ch);
                is_ifs = strchr(G.ifs, ch);
-               is_special = strchr("<>;&|(){}#'" /* special outside of "str" */
-                               "\\$\"" USE_HUSH_TICK("`") /* always special */
-                               , ch);
 
                if (!is_special && !is_ifs) { /* ordinary char */
+ ordinary_char:
                        o_addQchr(&dest, ch);
                        if ((dest.o_assignment == MAYBE_ASSIGNMENT
                            || dest.o_assignment == WORD_IS_KEYWORD)
                         && ch == '='
-                        && is_assignment(dest.data)
+                        && is_well_formed_var_name(dest.data, '=')
                        ) {
                                dest.o_assignment = DEFINITELY_ASSIGNMENT;
                        }
@@ -4553,14 +6351,58 @@ static struct pipe *parse_stream(char **pstring,
 #endif
                                /* Treat newline as a command separator. */
                                done_pipe(&ctx, PIPE_SEQ);
+                               debug_printf_parse("heredoc_cnt:%d\n", heredoc_cnt);
+                               if (heredoc_cnt) {
+                                       if (fetch_heredocs(heredoc_cnt, &ctx, input)) {
+                                               goto parse_error;
+                                       }
+                                       heredoc_cnt = 0;
+                               }
                                dest.o_assignment = MAYBE_ASSIGNMENT;
                                ch = ';';
                                /* note: if (is_ifs) continue;
                                 * will still trigger for us */
                        }
                }
-               if (end_trigger && end_trigger == ch) {
-//TODO: disallow "{ cmd }" without semicolon
+
+               /* "cmd}" or "cmd }..." without semicolon or &:
+                * } is an ordinary char in this case, even inside { cmd; }
+                * Pathological example: { ""}; } should exec "}" cmd
+                */
+               if (ch == '}') {
+                       if (!IS_NULL_CMD(ctx.command) /* cmd } */
+                        || dest.length != 0 /* word} */
+                        || dest.o_quoted    /* ""} */
+                       ) {
+                               goto ordinary_char;
+                       }
+                       if (!IS_NULL_PIPE(ctx.pipe)) /* cmd | } */
+                               goto skip_end_trigger;
+                       /* else: } does terminate a group */
+               }
+
+               if (end_trigger && end_trigger == ch
+                && (ch != ';' || heredoc_cnt == 0)
+#if ENABLE_HUSH_CASE
+                && (ch != ')'
+                   || ctx.ctx_res_w != RES_MATCH
+                   || (!dest.o_quoted && strcmp(dest.data, "esac") == 0)
+                   )
+#endif
+               ) {
+                       if (heredoc_cnt) {
+                               /* This is technically valid:
+                                * { cat <<HERE; }; echo Ok
+                                * heredoc
+                                * heredoc
+                                * HERE
+                                * but we don't support this.
+                                * We require heredoc to be in enclosing {}/(),
+                                * if any.
+                                */
+                               syntax_error_unterm_str("here document");
+                               goto parse_error;
+                       }
                        if (done_word(&dest, &ctx)) {
                                goto parse_error;
                        }
@@ -4570,9 +6412,6 @@ static struct pipe *parse_stream(char **pstring,
                        if (!HAS_KEYWORDS
                         IF_HAS_KEYWORDS(|| (ctx.ctx_res_w == RES_NONE && ctx.old_flag == 0))
                        ) {
-                               debug_printf_parse("parse_stream return %p: "
-                                               "end_trigger char found\n",
-                                               ctx.list_head);
                                o_free(&dest);
 #if !BB_MMU
                                debug_printf_parse("as_string '%s'\n", ctx.as_string.data);
@@ -4581,22 +6420,78 @@ static struct pipe *parse_stream(char **pstring,
                                else
                                        o_free_unsafe(&ctx.as_string);
 #endif
+                               debug_leave();
+                               debug_printf_parse("parse_stream return %p: "
+                                               "end_trigger char found\n",
+                                               ctx.list_head);
                                return ctx.list_head;
                        }
                }
+ skip_end_trigger:
                if (is_ifs)
                        continue;
 
-               if (dest.o_assignment == MAYBE_ASSIGNMENT) {
+               /* Catch <, > before deciding whether this word is
+                * an assignment. a=1 2>z b=2: b=2 is still assignment */
+               switch (ch) {
+               case '>':
+                       redir_fd = redirect_opt_num(&dest);
+                       if (done_word(&dest, &ctx)) {
+                               goto parse_error;
+                       }
+                       redir_style = REDIRECT_OVERWRITE;
+                       if (next == '>') {
+                               redir_style = REDIRECT_APPEND;
+                               ch = i_getch(input);
+                               nommu_addchr(&ctx.as_string, ch);
+                       }
+#if 0
+                       else if (next == '(') {
+                               syntax_error(">(process) not supported");
+                               goto parse_error;
+                       }
+#endif
+                       if (parse_redirect(&ctx, redir_fd, redir_style, input))
+                               goto parse_error;
+                       continue; /* back to top of while (1) */
+               case '<':
+                       redir_fd = redirect_opt_num(&dest);
+                       if (done_word(&dest, &ctx)) {
+                               goto parse_error;
+                       }
+                       redir_style = REDIRECT_INPUT;
+                       if (next == '<') {
+                               redir_style = REDIRECT_HEREDOC;
+                               heredoc_cnt++;
+                               debug_printf_parse("++heredoc_cnt=%d\n", heredoc_cnt);
+                               ch = i_getch(input);
+                               nommu_addchr(&ctx.as_string, ch);
+                       } else if (next == '>') {
+                               redir_style = REDIRECT_IO;
+                               ch = i_getch(input);
+                               nommu_addchr(&ctx.as_string, ch);
+                       }
+#if 0
+                       else if (next == '(') {
+                               syntax_error("<(process) not supported");
+                               goto parse_error;
+                       }
+#endif
+                       if (parse_redirect(&ctx, redir_fd, redir_style, input))
+                               goto parse_error;
+                       continue; /* back to top of while (1) */
+               }
+
+               if (dest.o_assignment == MAYBE_ASSIGNMENT
+                /* check that we are not in word in "a=1 2>word b=1": */
+                && !ctx.pending_redirect
+               ) {
                        /* ch is a special char and thus this word
                         * cannot be an assignment */
                        dest.o_assignment = NOT_ASSIGNMENT;
                }
 
-               next = '\0';
-               if (ch != '\n') {
-                       next = i_peek(input);
-               }
+               /* Note: nommu_addchr(&ctx.as_string, ch) is already done */
 
