mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 16:33:27 +00:00
The cross-process foreground hold relied on the `:napplet` host delivering its onPause "false" to release. If that process dies while foreground (a crash, an OS kill) it never sends it, and the broker would hold the main process resumed — Tor/relays/AUTH up — forever. Turn the hold into a renewing lease. A resumed host re-reports foreground on a 30s heartbeat; the broker stamps each launch token's last-seen time and a watchdog reaps any lease older than a 90s TTL, releasing its hold. A live app keeps renewing so it's never wrongly dropped; a dead one stops renewing and is reaped within the TTL, bounding any leak to one window instead of forever. Only the cross-process napplet/nSite path needs this — BrowserHostActivity runs in the main process, so if it dies the hold and every connection die with it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MgMpRcWj6y82LxLiwcuzmN