d736f5d53f
Review finding on #94633: _sanitize_label_value is lossy ('team/workspace' and 'team_workspace' both sanitize to 'team_workspace'; >63-char keys truncate identically), and container reuse is label-keyed — so two teams with DIFFERENT shared keys could silently attach to one running container (filesystem, processes, env) while their host sandboxes stayed separate. Shared-key labels now carry a sha256 digest suffix of the raw key (deterministic across processes; plain profile labels unchanged for backward compat). Docs also state the first-creator-wins rule for image/ mounts on a shared container. Adds adversarial collision tests.