f9e481baad
AgentSession defers and coalesces the wire-level agent_end while a prompt is in flight (#emitSessionEvent), so a multi-attempt retry saga often surfaces only ONE agent_end to EventController — which can be the final settle, not an intermediate attempt. Consuming #retryPending against whichever agent_end arrived first (previous commit) could therefore discard the real final failure notification. Switch to gating purely on the retry lifecycle: #retryPending is set by auto_retry_start and cleared only by auto_retry_end (both outcomes), never consumed by sendErrorNotification itself. Those lifecycle events are never deferred, so they reliably bracket the window a retry is actually outstanding regardless of how agent_end coalescing lands. Close the residual gap this creates: #handleRetryableError's classifier-refusal and Fireworks-fallback-ineligible branches could short-circuit a saga that already announced auto_retry_start without ever emitting auto_retry_end, latching #retryPending open forever. Both branches now emit a final auto_retry_end(false) when a prior attempt already started the saga. #handleAgentStart also clears #retryPending defensively so a saga that still somehow never resolves cannot suppress a later, unrelated turn's notification.