6f968d59a4
Six review findings, from the peer lead `vms` and a reviewer worker. The first one is a real defect that would have shipped as a dead control. 1. The scrub only ran in a login shell. It lived in the generated `.zlogin`, and zsh reads `.zlogin` only for a login shell. herdr does not open the same kind of shell everywhere: measured on herdr 0.8.0, a macOS pane runs `-zsh` (login) while a Linux pane runs a plain `/usr/bin/zsh`. So on the vhost this was being built for, `.zlogin` never ran and every member kept the whole secret store, in silence. The scrub body now lives in a generated `scrub.zsh` that BOTH `.zshrc` and `.zlogin` source, each after sourcing its own `$HOME` counterpart. Linux runs the first, macOS runs both, and the second pass is not merely harmless -- it re-scrubs anything the operator's `~/.zlogin` exported after `~/.zshrc` had finished. Re-running is idempotent. 2. `INFRASTRUCTURE_PASSTHROUGH` listed names that are not infrastructure: ANTHROPIC_AUTH_TOKEN, GITEA_TOKEN, GITEA_HOST, ANTHROPIC_BASE_URL, ANTHROPIC_MODEL, CLAUDE_CONFIG_DIR, OPENCODE_CONFIG, BRIDGED_MEMBER. I read each injection point and confirmed every one of them reaches `launch.env()` only when actually injected, so `allowed.addAll(launch.env().keySet())` already covers the legitimate case. As static entries they were pure leak surface: a host that happened to export ANTHROPIC_AUTH_TOKEN would have had it passed straight through. 3. A missing `scrub-report.txt` at teardown was logged at debug. The report is the only evidence the scrub ran at all. Its absence has an innocent reading and a serious one, and we cannot tell them apart from the daemon -- so it is now a WARN that says exactly that. Logging it at debug is how a control that quietly stopped working stays unnoticed. 4. Nothing tested that the control was wired in. Deleting the single `applyEnvironmentAllowListPolicy(cfg, launch)` line left all 896 tests green while turning the feature completely off -- the CB-586/CB-611 shape again. `HerdrPeerLauncherAllowListWiringTest` starts a real spawn and asserts on the env that reached herdr. Mutation-checked: unwiring that line fails it. 5. `EnvAllowListScrubTest` now also runs `zsh -i` with no `-l`, which is the Linux pane shape, so finding 1 is tested from a Mac. Mutation-checked: putting the scrub back in `.zlogin` alone fails that test alone, while the login-shell test still passes -- which is exactly the blind spot that let the bug through. 6. Two ZDOTDIR leaks closed. A failed spawn has no pane id, so its directory was never keyed for teardown; it is now removed on the way out. And `deleteOnExit` covers a clean shutdown and nothing else, so `generate` now reaps sibling directories older than 24h left by a killed daemon. Also: `policy:` is lowercased with Locale.ROOT, and the `.zlogin`-only claim is corrected in fleetd.example.yaml, FleetConfig and HerdrPeerLauncher. 901 tests, 0 failures, `mvn clean install` green.