* fix(ssh): keep an unreadable worktree catalog from authorizing teardown
#14004: the relay's worktree-list fallback caught every failure and returned
`[]`, so `SshGitProvider.listWorktrees` resolved as a success with an empty
list. Downstream reconciliation treats a resolved listing as authoritative,
which reaches `teardownMissingWorktreeTerminalsBestEffort` and the
unregistered-worktree removal paths — a data-loss path from a failed scan.
- relay: the `-z`-unsupported fallback lane propagates its failure instead of
swallowing it to `[]`.
- provider: an empty or malformed `git.listWorktrees` response is refused as
`WorktreeCatalogUnavailableError`. A Git repo always lists its own checkout,
so a zero-row listing can only be a scan that never answered — this is the
mixed-version guard against relays that still swallow.
- `listRepoWorktrees`: an unreachable SSH host reports unavailable instead of
an empty catalog.
#12661: `ssh:terminateSessions` now returns `{ terminated, unverifiable }`, so
an offline sweep that only tore down local transport cannot be mistaken for a
remote kill. The Manage-hosts toast warns instead of claiming success.
* chore(i18n): register the unreachable-terminal terminate message