mirror of
https://github.com/stablyai/orca.git
synced 2026-09-23 00:02:29 +00:00
A failed attach never proves the shell exited. The relay answers not-found for
a pane-identity mismatch and for any id it merely cannot hand back, so treating
it as death sent the pane a synthetic `pty:exit { code: -1 }`, cleared provider
state, deleted ownership and expired the lease — four claims about a process we
know nothing about, on a shell that is usually still running.
Collapse every failure into the non-destructive branch that already existed a
few lines above (`restoreRequired = 'reattachAttemptsExhausted'` + wakeRecovery).
A branch collapse, not a new mechanism: goalpost S3.
Two tests pinned the deleted premise and are INVERTED rather than patched, so
the new intent stays covered:
- ssh-relay-orphan-abandon-paths: "retires the lease without a kill when the
relay proves the PTY is gone" -> "leaves the shell running when the relay only
reports the PTY as not found". Its comment claimed attach verifies liveness
before answering not-found; it does not.
- ssh-relay-session: "invalidates and broadcasts remote PTYs that cannot
reattach" -> "leaves an unreattachable remote PTY alone while its sibling
reattaches".
Also repairs two clauses left red by c51be8072b (step A), which dropped the
expected-identity parameter and the expectedIdentityByPtyId map.
Mutation proof: restoring the destructive block reddens 6 of the 8 oracle
clauses in ssh-relay-reattach-exit-proof.test.ts; the 2 producer pins stay
green. Verified the mutation landed before believing the result.
Net production: -21 lines.
Co-authored-by: Orca <help@stably.ai>