acaafcc6bb
- claim_job_for_fire returns the atomically claimed snapshot with a unique fire owner; heartbeat_fire_claim renews the lease; mark_job_run fences terminal writes by expected_fire_owner so a stale worker cannot record over a replacement claim. - run_one_job heartbeats the fire claim and forwards a combined cancel event (ownership loss OR external cancel) into run_job; the agent path is interrupted cooperatively and script-based jobs (no_agent + pre-run scripts) are hard-stopped with a process-tree kill (POSIX killpg SIGTERM then SIGKILL for surviving group members; Windows taskkill /T /F), with a bounded pipe drain so a SIGTERM-ignoring descendant cannot wedge the worker on communicate() EOF. - Shutdown interruption is scoped to the exact execution token instead of the bare job ID, so a replacement run of the same job never consumes a stale interrupted flag. - fire_claim_fence serializes save/deliver side effects per profile+job with a cross-process flock; remove_job prunes the fence-lock entry. - Preserves upstream BaseException terminal recording (#73973), completed one-shot retention (#80624), blocked_config preflight (T1-26), and the advance_next_runs batch on top of current main.