mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 00:02:56 +00:00
The observed-exit ledger keyed evidence by id, but pty.revive reuses ids, so an entry did not say which incarnation it described. Admission now clears the id's prior observation and records its owning incarnation, and the node-pty onExit observer records before the disposed guard - a shutdown that stopped waiting is bookkeeping, and the process ending afterwards is still this relay watching it end - but only while that incarnation still owns the id. Ownership outlives the record because the observation can too: an empty pool is not evidence that a late callback still speaks for the id, so a bounded id -> incarnation map answers it after teardown removed the record. Forgetting either map withholds an exit, never invents one. Also drops ptyIdMintEpoch from pty.getCapabilities, restoring the base host exactly: pairing it with pty.listProcesses is the list-absence inference this PR removed from the client, and a host that publishes it hands an older client the second half of it. Renames the probe's doubt status to unverifiable, the execution-boundary vocabulary, and pins FIFO ledger eviction with a read before the overflow.