Follow-up from PR #117. Tighten checkpoint object-shape and timestamp validation only after separately modeling forward-version compatibility. The scenario requires a corrupted or forward-version checkpoint, a stale reused exact browser download ID, and matching file type; it is intentionally outside round six, which is limited to durable per-target proof and run-identity-bound lease release.
Follow-up from PR #117. Tighten checkpoint object-shape and timestamp validation only after separately modeling forward-version compatibility. The scenario requires a corrupted or forward-version checkpoint, a stale reused exact browser download ID, and matching file type; it is intentionally outside round six, which is limited to durable per-target proof and run-identity-bound lease release.