d66341ab28
The freshness window (updated_at >= live process create_time - 2s) had a P1 boundary hole: a stale failure written by the PREVIOUS process immediately before a fast restart landed inside the slack and was aggregated; if that platform was then removed, the new process never replaces the entry and NAS stays degraded indefinitely. Replace clock heuristics with persisted writer identity: - write_runtime_status now stamps every platform entry with the writing process's (writer_pid, writer_start_time) — the same PID-reuse fingerprint the liveness checks use, so a recycled PID never masquerades as the original writer. - The aggregation ownership filter requires exact equality between an entry's stamp and the profile's validated live gateway process (get_runtime_status_running_pid + _get_process_start_time). No slack, no timestamps. Legacy entries without a stamp fail closed. - Writer stamps are process recon (same class as the auth-gated gateway_pid) and are stripped from all /api/status projections, both active-profile and merged cross-profile entries. Near-boundary regression test: prior-process entry stamped 100ms before restart is excluded; recycled-pid-different-fingerprint excluded; legacy no-stamp excluded; current-process entry kept.