Automatically recover from an out-of-memory by respawning a fresh browsing
context (fresh wasm heap) and discarding the dead one — the manual "duplicate
tab, close the OOM'd one" fix, automated and capped at 2 retries so a too-small
machine stops instead of looping.
- recovery/oom-watch.ts: the recover() state machine with the retry counter in
the URL (?oomRetry=N, cap 2). Mode A soft detection — Module.onAbort plus
window error/unhandledrejection matched against an OOM signature, behind an
idempotent latch. Mode B hard-kill detection — a per-tab localStorage
heartbeat sentinel; a stale sentinel on the next load continues the retry
chain (heartbeat keys avoid mistaking a second live tab for a crash). Healthy
session (alive HEALTHY_RESET_MS) resets the chain. Default strategy is
location.replace; window.open+close is behind ?oomStrategy=newtab. Platform
access goes through injectable win/storage seams for testability.
- recovery/MemoryExhaustedDialog.tsx: terminal "out of memory" UI, reusing
0001's BlockingDialog; copy is honest about lost unsaved edits.
- wasm/boot.ts: forward emscripten Module.onAbort to the watcher (optional
BootOptions.onAbort).
- WasmTool: install the watcher, gate boot on its proceed flag (skip when the
chain is already exhausted), and render the terminal dialog.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>