8804e78354
Builds on @mrsucesso's durable-marker recovery (previous commit): - GET /api/hermes/update/receipt — the full durable receipt (steps, skips, gateway restart outcome, fleet matrix) + compact summary; the authoritative update-outcome record (written by every run since #91283, including refused/failed). - /api/actions/hermes-update/status now attaches the receipt summary, and when BOTH the in-memory registries and the update.log marker are gone (dashboard restarted + log rotated — the #81193 state), a finished receipt reports the outcome: success→0, partial→1. A still-running receipt proves nothing (clients keep polling). - Desktop (updates.ts): the apply poll reads the attached receipt — a finished receipt whose run started at/after this apply is authoritative, replacing timeout-based failure inference across the update's restart gap ('Backend update failed' on successful updates, #81193; 'boot failed' during update restarts, #87359). Live-verified: real uvicorn server + real UpdateReceipt writer (the exact code hermes update runs) over real HTTP — receipt endpoint 200 with summary; #81193 state (no registries, no marker) reports success from the receipt alone; partial receipt with a DOWN fleet row maps to exit 1 (no false success).