                switch (ch) {
                case '#':
@@ -4608,24 +6503,31 @@ static struct pipe *parse_stream(char **pstring,
                                        i_getch(input);
                                        /* note: we do not add it to &ctx.as_string */
                                }
-#if !BB_MMU
-//TODO: go back one char?
-                               o_addchr(&ctx.as_string, '\n');
-#endif
+                               nommu_addchr(&ctx.as_string, '\n');
                        } else {
                                o_addQchr(&dest, ch);
                        }
                        break;
                case '\\':
                        if (next == EOF) {
-                               syntax("\\<eof>");
-                               goto parse_error;
+                               syntax_error("\\<eof>");
+                               xfunc_die();
                        }
-                       o_addchr(&dest, '\\');
                        ch = i_getch(input);
-                       o_addchr(&dest, ch);
+                       if (ch != '\n') {
+                               o_addchr(&dest, '\\');
+                               /*nommu_addchr(&ctx.as_string, '\\'); - already done */
+                               o_addchr(&dest, ch);
+                               nommu_addchr(&ctx.as_string, ch);
+                               /* Example: echo Hello \2>file
+                                * we need to know that word 2 is quoted */
+                               dest.o_quoted = 1;
+                       }
 #if !BB_MMU
-                       o_addchr(&ctx.as_string, ch);
+                       else {
+                               /* It's "\<newline>". Remove trailing '\' from ctx.as_string */
+                               ctx.as_string.data[--ctx.as_string.length] = '\0';
+                       }
 #endif
                        break;
                case '$':
@@ -4636,89 +6538,45 @@ static struct pipe *parse_stream(char **pstring,
                        }
                        break;
                case '\'':
-                       dest.nonnull = 1;
+                       dest.o_quoted = 1;
                        while (1) {
                                ch = i_getch(input);
                                if (ch == EOF) {
-                                       syntax("unterminated '");
-                                       goto parse_error;
+                                       syntax_error_unterm_ch('\'');
+                                       /*xfunc_die(); - redundant */
                                }
-#if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
-#endif
+                               nommu_addchr(&ctx.as_string, ch);
                                if (ch == '\'')
                                        break;
-                               if (dest.o_assignment == NOT_ASSIGNMENT)
-                                       o_addqchr(&dest, ch);
-                               else
-                                       o_addchr(&dest, ch);
+                               o_addqchr(&dest, ch);
                        }
                        break;
                case '"':
-                       dest.nonnull = 1;
+                       dest.o_quoted = 1;
                        is_in_dquote ^= 1; /* invert */
-                       if (dest.o_assignment == NOT_ASSIGNMENT)
-                               dest.o_escape ^= 1;
-                       break;
-#if ENABLE_HUSH_TICK
-               case '`': {
-                       //int pos = dest.length;
-                       o_addchr(&dest, SPECIAL_VAR_SYMBOL);
-                       o_addchr(&dest, '`');
-                       add_till_backquote(&dest, input);
-                       o_addchr(&dest, SPECIAL_VAR_SYMBOL);
-                       //debug_printf_subst("SUBST RES3 '%s'\n", dest.data + pos);
-                       break;
-               }
-#endif
-               case '>':
-                       redir_fd = redirect_opt_num(&dest);
-                       if (done_word(&dest, &ctx)) {
-                               goto parse_error;
-                       }
-                       redir_style = REDIRECT_OVERWRITE;
-                       if (next == '>') {
-                               redir_style = REDIRECT_APPEND;
-                               ch = i_getch(input);
-#if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
-#endif
-                       }
-#if 0
-                       else if (next == '(') {
-                               syntax(">(process) not supported");
-                               goto parse_error;
-                       }
-#endif
-                       setup_redirect(&ctx, redir_fd, redir_style, input);
-                       break;
-               case '<':
-                       redir_fd = redirect_opt_num(&dest);
-                       if (done_word(&dest, &ctx)) {
-                               goto parse_error;
-                       }
-                       redir_style = REDIRECT_INPUT;
-                       if (next == '<') {
-                               redir_style = REDIRECT_HEREIS;
-                               ch = i_getch(input);
+                       if (dest.o_assignment == NOT_ASSIGNMENT)
+                               dest.o_escape ^= 1;
+                       break;
+#if ENABLE_HUSH_TICK
+               case '`': {
 #if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
+                       int pos;
 #endif
-                       } else if (next == '>') {
-                               redir_style = REDIRECT_IO;
-                               ch = i_getch(input);
+                       o_addchr(&dest, SPECIAL_VAR_SYMBOL);
+                       o_addchr(&dest, '`');
 #if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
+                       pos = dest.length;
 #endif
-                       }
-#if 0
-                       else if (next == '(') {
-                               syntax("<(process) not supported");
-                               goto parse_error;
-                       }
+                       add_till_backquote(&dest, input);
+#if !BB_MMU
+                       o_addstr(&ctx.as_string, dest.data + pos);
+                       o_addchr(&ctx.as_string, '`');
 #endif
-                       setup_redirect(&ctx, redir_fd, redir_style, input);
+                       o_addchr(&dest, SPECIAL_VAR_SYMBOL);
+                       //debug_printf_subst("SUBST RES3 '%s'\n", dest.data + pos);
                        break;
+               }
+#endif
                case ';':
 #if ENABLE_HUSH_CASE
  case_semi:
@@ -4735,10 +6593,8 @@ static struct pipe *parse_stream(char **pstring,
                                if (ch != ';')
                                        break;
                                ch = i_getch(input);
-#if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
-#endif
-                               if (ctx.ctx_res_w == RES_CASEI) {
+                               nommu_addchr(&ctx.as_string, ch);
+                               if (ctx.ctx_res_w == RES_CASE_BODY) {
                                        ctx.ctx_dsemicolon = 1;
                                        ctx.ctx_res_w = RES_MATCH;
                                        break;
@@ -4756,9 +6612,7 @@ static struct pipe *parse_stream(char **pstring,
                        }
                        if (next == '&') {
                                ch = i_getch(input);
-#if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
-#endif
+                               nommu_addchr(&ctx.as_string, ch);
                                done_pipe(&ctx, PIPE_AND);
                        } else {
                                done_pipe(&ctx, PIPE_BG);
@@ -4774,15 +6628,16 @@ static struct pipe *parse_stream(char **pstring,
 #endif
                        if (next == '|') { /* || */
                                ch = i_getch(input);
-#if !BB_MMU
-                               o_addchr(&ctx.as_string, ch);
-#endif
+                               nommu_addchr(&ctx.as_string, ch);
                                done_pipe(&ctx, PIPE_OR);
                        } else {
                                /* we could pick up a file descriptor choice here
                                 * with redirect_opt_num(), but bash doesn't do it.
                                 * "echo foo 2| cat" yields "foo 2". */
                                done_command(&ctx);
+#if !BB_MMU
+                               o_reset_to_empty_unquoted(&ctx.as_string);
+#endif
                        }
                        goto new_cmd;
                case '(':
@@ -4791,32 +6646,10 @@ static struct pipe *parse_stream(char **pstring,
                        if (ctx.ctx_res_w == RES_MATCH
                         && ctx.command->argv == NULL /* not (word|(... */
                         && dest.length == 0 /* not word(... */
-                        && dest.nonnull == 0 /* not ""(... */
+                        && dest.o_quoted == 0 /* not ""(... */
                        ) {
                                continue;
                        }
-#endif
-#if ENABLE_HUSH_FUNCTIONS
-                       if (dest.length != 0 /* not just () but word() */
-                        && dest.nonnull == 0 /* not a"b"c() */
-                        && ctx.command->argv == NULL /* it's the first word */
-//TODO: "func ( ) {...}" - note spaces - is valid format too in bash
-                        && i_peek(input) == ')'
-                        && !match_reserved_word(&dest)
-                       ) {
-                               bb_error_msg("seems like a function definition");
-                               i_getch(input);
-//if !BB_MMU o_addchr(&ctx.as_string...
-                               do {
-//TODO: do it properly.
-                                       ch = i_getch(input);
-                               } while (ch == ' ' || ch == '\n');
-                               if (ch != '{') {
-                                       syntax("was expecting {");
-                                       goto parse_error;
-                               }
-                               ch = 'F'; /* magic value */
-                       }
 #endif
                case '{':
                        if (parse_group(&dest, &ctx, input, ch) != 0) {
@@ -4832,7 +6665,7 @@ static struct pipe *parse_stream(char **pstring,
                        /* proper use of this character is caught by end_trigger:
                         * if we see {, we call parse_group(..., end_trigger='}')
                         * and it will match } earlier (not here). */
-                       syntax("unexpected } or )");
+                       syntax_error_unexpected_ch(ch);
                        goto parse_error;
                default:
                        if (HUSH_DEBUG)
@@ -4846,10 +6679,8 @@ static struct pipe *parse_stream(char **pstring,
                IF_HAS_KEYWORDS(struct parse_context *p2;)
 
                /* Clean up allocated tree.
-                * Samples for finding leaks on syntax error recovery path.
-                * Run them from interactive shell, watch pmap `pidof hush`.
-                * while if false; then false; fi do break; done
-                * (bash accepts it)
+                * Sample for finding leaks on syntax error recovery path.
+                * Run it from interactive shell, watch pmap `pidof hush`.
                 * while if false; then false; fi; do break; fi
                 * Samples to catch leaks at execution:
                 * while if (true | {true;}); then echo ok; fi; do break; done
@@ -4863,7 +6694,7 @@ static struct pipe *parse_stream(char **pstring,
                        debug_printf_clean("freeing list %p from ctx %p\n",
                                        pctx->list_head, pctx);
                        debug_print_tree(pctx->list_head, 0);
-                       free_pipe_list(pctx->list_head, 0);
+                       free_pipe_list(pctx->list_head);
                        debug_printf_clean("freed list %p\n", pctx->list_head);
 #if !BB_MMU
                        o_free_unsafe(&pctx->as_string);
@@ -4884,11 +6715,12 @@ static struct pipe *parse_stream(char **pstring,
                        if (pstring)
                                *pstring = NULL;
 #endif
+                       debug_leave();
                        return ERR_PTR;
                }
                /* Discard cached input, force prompt */
                input->p = NULL;
-               USE_HUSH_INTERACTIVE(input->promptme = 1;)
+               IF_HUSH_INTERACTIVE(input->promptme = 1;)
                goto reset;
        }
 }
@@ -4901,15 +6733,26 @@ static struct pipe *parse_stream(char **pstring,
  */
 static void parse_and_run_stream(struct in_str *inp, int end_trigger)
 {
+       /* Why we need empty flag?
+        * An obscure corner case "false; ``; echo $?":
+        * empty command in `` should still set $? to 0.
+        * But we can't just set $? to 0 at the start,
+        * this breaks "false; echo `echo $?`" case.
+        */
+       bool empty = 1;
        while (1) {
                struct pipe *pipe_list;
 
                pipe_list = parse_stream(NULL, inp, end_trigger);
-               if (!pipe_list) /* EOF */
+               if (!pipe_list) { /* EOF */
+                       if (empty)
+                               G.last_exitcode = 0;
                        break;
+               }
                debug_print_tree(pipe_list, 0);
                debug_printf_exec("parse_and_run_stream: run_and_free_list\n");
                run_and_free_list(pipe_list);
+               empty = 0;
        }
 }
 
@@ -4928,27 +6771,26 @@ static void parse_and_run_file(FILE *f)
 }
 
 /* Called a few times only (or even once if "sh -c") */
-static void block_signals(int second_time)
+static void init_sigmasks(void)
 {
        unsigned sig;
        unsigned mask;
+       sigset_t old_blocked_set;
+
+       if (!G.inherited_set_is_saved) {
+               sigprocmask(SIG_SETMASK, NULL, &G.blocked_set);
+               G.inherited_set = G.blocked_set;
+       }
+       old_blocked_set = G.blocked_set;
 
        mask = (1 << SIGQUIT);
        if (G_interactive_fd) {
-               mask = 0
-                       | (1 << SIGQUIT)
-                       | (1 << SIGTERM)
-                       | (1 << SIGHUP)
-#if ENABLE_HUSH_JOB
-                       | (1 << SIGTTIN) | (1 << SIGTTOU) | (1 << SIGTSTP)
-#endif
-                       | (1 << SIGINT)
-               ;
+               mask = (1 << SIGQUIT) | SPECIAL_INTERACTIVE_SIGS;
+               if (G_saved_tty_pgrp) /* we have ctty, job control sigs work */
+                       mask |= SPECIAL_JOB_SIGS;
        }
        G.non_DFL_mask = mask;
 
