Validated against exact installed public @poe-platform/safe-bash@0.1.690, source 6256c18, during #769 consumer integration.
Unit protocol-boundary reproduction (not an actual Chromium or hosted outage claim): acquire a private storage origin lease; Target.closeTarget acknowledges success but Target.targetDestroyed has not arrived; the trusted connection reports root Inspector.detached. lease.release() remains pending and its subscription stays registered. The probe fails after a bounded 50ms observation. Current source explains the permanent missing-event case: retirement awaits a resolve-only destroyed promise and ignores control disconnection.
Required fix: make preparation and pending retirement fail explicitly on trusted whole-control disconnection, without claiming a target was destroyed or resolving successful cleanup. Preserve actual target-destruction confirmation, private-session detach behavior, target/session identity, cleanup aggregation and subscription removal. Browser owner cleanup must still delete the owned provider lease. The consumer trusted control must publish its real socket termination so the library can observe the failure; no fake Target.targetDestroyed notifications.
Add fast regression tests for global disconnect before creation/loading, disconnect after close acknowledgement while destruction is pending, and session-scoped detach during healthy native destruction. Existing actual-native/storage behavior remains required. Direct main publication and exact public verification follow the normal producer release route.
Validated against exact installed public @poe-platform/safe-bash@0.1.690, source 6256c18, during #769 consumer integration.
Unit protocol-boundary reproduction (not an actual Chromium or hosted outage claim): acquire a private storage origin lease; Target.closeTarget acknowledges success but Target.targetDestroyed has not arrived; the trusted connection reports root Inspector.detached. lease.release() remains pending and its subscription stays registered. The probe fails after a bounded 50ms observation. Current source explains the permanent missing-event case: retirement awaits a resolve-only destroyed promise and ignores control disconnection.
Required fix: make preparation and pending retirement fail explicitly on trusted whole-control disconnection, without claiming a target was destroyed or resolving successful cleanup. Preserve actual target-destruction confirmation, private-session detach behavior, target/session identity, cleanup aggregation and subscription removal. Browser owner cleanup must still delete the owned provider lease. The consumer trusted control must publish its real socket termination so the library can observe the failure; no fake Target.targetDestroyed notifications.
Add fast regression tests for global disconnect before creation/loading, disconnect after close acknowledgement while destruction is pending, and session-scoped detach during healthy native destruction. Existing actual-native/storage behavior remains required. Direct main publication and exact public verification follow the normal producer release route.