96c406b968
Finding 1 (LeadLauncher): closing a labelled tab on a single agent.list miss could destroy a live lead's session — the ticket's own evidence showed that exact signal missing a genuinely running agent. A dead reading now only flags the tab (PendingCloseMarker); it is closed only if a later, independently-connected reconcile still finds it dead while flagged. A tab found live again has its flag cleared instead. Finding 2 (LeadTabScanner): the new agent.list cross-check in scan() was not covered by get()'s "keep the cache on a failed scan" contract, which only fires on a thrown HerdrException. A successful-but-short agent.list could silently drop a lead CallerResolver had already resolved, demoting it to Role.WORKER. A terminal already reported live now gets one grace scan before being dropped; a terminal never reported live gets none, so the original #359 exclusion is unaffected. Both mechanisms were mutation-tested: reverting either change turns exactly its own new tests red and nothing else.