-       if (!second_time)
-               sigprocmask(SIG_SETMASK, NULL, &G.blocked_set);
        sig = 0;
        while (mask) {
                if (mask & 1)
@@ -4958,13 +6800,21 @@ static void block_signals(int second_time)
        }
        sigdelset(&G.blocked_set, SIGCHLD);
 
-       sigprocmask(SIG_SETMASK, &G.blocked_set,
-                       second_time ? NULL : &G.inherited_set);
+       if (memcmp(&old_blocked_set, &G.blocked_set, sizeof(old_blocked_set)) != 0)
+               sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
+
        /* POSIX allows shell to re-enable SIGCHLD
         * even if it was SIG_IGN on entry */
-//     G.count_SIGCHLD++; /* ensure it is != G.handled_SIGCHLD */
-       if (!second_time)
-               signal(SIGCHLD, SIG_DFL); // SIGCHLD_handler);
+#if ENABLE_HUSH_FAST
+       G.count_SIGCHLD++; /* ensure it is != G.handled_SIGCHLD */
+       if (!G.inherited_set_is_saved)
+               signal(SIGCHLD, SIGCHLD_handler);
+#else
+       if (!G.inherited_set_is_saved)
+               signal(SIGCHLD, SIG_DFL);
+#endif
+
+       G.inherited_set_is_saved = 1;
 }
 
 #if ENABLE_HUSH_JOB
@@ -4981,7 +6831,7 @@ static void maybe_set_to_sigexit(int sig)
                        signal(sig, handler);
        }
 }
-/* Set handlers to restore tty pgrm and exit */
+/* Set handlers to restore tty pgrp and exit */
 static void set_fatal_handlers(void)
 {
        /* We _must_ restore tty pgrp on fatal signals */
@@ -4996,10 +6846,10 @@ static void set_fatal_handlers(void)
        /* bash 3.2 seems to handle these just like 'fatal' ones */
        maybe_set_to_sigexit(SIGPIPE);
        maybe_set_to_sigexit(SIGALRM);
-       maybe_set_to_sigexit(SIGHUP );
-       /* if we are interactive, SIGTERM and SIGINT are masked.
+       /* if we are interactive, SIGHUP, SIGTERM and SIGINT are masked.
         * if we aren't interactive... but in this case
         * we never want to restore pgrp on exit, and this fn is not called */
+       /*maybe_set_to_sigexit(SIGHUP );*/
        /*maybe_set_to_sigexit(SIGTERM);*/
        /*maybe_set_to_sigexit(SIGINT );*/
 }
@@ -5026,14 +6876,14 @@ int hush_main(int argc, char **argv)
                .flg_export = 1,
                .flg_read_only = 1,
        };
-       int signal_mask_is_inited = 0;
        int opt;
+       unsigned builtin_argc;
        char **e;
        struct variable *cur_var;
 
        INIT_G();
-       if (EXIT_SUCCESS) /* if EXIT_SUCCESS == 0, is already done */
-               G.last_return_code = EXIT_SUCCESS;
+       if (EXIT_SUCCESS) /* if EXIT_SUCCESS == 0, it is already done */
+               G.last_exitcode = EXIT_SUCCESS;
 #if !BB_MMU
        G.argv0_for_re_execing = argv[0];
 #endif
@@ -5057,51 +6907,124 @@ int hush_main(int argc, char **argv)
                }
                e++;
        }
+       /* reinstate HUSH_VERSION */
        debug_printf_env("putenv '%s'\n", hush_version_str);
-       putenv((char *)hush_version_str); /* reinstate HUSH_VERSION */
+       putenv((char *)hush_version_str);
+
+       /* Export PWD */
+       set_pwd_var(/*exp:*/ 1);
+       /* bash also exports SHLVL and _,
+        * and sets (but doesn't export) the following variables:
+        * BASH=/bin/bash
+        * BASH_VERSINFO=([0]="3" [1]="2" [2]="0" [3]="1" [4]="release" [5]="i386-pc-linux-gnu")
+        * BASH_VERSION='3.2.0(1)-release'
+        * HOSTTYPE=i386
+        * MACHTYPE=i386-pc-linux-gnu
+        * OSTYPE=linux-gnu
+        * HOSTNAME=<xxxxxxxxxx>
+        * PPID=<NNNNN> - we also do it elsewhere
+        * EUID=<NNNNN>
+        * UID=<NNNNN>
+        * GROUPS=()
+        * LINES=<NNN>
+        * COLUMNS=<NNN>
+        * BASH_ARGC=()
+        * BASH_ARGV=()
+        * BASH_LINENO=()
+        * BASH_SOURCE=()
+        * DIRSTACK=()
+        * PIPESTATUS=([0]="0")
+        * HISTFILE=/<xxx>/.bash_history
+        * HISTFILESIZE=500
+        * HISTSIZE=500
+        * MAILCHECK=60
+        * PATH=/usr/gnu/bin:/usr/local/bin:/bin:/usr/bin:.
+        * SHELL=/bin/bash
+        * SHELLOPTS=braceexpand:emacs:hashall:histexpand:history:interactive-comments:monitor
+        * TERM=dumb
+        * OPTERR=1
+        * OPTIND=1
+        * IFS=$' \t\n'
+        * PS1='\s-\v\$ '
+        * PS2='> '
+        * PS4='+ '
+        */
+
 #if ENABLE_FEATURE_EDITING
        G.line_input_state = new_line_input_t(FOR_SHELL);
 #endif
        G.global_argc = argc;
        G.global_argv = argv;
        /* Initialize some more globals to non-zero values */
-       set_cwd();
-#if ENABLE_HUSH_INTERACTIVE
-       if (ENABLE_FEATURE_EDITING)
-               cmdedit_set_initial_prompt();
-       G.PS2 = "> ";
-#endif
+       cmdedit_update_prompt();
+
+       if (setjmp(die_jmp)) {
+               /* xfunc has failed! die die die */
+               /* no EXIT traps, this is an escape hatch! */
+               G.exiting = 1;
+               hush_exit(xfunc_error_retval);
+       }
 
        /* Shell is non-interactive at first. We need to call
-        * block_signals(0) if we are going to execute "sh script",
-        * "sh -c cmds" or login shell's /etc/profile and friends.
-        * If we later decide that we are interactive, we run block_signals(0)
-        * (or re-run block_signals(1) if we ran block_signals(0) before)
+        * init_sigmasks() if we are going to execute "sh <script>",
+        * "sh -c <cmds>" or login shell's /etc/profile and friends.
+        * If we later decide that we are interactive, we run init_sigmasks()
         * in order to intercept (more) signals.
         */
 
        /* Parse options */
        /* http://www.opengroup.org/onlinepubs/9699919799/utilities/sh.html */
+       builtin_argc = 0;
        while (1) {
-               opt = getopt(argc, argv, "c:xins"
+               opt = getopt(argc, argv, "+c:xins"
 #if !BB_MMU
-                               "$:!:?:D:R:V:"
+                               "<:$:R:V:"
+# if ENABLE_HUSH_FUNCTIONS
+                               "F:"
+# endif
 #endif
                );
                if (opt <= 0)
                        break;
                switch (opt) {
                case 'c':
-                       if (!G.root_pid)
+                       /* Possibilities:
+                        * sh ... -c 'script'
+                        * sh ... -c 'script' ARG0 [ARG1...]
+                        * On NOMMU, if builtin_argc != 0,
+                        * sh ... -c 'builtin' BARGV... "" ARG0 [ARG1...]
+                        * "" needs to be replaced with NULL
+                        * and BARGV vector fed to builtin function.
+                        * Note: the form without ARG0 never happens:
+                        * sh ... -c 'builtin' BARGV... ""
+                        */
+                       if (!G.root_pid) {
                                G.root_pid = getpid();
+                               G.root_ppid = getppid();
+                       }
                        G.global_argv = argv + optind;
-                       if (!argv[optind]) {
-                               /* -c 'script' (no params): prevent empty $0 */
-                               *--G.global_argv = argv[0];
-                               optind--;
-                       } /* else -c 'script' PAR0 PAR1: $0 is PAR0 */
                        G.global_argc = argc - optind;
-                       block_signals(0); /* 0: called 1st time */
+                       if (builtin_argc) {
+                               /* -c 'builtin' [BARGV...] "" ARG0 [ARG1...] */
+                               const struct built_in_command *x;
+
+                               init_sigmasks();
+                               x = find_builtin(optarg);
+                               if (x) { /* paranoia */
+                                       G.global_argc -= builtin_argc; /* skip [BARGV...] "" */
+                                       G.global_argv += builtin_argc;
+                                       G.global_argv[-1] = NULL; /* replace "" */
+                                       G.last_exitcode = x->b_function(argv + optind - 1);
+                               }
+                               goto final_return;
+                       }
+                       if (!G.global_argv[0]) {
+                               /* -c 'script' (no params): prevent empty $0 */
+                               G.global_argv--; /* points to argv[i] of 'script' */
+                               G.global_argv[0] = argv[0];
+                               G.global_argc--;
+                       } /* else -c 'script' ARG0 [ARG1...]: $0 is ARG0 */
+                       init_sigmasks();
                        parse_and_run_string(optarg);
                        goto final_return;
                case 'i':
@@ -5114,24 +7037,55 @@ int hush_main(int argc, char **argv)
                         * operate, so simply do nothing here. */
                        break;
 #if !BB_MMU
-               case '$':
-                       G.root_pid = xatoi_u(optarg);
-                       break;
-               case '!':
-                       G.last_bg_pid = xatoi_u(optarg);
-                       break;
-               case '?':
-                       G.last_return_code = xatoi_u(optarg);
-                       break;
-#if ENABLE_HUSH_LOOPS
-               case 'D':
-                       G.depth_of_loop = xatoi_u(optarg);
+               case '<': /* "big heredoc" support */
+                       full_write(STDOUT_FILENO, optarg, strlen(optarg));
+                       _exit(0);
+               case '$': {
+                       unsigned long long empty_trap_mask;
+
+                       G.root_pid = bb_strtou(optarg, &optarg, 16);
+                       optarg++;
+                       G.root_ppid = bb_strtou(optarg, &optarg, 16);
+                       optarg++;
+                       G.last_bg_pid = bb_strtou(optarg, &optarg, 16);
+                       optarg++;
+                       G.last_exitcode = bb_strtou(optarg, &optarg, 16);
+                       optarg++;
+                       builtin_argc = bb_strtou(optarg, &optarg, 16);
+                       optarg++;
+                       empty_trap_mask = bb_strtoull(optarg, &optarg, 16);
+                       if (empty_trap_mask != 0) {
+                               int sig;
+                               init_sigmasks();
+                               G.traps = xzalloc(sizeof(G.traps[0]) * NSIG);
+                               for (sig = 1; sig < NSIG; sig++) {
+                                       if (empty_trap_mask & (1LL << sig)) {
+                                               G.traps[sig] = xzalloc(1); /* == xstrdup(""); */
+                                               sigaddset(&G.blocked_set, sig);
+                                       }
+                               }
+                               sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
+                       }
+# if ENABLE_HUSH_LOOPS
+                       optarg++;
+                       G.depth_of_loop = bb_strtou(optarg, &optarg, 16);
+# endif
                        break;
-#endif
+               }
                case 'R':
                case 'V':
-                       set_local_var(xstrdup(optarg), 0, opt == 'R');
+                       set_local_var(xstrdup(optarg), /*exp:*/ 0, /*lvl:*/ 0, /*ro:*/ opt == 'R');
+                       break;
+# if ENABLE_HUSH_FUNCTIONS
+               case 'F': {
+                       struct function *funcp = new_function(optarg);
+                       /* funcp->name is already set to optarg */
+                       /* funcp->body is set to NULL. It's a special case. */
+                       funcp->body_as_string = argv[optind];
+                       optind++;
                        break;
+               }
+# endif
 #endif
                case 'n':
                case 'x':
@@ -5148,26 +7102,26 @@ int hush_main(int argc, char **argv)
                }
        } /* option parsing loop */
 
