1c0d95badb
Narrow the fix to secret material and stop reverting #45947. The earlier revision added every read-denied name to the write denylist, which re-blocked auth.json and webhook_subscriptions.json and rewrote the test guarding them. #45947 freed those control files deliberately: containment belongs in Docker/remote backends and OS permissions, not an expanding hardcoded denylist. What #45947 kept blocked is secret material, and that list had drifted: auth/google_oauth.json (OAuth token store), the plaintext Bitwarden cache, vault/ (key + ciphertext side by side) and browser-profile/ (copied cookies / Login Data) were writable via write_file / patch. - Write-deny those four; control files stay writable and read-denied. - _WRITE_DENIED_SECRET_DIRS is its own tuple rather than _READ_DENIED_DIRS, so a future read-only convenience deny cannot silently become a write deny. - tests/tools/test_write_deny.py is restored unchanged from main. - New tests pin both halves: secrets denied, control files writable, and write denies stay a subset of read denies. Fixes #110464