a7b25b3c00
reapOrphans() treats any recorded backend with a matching process identity as orphan-reapable — including a backend owned by another live instance. The ownership file is shared across instances, so a second launch that reaches reap (even without the lock) SIGTERMs the running instance's backend. Claims now record the spawning Electron (parentPid + parentStartMarker, the same values already passed to the backend as HERMES_PARENT_PID / HERMES_PARENT_START_MARKER), and reapOrphans() skips any entry whose parent is still running. Even a second instance that wins a stale lock can never kill a live instance's backend. Legacy entries without parent data keep the old behaviour. Known tradeoff: a parent-liveness probe failure preserves the record, so a genuinely orphaned backend under a still-running parent is leaked until it dies naturally. That is preferable to killing a live instance's backend. Tests: parent-aware reap in backend-ownership.test.ts (live parent preserved, dead parent still reaped, probe failure preserved, parent identity round-trips through claim/parse).