-       if (!G.root_pid)
+       if (!G.root_pid) {
                G.root_pid = getpid();
+               G.root_ppid = getppid();
+       }
 
        /* If we are login shell... */
        if (argv[0] && argv[0][0] == '-') {
                FILE *input;
-               /* XXX what should argv be while sourcing /etc/profile? */
                debug_printf("sourcing /etc/profile\n");
                input = fopen_for_read("/etc/profile");
                if (input != NULL) {
                        close_on_exec_on(fileno(input));
-                       block_signals(0); /* 0: called 1st time */
-                       signal_mask_is_inited = 1;
+                       init_sigmasks();
                        parse_and_run_file(input);
                        fclose(input);
                }
                /* bash: after sourcing /etc/profile,
                 * tries to source (in the given order):
                 * ~/.bash_profile, ~/.bash_login, ~/.profile,
-                * stopping of first found. --noprofile turns this off.
+                * stopping on first found. --noprofile turns this off.
                 * bash also sources ~/.bash_logout on exit.
                 * If called as sh, skips .bash_XXX files.
                 */
@@ -5176,8 +7130,8 @@ int hush_main(int argc, char **argv)
        if (argv[optind]) {
                FILE *input;
                /*
-                * Non-interactive "bash <script>" sources $BASH_ENV here
-                * (without scanning $PATH).
+                * "bash <script>" (which is never interactive (unless -i?))
+                * sources $BASH_ENV here (without scanning $PATH).
                 * If called as sh, does the same but with $ENV.
                 */
                debug_printf("running script '%s'\n", argv[optind]);
@@ -5185,8 +7139,7 @@ int hush_main(int argc, char **argv)
                G.global_argc = argc - optind;
                input = xfopen_for_read(argv[optind]);
                close_on_exec_on(fileno(input));
-               if (!signal_mask_is_inited)
-                       block_signals(0); /* 0: called 1st time */
+               init_sigmasks();
                parse_and_run_file(input);
 #if ENABLE_FEATURE_CLEAN_UP
                fclose(input);
@@ -5195,180 +7148,455 @@ int hush_main(int argc, char **argv)
        }
 
        /* Up to here, shell was non-interactive. Now it may become one.
-        * NB: don't forget to (re)run block_signals(0/1) as needed.
+        * NB: don't forget to (re)run init_sigmasks() as needed.
+        */
+
+       /* A shell is interactive if the '-i' flag was given,
+        * or if all of the following conditions are met:
+        *    no -c command
+        *    no arguments remaining or the -s flag given
+        *    standard input is a terminal
+        *    standard output is a terminal
+        * Refer to Posix.2, the description of the 'sh' utility.
+        */
+#if ENABLE_HUSH_JOB
+       if (isatty(STDIN_FILENO) && isatty(STDOUT_FILENO)) {
+               G_saved_tty_pgrp = tcgetpgrp(STDIN_FILENO);
+               debug_printf("saved_tty_pgrp:%d\n", G_saved_tty_pgrp);
+               if (G_saved_tty_pgrp < 0)
+                       G_saved_tty_pgrp = 0;
+
+               /* try to dup stdin to high fd#, >= 255 */
+               G_interactive_fd = fcntl(STDIN_FILENO, F_DUPFD, 255);
+               if (G_interactive_fd < 0) {
+                       /* try to dup to any fd */
+                       G_interactive_fd = dup(STDIN_FILENO);
+                       if (G_interactive_fd < 0) {
+                               /* give up */
+                               G_interactive_fd = 0;
+                               G_saved_tty_pgrp = 0;
+                       }
+               }
+// TODO: track & disallow any attempts of user
+// to (inadvertently) close/redirect G_interactive_fd
+       }
+       debug_printf("interactive_fd:%d\n", G_interactive_fd);
+       if (G_interactive_fd) {
+               close_on_exec_on(G_interactive_fd);
+
+               if (G_saved_tty_pgrp) {
+                       /* If we were run as 'hush &', sleep until we are
+                        * in the foreground (tty pgrp == our pgrp).
+                        * If we get started under a job aware app (like bash),
+                        * make sure we are now in charge so we don't fight over
+                        * who gets the foreground */
+                       while (1) {
+                               pid_t shell_pgrp = getpgrp();
+                               G_saved_tty_pgrp = tcgetpgrp(G_interactive_fd);
+                               if (G_saved_tty_pgrp == shell_pgrp)
+                                       break;
+                               /* send TTIN to ourself (should stop us) */
+                               kill(- shell_pgrp, SIGTTIN);
+                       }
+               }
+
+               /* Block some signals */
+               init_sigmasks();
+
+               if (G_saved_tty_pgrp) {
+                       /* Set other signals to restore saved_tty_pgrp */
+                       set_fatal_handlers();
+                       /* Put ourselves in our own process group
+                        * (bash, too, does this only if ctty is available) */
+                       bb_setpgrp(); /* is the same as setpgid(our_pid, our_pid); */
+                       /* Grab control of the terminal */
+                       tcsetpgrp(G_interactive_fd, getpid());
+               }
+               /* -1 is special - makes xfuncs longjmp, not exit
+                * (we reset die_sleep = 0 whereever we [v]fork) */
+               enable_restore_tty_pgrp_on_exit(); /* sets die_sleep = -1 */
+       } else {
+               init_sigmasks();
+       }
+#elif ENABLE_HUSH_INTERACTIVE
+       /* No job control compiled in, only prompt/line editing */
+       if (isatty(STDIN_FILENO) && isatty(STDOUT_FILENO)) {
+               G_interactive_fd = fcntl(STDIN_FILENO, F_DUPFD, 255);
+               if (G_interactive_fd < 0) {
+                       /* try to dup to any fd */
+                       G_interactive_fd = dup(STDIN_FILENO);
+                       if (G_interactive_fd < 0)
+                               /* give up */
+                               G_interactive_fd = 0;
+               }
+       }
+       if (G_interactive_fd) {
+               close_on_exec_on(G_interactive_fd);
+       }
+       init_sigmasks();
+#else
+       /* We have interactiveness code disabled */
+       init_sigmasks();
+#endif
+       /* bash:
+        * if interactive but not a login shell, sources ~/.bashrc
+        * (--norc turns this off, --rcfile <file> overrides)
+        */
+
+       if (!ENABLE_FEATURE_SH_EXTRA_QUIET && G_interactive_fd) {
+               /* note: ash and hush share this string */
+               printf("\n\n%s %s\n"
+                       IF_HUSH_HELP("Enter 'help' for a list of built-in commands.\n")
+                       "\n",
+                       bb_banner,
+                       "hush - the humble shell"
+               );
+       }
+
+       parse_and_run_file(stdin);
+
+ final_return:
+#if ENABLE_FEATURE_CLEAN_UP
+       if (G.cwd != bb_msg_unknown)
+               free((char*)G.cwd);
+       cur_var = G.top_var->next;
+       while (cur_var) {
+               struct variable *tmp = cur_var;
+               if (!cur_var->max_len)
+                       free(cur_var->varstr);
+               cur_var = cur_var->next;
+               free(tmp);
+       }
+#endif
+       hush_exit(G.last_exitcode);
+}
+
+
+#if ENABLE_LASH
+int lash_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
+int lash_main(int argc, char **argv)
+{
+       bb_error_msg("lash is deprecated, please use hush instead");
+       return hush_main(argc, argv);
+}
+#endif
+
+#if ENABLE_MSH
+int msh_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
+int msh_main(int argc, char **argv)
+{
+       //bb_error_msg("msh is deprecated, please use hush instead");
+       return hush_main(argc, argv);
+}
+#endif
+
+
+/*
+ * Built-ins
+ */
+static int FAST_FUNC builtin_true(char **argv UNUSED_PARAM)
+{
+       return 0;
+}
+
+static int run_applet_main(char **argv, int (*applet_main_func)(int argc, char **argv))
+{
+       int argc = 0;
+       while (*argv) {
+               argc++;
+               argv++;
+       }
+       return applet_main_func(argc, argv - argc);
+}
+
+static int FAST_FUNC builtin_test(char **argv)
+{
+       return run_applet_main(argv, test_main);
+}
+
+static int FAST_FUNC builtin_echo(char **argv)
+{
+       return run_applet_main(argv, echo_main);
+}
+
+#if ENABLE_PRINTF
+static int FAST_FUNC builtin_printf(char **argv)
+{
+       return run_applet_main(argv, printf_main);
+}
+#endif
+
+static char **skip_dash_dash(char **argv)
+{
+       argv++;
+       if (argv[0] && argv[0][0] == '-' && argv[0][1] == '-' && argv[0][2] == '\0')
+               argv++;
+       return argv;
+}
+
+static int FAST_FUNC builtin_eval(char **argv)
+{
+       int rcode = EXIT_SUCCESS;
+
+       argv = skip_dash_dash(argv);
+       if (*argv) {
+               char *str = expand_strvec_to_string(argv);
+               /* bash:
+                * eval "echo Hi; done" ("done" is syntax error):
+                * "echo Hi" will not execute too.
+                */
+               parse_and_run_string(str);
+               free(str);
+               rcode = G.last_exitcode;
+       }
+       return rcode;
+}
+
+static int FAST_FUNC builtin_cd(char **argv)
+{
+       const char *newdir;
+
+       argv = skip_dash_dash(argv);
+       newdir = argv[0];
+       if (newdir == NULL) {
+               /* bash does nothing (exitcode 0) if HOME is ""; if it's unset,
+                * bash says "bash: cd: HOME not set" and does nothing
+                * (exitcode 1)
+                */
+               const char *home = get_local_var_value("HOME");
+               newdir = home ? home : "/";
+       }
+       if (chdir(newdir)) {
+               /* Mimic bash message exactly */
+               bb_perror_msg("cd: %s", newdir);
+               return EXIT_FAILURE;
+       }
+       /* Read current dir (get_cwd(1) is inside) and set PWD.
+        * Note: do not enforce exporting. If PWD was unset or unexported,
+        * set it again, but do not export. bash does the same.
+        */
+       set_pwd_var(/*exp:*/ 0);
+       return EXIT_SUCCESS;
+}
+
+static int FAST_FUNC builtin_exec(char **argv)
+{
+       argv = skip_dash_dash(argv);
+       if (argv[0] == NULL)
+               return EXIT_SUCCESS; /* bash does this */
+
+       /* Careful: we can end up here after [v]fork. Do not restore
+        * tty pgrp then, only top-level shell process does that */
+       if (G_saved_tty_pgrp && getpid() == G.root_pid)
+               tcsetpgrp(G_interactive_fd, G_saved_tty_pgrp);
+
+       /* TODO: if exec fails, bash does NOT exit! We do.
+        * We'll need to undo sigprocmask (it's inside execvp_or_die)
+        * and tcsetpgrp, and this is inherently racy.
+        */
+       execvp_or_die(argv);
+}
+
+static int FAST_FUNC builtin_exit(char **argv)
+{
+       debug_printf_exec("%s()\n", __func__);
+
+       /* interactive bash:
+        * # trap "echo EEE" EXIT
+        * # exit
+        * exit
+        * There are stopped jobs.
+        * (if there are _stopped_ jobs, running ones don't count)
+        * # exit
+        * exit
+        # EEE (then bash exits)
+        *
+        * we can use G.exiting = -1 as indicator "last cmd was exit"
         */
 
