Parent
Source: handoff-inbox item 20260723-021058-disk-hygiene-0-6-4-consumer-audit (finding F2 ambitious path; relates to F12 — captures most of the declined Windows-execution-lane value at a fraction of the risk).
What to build
New hygiene.py handoff-verify subcommand: takes a snapshot + the approved exact paths, reruns identity/reparse/owner/handle revalidation deterministically, and emits per-path verdicts. The model then deletes only verdict-clear paths in the manual lane — bringing snapshot binding to Windows without adding an engine deletion lane.
Engine work follows existing hygiene.py subcommand/test idioms. Semver bump + CHANGELOG entry.
Acceptance criteria
Blocked by
None — can start immediately (the cheap process-fix issue lands independently).
Parent
Source: handoff-inbox item
20260723-021058-disk-hygiene-0-6-4-consumer-audit(finding F2 ambitious path; relates to F12 — captures most of the declined Windows-execution-lane value at a fraction of the risk).What to build
New
hygiene.py handoff-verifysubcommand: takes a snapshot + the approved exact paths, reruns identity/reparse/owner/handle revalidation deterministically, and emits per-path verdicts. The model then deletes only verdict-clear paths in the manual lane — bringing snapshot binding to Windows without adding an engine deletion lane.Engine work follows existing
hygiene.pysubcommand/test idioms. Semver bump + CHANGELOG entry.Acceptance criteria
handoff-verifyaccepts a snapshot reference + approved path list and re-runs the engine's revalidation checks per pathBlocked by
None — can start immediately (the cheap process-fix issue lands independently).