cf8b505531
The Desktop-spawned hand-off consistently died during Electron's quit teardown on macOS: the orchestrator process group was terminated right after `running: hermes update ...`, so no exit code, result file, bundle swap, or relaunch ever happened, and the loopback shim window surfaced the death as ERR_CONNECTION_REFUSED or "Aw, Snap!" error code 15 (reproductions in #66753). - Re-exec the orchestrator through a one-shot setsid child and let the direct Electron child exit immediately; the real orchestrator is owned by launchd (PPID 1), outside Electron's teardown, same marker/result protocol. - Hold TERM ignored across the `hermes update` invocation and log-and-ignore the single teardown TERM that can still arrive after the desktop PID dies (durable SIGNAL breadcrumb for diagnosis). - Delay start_ui until the desktop PID is gone plus 1s so the shim server/window are never born inside the teardown window. - Run both UI processes in their own sessions; keep SIGTERM/SIGHUP ignored in the shim server and stop it with SIGKILL, so a stray TERM can no longer leave the progress window on a dead loopback URL while the update continues. Verified on a production git install (macOS arm64, Darwin 27.0, v0.20.1): six consecutive Desktop-triggered/production-shape updates completed end-to-end including a full desktop rebuild + codesign; the shim survived a deliberately injected TERM+HUP mid-update and a full `hermes desktop --force-build --build-only` running alongside it. Fixes the macOS reproductions in #66753. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>