4bc84d0499
A torn renderer bundle (update replaced the app while its files were locked, e.g. antivirus or a still-running instance) loads index.html fine and then dies on the first lazy import — a white screen with only a desktop.log line. A main-frame load failure (missing index.html, blocked file) was likewise log-only. - resolveRendererIndex() already detects torn bundles; the primary window now refuses to load one and shows a visible repair page (error code, missing assets, 'hermes desktop --force-build', Reload) instead of a blank window. - did-fail-load on the main frame now gets bounded auto-reload through the shared rolling reload budget (transient failures self-heal) and, once the budget is exhausted, surfaces the visible error page. ERR_ABORTED and sub-frame failures stay log-only, and helper windows (OAuth/portal) keep their log-only policy (opt-in via reloadOnFailedLoad). Regression tests cover the policy decisions (reload / abort / budget-exhausted surface), budget sharing with render-process-gone, and the error page content + data: URL loading.