6e854595e2
Addresses the round-3 findings from @Adolanium + @kshitijk4poor on #95620: 1. Overlay-before-reuse race (blocker): _real_profile_cdp ran snapshot_real_profile BEFORE the session-reuse check, so a cold resolve that ends in reuse rewrote Cookies/Login Data under a live Chromium holding the user-data-dir open (torn DBs, locked txns, phantom logouts). Now: resolve copy dir as a PATH, probe reuse first, return early on a hit; snapshot/overlay only on the relaunch path when no live browser owns the dir. 2. Torn first copy poisoned freshness forever: freshness keyed on isdir(Default), so a half-written copy (disk full / Ctrl+C) was treated as populated and only ever got auth overlays. Now gated on a .hermes-snapshot-complete marker written only after a full copy succeeds; a torn copy is rebuilt from scratch. 3. Consent revocation left copied credentials on disk: turning use_real_profile off now deletes ~/.hermes/browser-profile/ on next browser use (cleanup_real_profile_snapshots), so cookies/logins don't outlive consent. 4. Stale non-active profile copies: only the ACTIVE profile (last_used) is copied into the copy's Default now — other Chrome profiles are never snapshotted (smaller copy, no stale credential dirs lingering). 5. Docs/config/desktop wording aligned to actual behavior (active-profile only, refresh on fresh session, consent-off cleanup). Tests: overlay-skipped-on-reuse + overlay-runs-on-relaunch, done-marker gating + torn-copy rebuild, active-only copy, consent-off cleanup (removes store + idempotent + triggered from _real_profile_cdp). 206 browser + 222 backup/file_safety pass. Live: reuse skips re-snapshot; direct launch on the active-only copy loads the real signed-in Gmail inbox.