mirror of
https://github.com/stablyai/orca.git
synced 2026-10-04 16:02:08 +00:00
Quitting skipped the running-process confirmation unconditionally. That is correct in exactly one state: with the daemon adapter installed, quit's killAllPty() is a no-op against it and the shells are the daemon's children, which it declines to retire while a session is live — observed in production with a daemon and its PTY shells up 12 days against an app main started that morning. The bypass was written for that world but was never conditional on it, so in the degraded states — daemon init threw, the fail-open elapsed, or DegradedDaemonPtyProvider is installed and spawns fresh sessions in-process — the same silent quit killed live local processes with no warning and no way for the user to tell the two apart. Measured in an isolated node-pty probe: the foreground worker died both on an explicit kill and on a bare parent exit, while a detached-fork control survived. "There is no kill call" is not protection. Main now answers the one fact the renderer cannot see and sends it on window:close-requested as localPtysSurviveQuit, resolved per request from the existing daemonOwnsFreshPersistentPtys() — the adapter is installed, swapped and lost over a run, so a value captured at window creation would be stale. A quit skips the confirmation only on an explicit yes: a missing getter, a throwing read, an absent or non-boolean wire field all resolve to "does not survive" and ask, because an undetermined answer is not a yes. No fourth reading of "is anything running" — the probe is the one #17044 and #17077 settled, anyPtyBlocksWindowClose over readPtyProcessInspectionEvidence, with the whole verdict vocabulary unchanged. Pane selection moves next to it as collectWindowClosePtyIds. A quit drops panes on a RESOLVED SSH target: shutdown marks the lease detached rather than terminated and the remote shell is nohup-detached, so quitting ends nothing there and probing would only make the quit slower. Only a resolved target — getConnectionIdFromState answers undefined while the backing repo has not hydrated, and an unresolved host is not evidence the work survives, so those panes stay in. Nothing changes for an ordinary window close, which still probes every pane on its execution host, and nothing changes on a quit with a healthy daemon. No platform-specific behaviour is added: the gate is the same on all three, and the win32 minimize-to-tray branch still short-circuits ahead of it. No new stream opcode; the payload gains one optional-by-absence boolean that older readers already fall safe on.