90e916efc9
Salvage hardening on top of the three cherry-picked contributor commits (#91297 gebilaowang404 + AlexMnrs, #96741 burak33bb, #98826 ayushnangia), closing the remaining unverified-PID kill sites as one class (#98814, #89614): - pid_is_hermes: token-boundary 'hermes' match (no more loose substring false-positives), and an explicit start-time expectation is now honored on POSIX too (a mismatched fingerprint is a recycled PID on any platform). - kill_process_tree: drop the guard on our OWN retained Popen child — a retained handle pins the PID, so the check could only false-refuse. - gateway.status.terminate_pid: POSIX force-kills also refuse when a caller-provided expected_start_time no longer matches. - kill_gateway_processes: re-verify the LIVE cmdline at kill time (the scan-time match is a TOCTOU window). - _reap_unsupervised_gateway_orphans: fingerprint orphans at scan time and require a still-matching identity before the delayed SIGKILL escalation. - whatsapp _kill_port_process: never kill a bare netstat/lsof-scanned PID unless the live process is actually a node bridge (was a stranger-kill). - browser daemon reap/close paths: pass the start-time fingerprint into ProcessRegistry._terminate_host_pid (previously unverified), and the session-close path now runs the same daemon identity verification as the orphan reaper. - tests/hermes_cli/test_taskkill_identity_windows_live.py: live Windows probes (real spawned processes, real psutil ancestry) wired into the on-demand windows-latest wine2e lane. Fixes #98814 Fixes #89614