-       /* A shell is interactive if the '-i' flag was given, or if all of
-        * the following conditions are met:
-        *    no -c command
-        *    no arguments remaining or the -s flag given
-        *    standard input is a terminal
-        *    standard output is a terminal
-        * Refer to Posix.2, the description of the 'sh' utility.
-        */
-#if ENABLE_HUSH_JOB
-       if (isatty(STDIN_FILENO) && isatty(STDOUT_FILENO)) {
-               G.saved_tty_pgrp = tcgetpgrp(STDIN_FILENO);
-               debug_printf("saved_tty_pgrp:%d\n", G.saved_tty_pgrp);
-               if (G.saved_tty_pgrp >= 0) {
-                       /* try to dup stdin to high fd#, >= 255 */
-                       G_interactive_fd = fcntl(STDIN_FILENO, F_DUPFD, 255);
-                       if (G_interactive_fd < 0) {
-                               /* try to dup to any fd */
-                               G_interactive_fd = dup(STDIN_FILENO);
-                               if (G_interactive_fd < 0)
-                                       /* give up */
-                                       G_interactive_fd = 0;
+       /* note: EXIT trap is run by hush_exit */
+       argv = skip_dash_dash(argv);
+       if (argv[0] == NULL)
+               hush_exit(G.last_exitcode);
+       /* mimic bash: exit 123abc == exit 255 + error msg */
+       xfunc_error_retval = 255;
+       /* bash: exit -2 == exit 254, no error msg */
+       hush_exit(xatoi(argv[0]) & 0xff);
+}
+
+static void print_escaped(const char *s)
+{
+       if (*s == '\'')
+               goto squote;
+       do {
+               const char *p = strchrnul(s, '\'');
+               /* print 'xxxx', possibly just '' */
+               printf("'%.*s'", (int)(p - s), s);
+               if (*p == '\0')
+                       break;
+               s = p;
+ squote:
+               /* s points to '; print "'''...'''" */
+               putchar('"');
+               do putchar('\''); while (*++s == '\'');
+               putchar('"');
+       } while (*s);
+}
+
+#if !ENABLE_HUSH_LOCAL
+#define helper_export_local(argv, exp, lvl) \
+       helper_export_local(argv, exp)
+#endif
+static void helper_export_local(char **argv, int exp, int lvl)
+{
+       do {
+               char *name = *argv;
+
+               /* So far we do not check that name is valid (TODO?) */
+
+               if (strchr(name, '=') == NULL) {
+                       struct variable *var;
+
+                       var = get_local_var(name);
+                       if (exp == -1) { /* unexporting? */
+                               /* export -n NAME (without =VALUE) */
+                               if (var) {
+                                       var->flg_export = 0;
+                                       debug_printf_env("%s: unsetenv '%s'\n", __func__, name);
+                                       unsetenv(name);
+                               } /* else: export -n NOT_EXISTING_VAR: no-op */
+                               continue;
                        }
-// TODO: track & disallow any attempts of user
-// to (inadvertently) close/redirect it
+                       if (exp == 1) { /* exporting? */
+                               /* export NAME (without =VALUE) */
+                               if (var) {
+                                       var->flg_export = 1;
+                                       debug_printf_env("%s: putenv '%s'\n", __func__, var->varstr);
+                                       putenv(var->varstr);
+                                       continue;
+                               }
+                       }
+                       /* Exporting non-existing variable.
+                        * bash does not put it in environment,
+                        * but remembers that it is exported,
+                        * and does put it in env when it is set later.
+                        * We just set it to "" and export. */
+                       /* Or, it's "local NAME" (without =VALUE).
+                        * bash sets the value to "". */
+                       name = xasprintf("%s=", name);
+               } else {
+                       /* (Un)exporting/making local NAME=VALUE */
+                       name = xstrdup(name);
                }
-       }
-       debug_printf("interactive_fd:%d\n", G_interactive_fd);
-       if (G_interactive_fd) {
-               pid_t shell_pgrp;
+               set_local_var(name, /*exp:*/ exp, /*lvl:*/ lvl, /*ro:*/ 0);
+       } while (*++argv);
+}
 
-               /* We are indeed interactive shell, and we will perform
-                * job control. Setting up for that. */
+static int FAST_FUNC builtin_export(char **argv)
+{
+       unsigned opt_unexport;
 
