65fd8cb0e8
The Agent Hub kill path called AgentLifecycleManager.release(), which disposes the session and then unregisters the ref while leaving the on-disk <id>.jsonl intact. On the next hub open, registerPersistedSubagents rescans the transcript tree and its `if (!registry.get(id))` guard cannot distinguish an explicit kill from a normally-parked agent, so it re-adopts the killed id as a fresh `parked` row. Add a `tombstone` option to release() that mirrors finalizeSubagentLifecycle's genuine-kill path: dispose and detach the session but keep the ref registered as terminal `aborted` instead of removing it. The kept-registered id makes the rescan guard skip it, and the transcript stays on disk (still reachable via history://<id>, per #5261). The hub kill button now passes tombstone: true. Fixes #7250