9e9e1b2245
Live Windows CI proved copy-while-running is impossible (Chrome opens the cookie DB deny-all). So to make Windows actually WORK — not just fail cleanly — add opt-in auto-close: browser.real_profile_autoclose (default false). When the profile is locked and consent is on, snapshot_real_profile terminates the browser process tree bound to THAT user-data-dir (psutil, identity+binding verified like the daemon reaper — browser binary AND this exact --user-data-dir in cmdline, fail-closed on ambiguity), waits for the lock to release, then snapshots. Destructive (loses unsaved tabs) so it's off by default and the agent asks first; the fail-fast message names the option. No effect on POSIX. - close_browser_holding_profile: graceful terminate → kill → poll until the cookie DB is openable again (bounded); reports relaunch/tray failure clearly. - _processes_holding_profile: identity+binding matcher (never kills an unrelated same-name process on a different dir). - Config key + docs admonition. Tests: autoclose closes-then-snapshots, autoclose-failure-reports, fail-fast names the option, process-matcher identity/binding. 74 real-profile tests pass. Windows live E2E (PROOF workflow, reverted before merge): autoclose-off fails fast <30s; autoclose-on terminates real Chrome, lock releases, valid cookie DB copied.