-               close_on_exec_on(G_interactive_fd);
-               /* If we were run as 'hush &', sleep until we are
-                * in the foreground (tty pgrp == our pgrp).
-                * If we get started under a job aware app (like bash),
-                * make sure we are now in charge so we don't fight over
-                * who gets the foreground */
-               while (1) {
-                       shell_pgrp = getpgrp();
-                       G.saved_tty_pgrp = tcgetpgrp(G_interactive_fd);
-                       if (G.saved_tty_pgrp == shell_pgrp)
-                               break;
-                       /* send TTIN to ourself (should stop us) */
-                       kill(- shell_pgrp, SIGTTIN);
-               }
-               /* Block some signals */
-               block_signals(signal_mask_is_inited);
-               /* Set other signals to restore saved_tty_pgrp */
-               set_fatal_handlers();
-               /* Put ourselves in our own process group */
-               bb_setpgrp(); /* is the same as setpgid(our_pid, our_pid); */
-               /* Grab control of the terminal */
-               tcsetpgrp(G_interactive_fd, getpid());
-               /* -1 is special - makes xfuncs longjmp, not exit
-                * (we reset die_sleep = 0 whereever we [v]fork) */
-               die_sleep = -1;
-               if (setjmp(die_jmp)) {
-                       /* xfunc has failed! die die die */
-                       hush_exit(xfunc_error_retval);
-               }
-       } else if (!signal_mask_is_inited) {
-               block_signals(0); /* 0: called 1st time */
-       } /* else: block_signals(0) was done before */
-#elif ENABLE_HUSH_INTERACTIVE
-       /* No job control compiled in, only prompt/line editing */
-       if (isatty(STDIN_FILENO) && isatty(STDOUT_FILENO)) {
-               G_interactive_fd = fcntl(STDIN_FILENO, F_DUPFD, 255);
-               if (G_interactive_fd < 0) {
-                       /* try to dup to any fd */
-                       G_interactive_fd = dup(STDIN_FILENO);
-                       if (G_interactive_fd < 0)
-                               /* give up */
-                               G_interactive_fd = 0;
-               }
-       }
-       if (G_interactive_fd) {
-               close_on_exec_on(G_interactive_fd);
-               block_signals(signal_mask_is_inited);
-       } else if (!signal_mask_is_inited) {
-               block_signals(0);
-       }
+#if ENABLE_HUSH_EXPORT_N
+       /* "!": do not abort on errors */
+       opt_unexport = getopt32(argv, "!n");
+       if (opt_unexport == (uint32_t)-1)
+               return EXIT_FAILURE;
+       argv += optind;
 #else
-       /* We have interactiveness code disabled */
-       if (!signal_mask_is_inited) {
-               block_signals(0);
-       }
+       opt_unexport = 0;
+       argv++;
 #endif
-       /* bash:
-        * if interactive but not a login shell, sources ~/.bashrc
-        * (--norc turns this off, --rcfile <file> overrides)
-        */
 
-       if (!ENABLE_FEATURE_SH_EXTRA_QUIET && G_interactive_fd) {
-               printf("\n\n%s hush - the humble shell v"HUSH_VER_STR"\n", bb_banner);
-               printf("Enter 'help' for a list of built-in commands.\n\n");
+       if (argv[0] == NULL) {
+               char **e = environ;
+               if (e) {
+                       while (*e) {
+#if 0
+                               puts(*e++);
+#else
+                               /* ash emits: export VAR='VAL'
+                                * bash: declare -x VAR="VAL"
+                                * we follow ash example */
+                               const char *s = *e++;
+                               const char *p = strchr(s, '=');
+
+                               if (!p) /* wtf? take next variable */
+                                       continue;
+                               /* export var= */
+                               printf("export %.*s", (int)(p - s) + 1, s);
+                               print_escaped(p + 1);
+                               putchar('\n');
+#endif
+                       }
+                       /*fflush_all(); - done after each builtin anyway */
+               }
+               return EXIT_SUCCESS;
        }
 
-       parse_and_run_file(stdin);
+       helper_export_local(argv, (opt_unexport ? -1 : 1), 0);
 
- final_return:
-#if ENABLE_FEATURE_CLEAN_UP
-       if (G.cwd != bb_msg_unknown)
-               free((char*)G.cwd);
-       cur_var = G.top_var->next;
-       while (cur_var) {
-               struct variable *tmp = cur_var;
-               if (!cur_var->max_len)
-                       free(cur_var->varstr);
-               cur_var = cur_var->next;
-               free(tmp);
-       }
-#endif
-       hush_exit(G.last_return_code);
+       return EXIT_SUCCESS;
 }
 
-
-#if ENABLE_LASH
-int lash_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
-int lash_main(int argc, char **argv)
+#if ENABLE_HUSH_LOCAL
+static int FAST_FUNC builtin_local(char **argv)
 {
-       //bb_error_msg("lash is deprecated, please use hush instead");
-       return hush_main(argc, argv);
+       if (G.func_nest_level == 0) {
+               bb_error_msg("%s: not in a function", argv[0]);
+               return EXIT_FAILURE; /* bash compat */
+       }
+       helper_export_local(argv, 0, G.func_nest_level);
+       return EXIT_SUCCESS;
 }
 #endif
 
-
-/*
- * Built-ins
- */
-static int builtin_trap(char **argv)
+static int FAST_FUNC builtin_trap(char **argv)
 {
-       int i;
        int sig;
        char *new_cmd;
 
        if (!G.traps)
                G.traps = xzalloc(sizeof(G.traps[0]) * NSIG);
 
-       if (!argv[1]) {
-               /* No args: print all trapped.  This isn't 100% correct as we should
-                * be escaping the cmd so that it can be pasted back in ...
-                */
-               for (i = 0; i < NSIG; ++i)
-                       if (G.traps[i])
-                               printf("trap -- '%s' %s\n", G.traps[i], get_signame(i));
+       argv++;
+       if (!*argv) {
+               int i;
+               /* No args: print all trapped */
+               for (i = 0; i < NSIG; ++i) {
+                       if (G.traps[i]) {
+                               printf("trap -- ");
+                               print_escaped(G.traps[i]);
+                               /* note: bash adds "SIG", but only if invoked
+                                * as "bash". If called as "sh", or if set -o posix,
+                                * then it prints short signal names.
+                                * We are printing short names: */
+                               printf(" %s\n", get_signame(i));
+                       }
+               }
+               /*fflush_all(); - done after each builtin anyway */
                return EXIT_SUCCESS;
        }
 
        new_cmd = NULL;
-       i = 0;
-       /* if first arg is decimal: reset all specified */
-       sig = bb_strtou(*++argv, NULL, 10);
+       /* If first arg is a number: reset all specified signals */
+       sig = bb_strtou(*argv, NULL, 10);
        if (errno == 0) {
                int ret;
set_all:
process_sig_list:
                ret = EXIT_SUCCESS;
                while (*argv) {
                        sig = get_signum(*argv++);
                        if (sig < 0 || sig >= NSIG) {
                                ret = EXIT_FAILURE;
-                               /* mimic bash message exactly */
-                               bb_perror_msg("trap: %s: invalid signal specification", argv[i]);
+                               /* Mimic bash message exactly */
+                               bb_perror_msg("trap: %s: invalid signal specification", argv[-1]);
                                continue;
                        }
 
                        free(G.traps[sig]);
                        G.traps[sig] = xstrdup(new_cmd);
 
-                       debug_printf("trap: setting SIG%s (%i) to '%s'",
+                       debug_printf("trap: setting SIG%s (%i) to '%s'\n",
                                get_signame(sig), sig, G.traps[sig]);
 
                        /* There is no signal for 0 (EXIT) */
@@ -5378,167 +7606,86 @@ static int builtin_trap(char **argv)
                        if (new_cmd) {
                                sigaddset(&G.blocked_set, sig);
                        } else {
-                               /* there was a trap handler, we are removing it
+                               /* There was a trap handler, we are removing it
                                 * (if sig has non-DFL handling,
                                 * we don't need to do anything) */
                                if (sig < 32 && (G.non_DFL_mask & (1 << sig)))
                                        continue;
                                sigdelset(&G.blocked_set, sig);
                        }
-                       sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
                }
+               sigprocmask(SIG_SETMASK, &G.blocked_set, NULL);
                return ret;
        }
 
-       /* first arg is "-": reset all specified to default */
-       /* first arg is "": ignore all specified */
-       /* everything else: execute first arg upon signal */
-       if (!argv[1]) {
+       if (!argv[1]) { /* no second arg */
                bb_error_msg("trap: invalid arguments");
                return EXIT_FAILURE;
        }
-       if (LONE_DASH(*argv))
-               /* nothing! */;
-       else
-               new_cmd = *argv;
-       argv++;
-       goto set_all;
-}
-
-static int builtin_true(char **argv UNUSED_PARAM)
-{
-       return 0;
-}
-
-static int builtin_test(char **argv)
-{
-       int argc = 0;
-       while (*argv) {
-               argc++;
-               argv++;
-       }
-       return test_main(argc, argv - argc);
-}
-
-static int builtin_echo(char **argv)
-{
-       int argc = 0;
-       while (*argv) {
-               argc++;
-               argv++;
-       }
-       return echo_main(argc, argv - argc);
-}
-
-static int builtin_eval(char **argv)
-{
-       int rcode = EXIT_SUCCESS;
-
-       if (argv[1]) {
-               char *str = expand_strvec_to_string(argv + 1);
-               /* bash:
-                * eval "echo Hi; done" ("done" is syntax error):
-                * "echo Hi" will not execute too.
-                */
-               parse_and_run_string(str);
-               free(str);
-               rcode = G.last_return_code;
-       }
-       return rcode;
-}
-
-static int builtin_cd(char **argv)
-{
-       const char *newdir;
-       if (argv[1] == NULL) {
-               /* bash does nothing (exitcode 0) if HOME is ""; if it's unset,
-                * bash says "bash: cd: HOME not set" and does nothing (exitcode 1)
-                */
-               newdir = getenv("HOME") ? : "/";
-       } else
-               newdir = argv[1];
-       if (chdir(newdir)) {
-               printf("cd: %s: %s\n", newdir, strerror(errno));
-               return EXIT_FAILURE;
-       }
-       set_cwd();
-       return EXIT_SUCCESS;
-}
 
