Files
orca/src/preload
Brennan Benson 289685a66c fix(terminal): only skip the quit warning when the work actually survives
Quitting skipped the running-process confirmation unconditionally. That is
correct in exactly one state: with the daemon adapter installed, quit's
killAllPty() is a no-op against it and the shells are the daemon's children,
which it declines to retire while a session is live — observed in production
with a daemon and its PTY shells up 12 days against an app main started that
morning. The bypass was written for that world but was never conditional on
it, so in the degraded states — daemon init threw, the fail-open elapsed, or
DegradedDaemonPtyProvider is installed and spawns fresh sessions in-process —
the same silent quit killed live local processes with no warning and no way
for the user to tell the two apart. Measured in an isolated node-pty probe:
the foreground worker died both on an explicit kill and on a bare parent exit,
while a detached-fork control survived. "There is no kill call" is not
protection.

Main now answers the one fact the renderer cannot see and sends it on
window:close-requested as localPtysSurviveQuit, resolved per request from the
existing daemonOwnsFreshPersistentPtys() — the adapter is installed, swapped
and lost over a run, so a value captured at window creation would be stale. A
quit skips the confirmation only on an explicit yes: a missing getter, a
throwing read, an absent or non-boolean wire field all resolve to "does not
survive" and ask, because an undetermined answer is not a yes.

No fourth reading of "is anything running" — the probe is the one #17044 and
#17077 settled, anyPtyBlocksWindowClose over readPtyProcessInspectionEvidence,
with the whole verdict vocabulary unchanged. Pane selection moves next to it
as collectWindowClosePtyIds. A quit drops panes on a RESOLVED SSH target:
shutdown marks the lease detached rather than terminated and the remote shell
is nohup-detached, so quitting ends nothing there and probing would only make
the quit slower. Only a resolved target — getConnectionIdFromState answers
undefined while the backing repo has not hydrated, and an unresolved host is
not evidence the work survives, so those panes stay in.

Nothing changes for an ordinary window close, which still probes every pane on
its execution host, and nothing changes on a quit with a healthy daemon. No
platform-specific behaviour is added: the gate is the same on all three, and
the win32 minimize-to-tray branch still short-circuits ahead of it. No new
stream opcode; the payload gains one optional-by-absence boolean that older
readers already fall safe on.
2026-08-28 17:52:45 -07:00
..