SIGN IN SIGN UP

fix(curl): don't build the stdout string when writing the body to a file (#378)

`curl -o FILE URL` (and `-O`) called `buildOutput()`, which stringifies the
entire response body via `fetchBodyToStdoutString()`, and then immediately
threw the resulting string away — stdout is forced to "" on that path unless
`-v` is given.

For a large download that transient string is the whole payload as a JS string
(UTF-16, so up to ~2x the byte size) held alongside the `Uint8Array` that is
being written to the filesystem. A browser-hosted embedder of just-bash
reproducibly crashed its renderer on a 250 MB download; ~60 MB was fine.

Skip `buildOutput()` entirely when the body goes to a file and we are not
verbose. Behaviour is unchanged:

- `-o`/`-O` without `-v`: stdout was already forced to "", so this is a pure
  allocation win (it keeps today's behaviour of discarding `-i` headers too).
- `-o`/`-O` with `-v`: verbose output is still built as before.
- `--write-out` still overwrites `output` after the file write.
- `-I`/`--head`, `--fail`, redirects and exit codes are untouched.

Signed-off-by: Lars Trieloff <lars@trieloff.net>
Co-authored-by: Claude Code <noreply@anthropic.com>
L
Lars Trieloff committed
a2a5843e4b3526148c7bab04dcd7be8e859e713a
Parent: c9bd93e
Committed by GitHub <noreply@github.com> on 8/30/2026, 11:48:59 AM