* docs: add SSH agent identity implementation plan
* feat(ssh): host-stamped remote foreground identity
* fix(runtime): preserve unfenced inspect call shape
* perf(ssh): traverse foreground descendants linearly
* fix(ssh): bound retired PTY evidence records
* test(ssh): cover retired incarnation retention
* fix(ssh): make remote process inspection total
* Split SSH identity build hot spots
* Fix process table snapshot module split
* test(ssh): update process inspection expectations
* docs: drop the SSH identity plan from the PR
The design doc does not belong in the product repo; it stays out of the
shipped tree while the implementation carries its own comments.
---------
Co-authored-by: Merge Sim <sim@local>
The split silently dropped jira.searchUsers and
runtimeEnvironments.retryControlConnection. Neither failed typecheck: the bridge
modules carried no satisfies annotation and the composed api object was
unannotated, so a missing key was only a runtime TypeError in the renderer.
Annotates each module against PreloadApi, the type window.api is already
declared as, so the contract supplies the shape rather than a parallel copy.
Deleting jira.searchUsers now fails with TS2741 naming the key.
Turning this on surfaced 106 places where a bridge locally annotated
Promise<unknown> or unknown[] over a contract that declares concrete types --
the bridge was erasing types the renderer relied on. Those annotations are gone.
Also exposes app.awaitBeforeUnloadCheckpoint, which was declared and called but
never actually on the bridge, so the lazy-chunk recovery reload optional-chained
to a no-op and navigated without joining the checkpoint. The missing key was
caught by the new annotation rather than by hand.