The Desktop-spawned hand-off consistently died during Electron's quit
teardown on macOS: the orchestrator process group was terminated right
after `running: hermes update ...`, so no exit code, result file, bundle
swap, or relaunch ever happened, and the loopback shim window surfaced
the death as ERR_CONNECTION_REFUSED or "Aw, Snap!" error code 15
(reproductions in #66753).
- Re-exec the orchestrator through a one-shot setsid child and let the
direct Electron child exit immediately; the real orchestrator is owned
by launchd (PPID 1), outside Electron's teardown, same marker/result
protocol.
- Hold TERM ignored across the `hermes update` invocation and
log-and-ignore the single teardown TERM that can still arrive after
the desktop PID dies (durable SIGNAL breadcrumb for diagnosis).
- Delay start_ui until the desktop PID is gone plus 1s so the shim
server/window are never born inside the teardown window.
- Run both UI processes in their own sessions; keep SIGTERM/SIGHUP
ignored in the shim server and stop it with SIGKILL, so a stray TERM
can no longer leave the progress window on a dead loopback URL while
the update continues.
Verified on a production git install (macOS arm64, Darwin 27.0,
v0.20.1): six consecutive Desktop-triggered/production-shape updates
completed end-to-end including a full desktop rebuild + codesign; the
shim survived a deliberately injected TERM+HUP mid-update and a full
`hermes desktop --force-build --build-only` running alongside it.
Fixes the macOS reproductions in #66753.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>