-static int builtin_exec(char **argv)
-{
-       if (argv[1] == NULL)
-               return EXIT_SUCCESS; /* bash does this */
-       {
-#if !BB_MMU
-               nommu_save_t dummy;
-#endif
-// FIXME: if exec fails, bash does NOT exit! We do...
-               pseudo_exec_argv(&dummy, argv + 1, 0, NULL);
-               /* never returns */
+       /* First arg is "-": reset all specified to default */
+       /* First arg is "--": skip it, the rest is "handler SIGs..." */
+       /* Everything else: set arg as signal handler
+        * (includes "" case, which ignores signal) */
+       if (argv[0][0] == '-') {
+               if (argv[0][1] == '\0') { /* "-" */
+                       /* new_cmd remains NULL: "reset these sigs" */
+                       goto reset_traps;
+               }
+               if (argv[0][1] == '-' && argv[0][2] == '\0') { /* "--" */
+                       argv++;
+               }
+               /* else: "-something", no special meaning */
        }
+       new_cmd = *argv;
+ reset_traps:
+       argv++;
+       goto process_sig_list;
 }
 
-static int builtin_exit(char **argv)
-{
-// TODO: bash does it ONLY on top-level sh exit (+interacive only?)
-       //puts("exit"); /* bash does it */
-// TODO: warn if we have background jobs: "There are stopped jobs"
-// On second consecutive 'exit', exit anyway.
-       if (argv[1] == NULL)
-               hush_exit(G.last_return_code);
-       /* mimic bash: exit 123abc == exit 255 + error msg */
-       xfunc_error_retval = 255;
-       /* bash: exit -2 == exit 254, no error msg */
-       hush_exit(xatoi(argv[1]) & 0xff);
-}
-
-static int builtin_export(char **argv)
+/* http://www.opengroup.org/onlinepubs/9699919799/utilities/type.html */
+static int FAST_FUNC builtin_type(char **argv)
 {
-       const char *value;
-       char *name = argv[1];
-
-       if (name == NULL) {
-               // TODO:
-               // ash emits: export VAR='VAL'
-               // bash: declare -x VAR="VAL"
-               // (both also escape as needed (quotes, $, etc))
-               char **e = environ;
-               if (e)
-                       while (*e)
-                               puts(*e++);
-               return EXIT_SUCCESS;
-       }
+       int ret = EXIT_SUCCESS;
 
-       value = strchr(name, '=');
-       if (!value) {
-               /* They are exporting something without a =VALUE */
-               struct variable *var;
+       while (*++argv) {
+               const char *type;
+               char *path = NULL;
 
-               var = get_local_var(name);
-               if (var) {
-                       var->flg_export = 1;
-                       debug_printf_env("%s: putenv '%s'\n", __func__, var->varstr);
-                       putenv(var->varstr);
+               if (0) {} /* make conditional compile easier below */
+               /*else if (find_alias(*argv))
+                       type = "an alias";*/
+#if ENABLE_HUSH_FUNCTIONS
+               else if (find_function(*argv))
+                       type = "a function";
+#endif
+               else if (find_builtin(*argv))
+                       type = "a shell builtin";
+               else if ((path = find_in_path(*argv)) != NULL)
+                       type = path;
+               else {
+                       bb_error_msg("type: %s: not found", *argv);
+                       ret = EXIT_FAILURE;
+                       continue;
                }
-               /* bash does not return an error when trying to export
-                * an undefined variable.  Do likewise. */
-               return EXIT_SUCCESS;
+
+               printf("%s is %s\n", *argv, type);
+               free(path);
        }
 
-       set_local_var(xstrdup(name), 1, 0);
-       return EXIT_SUCCESS;
+       return ret;
 }
 
 #if ENABLE_HUSH_JOB
 /* built-in 'fg' and 'bg' handler */
-static int builtin_fg_bg(char **argv)
+static int FAST_FUNC builtin_fg_bg(char **argv)
 {
        int i, jobnum;
        struct pipe *pi;
 
        if (!G_interactive_fd)
                return EXIT_FAILURE;
+
        /* If they gave us no args, assume they want the last backgrounded task */
        if (!argv[1]) {
                for (pi = G.job_list; pi; pi = pi->next) {
@@ -5561,9 +7708,9 @@ static int builtin_fg_bg(char **argv)
        bb_error_msg("%s: %d: no such job", argv[0], jobnum);
        return EXIT_FAILURE;
  found:
-       // TODO: bash prints a string representation
-       // of job being foregrounded (like "sleep 1 | cat")
-       if (argv[0][0] == 'f') {
+       /* TODO: bash prints a string representation
+        * of job being foregrounded (like "sleep 1 | cat") */
+       if (argv[0][0] == 'f' && G_saved_tty_pgrp) {
                /* Put the job into the foreground.  */
                tcsetpgrp(G_interactive_fd, pi->pgrp);
        }
@@ -5594,23 +7741,24 @@ static int builtin_fg_bg(char **argv)
 #endif
 
 #if ENABLE_HUSH_HELP
-static int builtin_help(char **argv UNUSED_PARAM)
+static int FAST_FUNC builtin_help(char **argv UNUSED_PARAM)
 {
        const struct built_in_command *x;
 
-       printf("\n"
+       printf(
                "Built-in commands:\n"
                "------------------\n");
-       for (x = bltins; x != &bltins[ARRAY_SIZE(bltins)]; x++) {
-               printf("%s\t%s\n", x->cmd, x->descr);
+       for (x = bltins1; x != &bltins1[ARRAY_SIZE(bltins1)]; x++) {
+               if (x->b_descr)
+                       printf("%-10s%s\n", x->b_cmd, x->b_descr);
        }
-       printf("\n\n");
+       bb_putchar('\n');
        return EXIT_SUCCESS;
 }
 #endif
 
 #if ENABLE_HUSH_JOB
-static int builtin_jobs(char **argv UNUSED_PARAM)
+static int FAST_FUNC builtin_jobs(char **argv UNUSED_PARAM)
 {
        struct pipe *job;
        const char *status_string;
@@ -5627,19 +7775,79 @@ static int builtin_jobs(char **argv UNUSED_PARAM)
 }
 #endif
 
-static int builtin_pwd(char **argv UNUSED_PARAM)
+#if HUSH_DEBUG
+static int FAST_FUNC builtin_memleak(char **argv UNUSED_PARAM)
+{
+       void *p;
+       unsigned long l;
+
+# ifdef M_TRIM_THRESHOLD
+       /* Optional. Reduces probability of false positives */
+       malloc_trim(0);
+# endif
+       /* Crude attempt to find where "free memory" starts,
+        * sans fragmentation. */
+       p = malloc(240);
+       l = (unsigned long)p;
+       free(p);
+       p = malloc(3400);
+       if (l < (unsigned long)p) l = (unsigned long)p;
+       free(p);
+
+       if (!G.memleak_value)
+               G.memleak_value = l;
+
+       l -= G.memleak_value;
+       if ((long)l < 0)
+               l = 0;
+       l /= 1024;
+       if (l > 127)
+               l = 127;
+
+       /* Exitcode is "how many kilobytes we leaked since 1st call" */
+       return l;
+}
+#endif
+
+static int FAST_FUNC builtin_pwd(char **argv UNUSED_PARAM)
 {
-       puts(set_cwd());
+       puts(get_cwd(0));
        return EXIT_SUCCESS;
 }
 
-static int builtin_read(char **argv)
+static int FAST_FUNC builtin_read(char **argv)
 {
-       char *string;
-       const char *name = argv[1] ? argv[1] : "REPLY";
+       const char *r;
+       char *opt_n = NULL;
+       char *opt_p = NULL;
+       char *opt_t = NULL;
+       char *opt_u = NULL;
+       int read_flags;
+
+       /* "!": do not abort on errors.
+        * Option string must start with "sr" to match BUILTIN_READ_xxx
+        */
+       read_flags = getopt32(argv, "!srn:p:t:u:", &opt_n, &opt_p, &opt_t, &opt_u);
+       if (read_flags == (uint32_t)-1)
+               return EXIT_FAILURE;
+       argv += optind;
+
+       r = shell_builtin_read(set_local_var_from_halves,
+               argv,
+               get_local_var_value("IFS"), /* can be NULL */
+               read_flags,
+               opt_n,
+               opt_p,
+               opt_t,
+               opt_u
+       );
+
+       if ((uintptr_t)r > 1) {
+               bb_error_msg("%s", r);
+               r = (char*)(uintptr_t)1;
+       }
 
-       string = xmalloc_reads(STDIN_FILENO, xasprintf("%s=", name), NULL);
-       return set_local_var(string, 0, 0);
+       return (uintptr_t)r;
 }
 
 /* http://www.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#set
@@ -5663,7 +7871,7 @@ static int builtin_read(char **argv)
  *
  * So far, we only support "set -- [argument...]" and some of the short names.
  */
-static int builtin_set(char **argv)
+static int FAST_FUNC builtin_set(char **argv)
 {
        int n;
        char **pp, **g_argv;
@@ -5681,19 +7889,14 @@ static int builtin_set(char **argv)
                        ++argv;
                        goto set_argv;
                }
-
-               if (arg[0] == '+' || arg[0] == '-') {
-                       for (n = 1; arg[n]; ++n)
-                               if (set_mode(arg[0], arg[n]))
-                                       goto error;
-                       continue;
-               }
-
-               break;
+               if (arg[0] != '+' && arg[0] != '-')
+                       break;
+               for (n = 1; arg[n]; ++n)
+                       if (set_mode(arg[0], arg[n]))
+                               goto error;
        } while ((arg = *++argv) != NULL);
        /* Now argv[0] is 1st argument */
 
