personal memory agent

fix(release): close audit gaps in advisory and proof validation master

validate_install_proof could raise ValueError on a retained proof with a non-integer bytes value instead of returning the standard failure list. That path became reachable for more callers once the semantic pass stopped being gated behind optional bindings, and in the CLI it surfaced through the generic exception renderer with repair: bash scripts/release.sh --candidate, which is actively wrong advice during --recover. It now fails closed with actionable repair text. --recover validated retained policy timestamps with a regex that accepts impossible values such as month 99, so recover could accept policy_run state the live rail could never produce. Retained validation now matches live PolicyRun strength across every policy timestamp field. Advisory freshness failures carried a copy-pasted repair string that told an operator nothing. They now name the real repair, and distinguish a stale fetch from stale content from a clock problem. The liveness gate imported three underscore-private helpers from the advisory rail. With two consumers these are API, so they are public names now, with no aliases left behind. Identity helpers still named their parameter db_root after identity moved to the snapshot. Rename those parameters to match the contract the module docstring states, with no behavior change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>