M11. RendererCrashRecorder held one install-wide `enabled` flag that every window
overwrote with its own profile's switch, so an opted-out window's crash was
written to disk and reported into another profile, and an opted-out window
wiped the opted-in profile's pending crash.
- Consent is kept per webContents id (the IPC sender), with a hash of the
window's focused profile key; set-enabled now carries that key.
- A crash is recorded only when the crashed window's own profile collects;
each pending entry is tagged with the profile hash (file v2: {entries:[{profile,
reason}]}; an untagged v1 file is ignored — whose it was is unknown).
- take() returns only the calling window's profile's reasons; one claim per
profile (the same window may re-claim after its renderer reloaded); ack drops
only the claimed count. Turning a profile off drops only that profile's entries.
- main.ts passes the window's webContents id to recordRendererGone.
Tests: renderer-crash-metrics.test.ts moves to the per-window API (contract
change: every call names its window, set-enabled names the profile); one new
invariant test (opted-out window records nothing, another profile neither
drains nor purges) — the base API cannot express it, so RED is shown by the
reviewer's probe instead.
Probe (review/desktop/jsrun/.../renderer-crash-metrics.probe.test.ts, adapted to
window ids):
before: after opted-out window crash, file exists: true {"v":1,"reasons":["crash"]}
take by window 2: {"reasons":["crash"]}; A crash record after B-window off: false
after: file exists: false; take by window 2: null; A crash record after B-window off: true