ff6aacdc78
herdr keeps worker panes alive across a daemon restart by design, and a worker's paneId is held only by its spawner — so a worker whose owning process exited before its DELETE leaks with nothing tracking it (there is no registry; list() only asks herdr). Observed as three idle claude-ollama panes left in the worker space from earlier runs. On boot, WorkerService.reapOrphanWorkers() scans herdr for agents whose name matches our claude-<profile>-<nonce>-<seq> scheme with a nonce other than this process's nameNonce, and tears each down (pane + its now-empty dedicated tab). A current-nonce worker is ours and live (spared); a user's own claude session carries no such name (untouched). Keyed on the nonce so it survives kill -9 and reaps a *previous* daemon's leaks — the actual case shutdown-hook reaping and an in-memory registry both miss. - Agent now projects herdr's 'name' (was dropped) so the reaper can key on it. - isForeignWorker/workerNonce are pure + package-private for unit testing. - FakeHerdr.withAgent seeds named agents into agent.list. - Wired best-effort into Bridged startup before serving. Closes lms/claude-bridge#1