mirror of
https://github.com/stablyai/orca.git
synced 2026-10-06 08:02:28 +00:00
A hosted document is replaced without the shell session, its build or the view epoch moving: a native-route excursion deactivates the view to about:blank and reloads on return, the route error boundary reloads in place, and a re-attached view reloads its URL. The previous page's broker survived all three, and its subscription records kept holding every per-operation grant (one for workspace, account and source control), so the new document's subscribes were refused with rate_limited for the rest of the shell session and the host kept publishing to records nobody read. The shell owns the document lifecycle, so it now observes it: the native views report every document load start (Android through onPageStarted, iOS through didStartProvisionalNavigation, which is the only signal a page-initiated reload gives), and a load that displaces a document that finished loading bumps a page document epoch. The broker hook retires on that epoch exactly as it does on a view-epoch bump, before the incoming document is initialized. A first load and the duplicate load-start events for one navigation are not replacements and do not retire anything. Android also never destroyed its WebView: OnViewDestroys only dropped the registry entry, so every package swap, host switch and route exit leaked a renderer process, a JavaScript context, the message listener and both script handlers. Unmount now destroys it; deactivation still only parks it. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb