25633d357d
On Windows the descendant tree used to reap a cancelled bash run is built from raw th32ParentProcessID links that outlive their recorded parent. A recycled pid matching the harness's stale parent pid could surface omp itself (or an ancestor) as a false descendant, and signal_tree TerminateProcess'd it — killing the session with no cleanup and no session_exit record when a blocking command hit its timeout. Add host_protected_pids() (harness pid plus its resolvable ancestor chain) and skip those pids in signal_tree and terminate_tree. The guard is cross-platform: a no-op on Unix, where the descendant walk is already identity-pinned, and the safety net that keeps a tool timeout from ever taking down the harness on Windows. Fixes #7452