c98ed22e42
The gateway lifecycle guard (cron/lifecycle_guard.py) applied shell-style tokenization and script-reference resolution to non-shell content, with two regressions: #77131 - every .py cron script using pathlib division was hard-blocked: Path.home() / ".hermes" / ".env" tokenizes the bare "/" operator as an executable path, which resolves to the filesystem root; the regular-file check then fails closed as unsafe. Since Python runs under the interpreter, never through a POSIX shell, the shell-script reference walk is a false-positive generator on Python sources. check_gateway_lifecycle now skips the walk for *.py scripts (the direct command regex still scans the full text), and _iter_referenced_shell_scripts skips pure-separator tokens. #76762 - terminal commands invoking a binary by absolute path (e.g. /usr/bin/python3) crashed the guard with ValueError: embedded null byte: the walk read the binary's bytes, decoded them as text, and re-tokenized machine code; the recursion then hit Path.resolve() on a NUL-bearing path while only OSError was caught. _read_referenced_script now skips NUL-containing files (binaries are not referenced shell scripts) and resolve() tolerates ValueError. Shell scripts (.sh/.bash/.zsh) keep the full deep scan; literal lifecycle commands in .py scripts are still blocked by the direct regex. New tests cover all four behaviors.