1810cfc8dd
request_review on a running task under a live claim now requires the caller to prove ownership (expected_run_id, the unchanged worker path) or pass an explicit force=True override (CLI --force; dashboard human actions pass force=True) instead of silently clearing claim_lock / worker_pid of a live run. Failures now carry distinct diagnostic reasons via with_reason=True (mirroring request_changes' tuple pattern): live-claim refusal, malformed re-review provenance, unsatisfied parents, unknown task, and CAS miss. Tool/CLI handlers surface the specific reason instead of the generic 'unknown id or not in running/ready'. Regression tests: live-claim refusal + force/worker paths; malformed provenance gets a distinct reason and explicit reviewer= recovers.