subprocess.run inside the async handler serialized every request behind the slowest command (found 2026-08-01 when a du wedged the server mid- migration). Run it in the default thread pool via run_in_executor so concurrent calls actually run concurrently. Timeout default 30->60, cap 300->600, schema text matched.