-       /* Only reset global_argv if we didn't process anything */
        if (arg == NULL)
                return EXIT_SUCCESS;
  set_argv:
@@ -5727,11 +7930,12 @@ static int builtin_set(char **argv)
        return EXIT_FAILURE;
 }
 
-static int builtin_shift(char **argv)
+static int FAST_FUNC builtin_shift(char **argv)
 {
        int n = 1;
-       if (argv[1]) {
-               n = atoi(argv[1]);
+       argv = skip_dash_dash(argv);
+       if (argv[0]) {
+               n = atoi(argv[0]);
        }
        if (n >= 0 && n < G.global_argc) {
                if (G.global_args_malloced) {
@@ -5747,89 +7951,130 @@ static int builtin_shift(char **argv)
        return EXIT_FAILURE;
 }
 
-static int builtin_source(char **argv)
+static int FAST_FUNC builtin_source(char **argv)
 {
+       char *arg_path, *filename;
        FILE *input;
+       save_arg_t sv;
+#if ENABLE_HUSH_FUNCTIONS
+       smallint sv_flg;
+#endif
 
-       if (argv[1] == NULL)
-               return EXIT_FAILURE;
-
-       /* XXX search through $PATH is missing */
-       input = fopen_for_read(argv[1]);
+       argv = skip_dash_dash(argv);
+       filename = argv[0];
+       if (!filename) {
+               /* bash says: "bash: .: filename argument required" */
+               return 2; /* bash compat */
+       }
+       arg_path = NULL;
+       if (!strchr(filename, '/')) {
+               arg_path = find_in_path(filename);
+               if (arg_path)
+                       filename = arg_path;
+       }
+       input = fopen_or_warn(filename, "r");
+       free(arg_path);
        if (!input) {
-               bb_error_msg("can't open '%s'", argv[1]);
+               /* bb_perror_msg("%s", *argv); - done by fopen_or_warn */
                return EXIT_FAILURE;
        }
        close_on_exec_on(fileno(input));
 
-       /* Now run the file */
-       /* XXX argv and argc are broken; need to save old G.global_argv
-        * (pointer only is OK!) on this stack frame,
-        * set G.global_argv=argv+1, recurse, and restore. */
+#if ENABLE_HUSH_FUNCTIONS
+       sv_flg = G.flag_return_in_progress;
+       /* "we are inside sourced file, ok to use return" */
+       G.flag_return_in_progress = -1;
+#endif
+       save_and_replace_G_args(&sv, argv);
+
        parse_and_run_file(input);
        fclose(input);
-       return G.last_return_code;
+
+       restore_G_args(&sv, argv);
+#if ENABLE_HUSH_FUNCTIONS
+       G.flag_return_in_progress = sv_flg;
+#endif
+
+       return G.last_exitcode;
 }
 
-static int builtin_umask(char **argv)
+static int FAST_FUNC builtin_umask(char **argv)
 {
-       mode_t new_umask;
-       const char *arg = argv[1];
-       if (arg) {
-               new_umask = bb_strtou(arg, NULL, 8);
-               if (errno)
-                       return EXIT_FAILURE;
+       int rc;
+       mode_t mask;
+
+       mask = umask(0);
+       argv = skip_dash_dash(argv);
+       if (argv[0]) {
+               mode_t old_mask = mask;
+
+               mask ^= 0777;
+               rc = bb_parse_mode(argv[0], &mask);
+               mask ^= 0777;
+               if (rc == 0) {
+                       mask = old_mask;
+                       /* bash messages:
+                        * bash: umask: 'q': invalid symbolic mode operator
+                        * bash: umask: 999: octal number out of range
+                        */
+                       bb_error_msg("%s: invalid mode '%s'", "umask", argv[0]);
+               }
        } else {
-               new_umask = umask(0);
-               printf("%.3o\n", (unsigned) new_umask);
+               rc = 1;
+               /* Mimic bash */
+               printf("%04o\n", (unsigned) mask);
+               /* fall through and restore mask which we set to 0 */
        }
-       umask(new_umask);
-       return EXIT_SUCCESS;
+       umask(mask);
+
+       return !rc; /* rc != 0 - success */
 }
 
 /* http://www.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#unset */
-static int builtin_unset(char **argv)
+static int FAST_FUNC builtin_unset(char **argv)
 {
-       size_t i;
        int ret;
-       bool var = true;
-
-       if (!argv[1])
-               return EXIT_SUCCESS;
+       unsigned opts;
 
-       i = 0;
-       if (argv[1][0] == '-') {
-               switch (argv[1][1]) {
-               case 'v': break;
-               case 'f': if (ENABLE_HUSH_FUNCTIONS) { var = false; break; }
-               default:
-                       bb_error_msg("unset: %s: invalid option", argv[1]);
-                       return EXIT_FAILURE;
-               }
-               ++i;
+       /* "!": do not abort on errors */
+       /* "+": stop at 1st non-option */
+       opts = getopt32(argv, "!+vf");
+       if (opts == (unsigned)-1)
+               return EXIT_FAILURE;
+       if (opts == 3) {
+               bb_error_msg("unset: -v and -f are exclusive");
+               return EXIT_FAILURE;
        }
+       argv += optind;
 
        ret = EXIT_SUCCESS;
-       while (argv[++i]) {
-               if (var) {
-                       if (unset_local_var(argv[i]))
+       while (*argv) {
+               if (!(opts & 2)) { /* not -f */
+                       if (unset_local_var(*argv)) {
+                               /* unset <nonexistent_var> doesn't fail.
+                                * Error is when one tries to unset RO var.
+                                * Message was printed by unset_local_var. */
                                ret = EXIT_FAILURE;
+                       }
                }
 #if ENABLE_HUSH_FUNCTIONS
-               else
-                       unset_local_func(argv[i]);
+               else {
+                       unset_func(*argv);
+               }
 #endif
+               argv++;
        }
        return ret;
 }
 
 /* http://www.opengroup.org/onlinepubs/9699919799/utilities/wait.html */
-static int builtin_wait(char **argv)
+static int FAST_FUNC builtin_wait(char **argv)
 {
        int ret = EXIT_SUCCESS;
        int status, sig;
 
-       if (*++argv == NULL) {
+       argv = skip_dash_dash(argv);
+       if (argv[0] == NULL) {
                /* Don't care about wait results */
                /* Note 1: must wait until there are no more children */
                /* Note 2: must be interruptible */
@@ -5893,31 +8138,66 @@ static int builtin_wait(char **argv)
        return ret;
 }
 
+#if ENABLE_HUSH_LOOPS || ENABLE_HUSH_FUNCTIONS
+static unsigned parse_numeric_argv1(char **argv, unsigned def, unsigned def_min)
+{
+       if (argv[1]) {
+               def = bb_strtou(argv[1], NULL, 10);
+               if (errno || def < def_min || argv[2]) {
+                       bb_error_msg("%s: bad arguments", argv[0]);
+                       def = UINT_MAX;
+               }
+       }
+       return def;
+}
+#endif
+
 #if ENABLE_HUSH_LOOPS
-static int builtin_break(char **argv)
+static int FAST_FUNC builtin_break(char **argv)
 {
+       unsigned depth;
        if (G.depth_of_loop == 0) {
                bb_error_msg("%s: only meaningful in a loop", argv[0]);
                return EXIT_SUCCESS; /* bash compat */
        }
        G.flag_break_continue++; /* BC_BREAK = 1 */
-       G.depth_break_continue = 1;
-       if (argv[1]) {
-               G.depth_break_continue = bb_strtou(argv[1], NULL, 10);
-               if (errno || !G.depth_break_continue || argv[2]) {
-                       bb_error_msg("%s: bad arguments", argv[0]);
-                       G.flag_break_continue = BC_BREAK;
-                       G.depth_break_continue = UINT_MAX;
-               }
-       }
-       if (G.depth_of_loop < G.depth_break_continue)
+
+       G.depth_break_continue = depth = parse_numeric_argv1(argv, 1, 1);
+       if (depth == UINT_MAX)
+               G.flag_break_continue = BC_BREAK;
+       if (G.depth_of_loop < depth)
                G.depth_break_continue = G.depth_of_loop;
+
        return EXIT_SUCCESS;
 }
 
-static int builtin_continue(char **argv)
+static int FAST_FUNC builtin_continue(char **argv)
 {
        G.flag_break_continue = 1; /* BC_CONTINUE = 2 = 1+1 */
        return builtin_break(argv);
 }
 #endif
+
+#if ENABLE_HUSH_FUNCTIONS
+static int FAST_FUNC builtin_return(char **argv)
+{
+       int rc;
+
+       if (G.flag_return_in_progress != -1) {
+               bb_error_msg("%s: not in a function or sourced script", argv[0]);
+               return EXIT_FAILURE; /* bash compat */
+       }
+
+       G.flag_return_in_progress = 1;
+
+       /* bash:
+        * out of range: wraps around at 256, does not error out
+        * non-numeric param:
+        * f() { false; return qwe; }; f; echo $?
+        * bash: return: qwe: numeric argument required  <== we do this
+        * 255  <== we also do this
+        */
+       rc = parse_numeric_argv1(argv, G.last_exitcode, 0);
+       return rc;
+}
+#endif