694f242a9e
lab-provision-browsercsv.sh + csv-commit-probe.py drive the real `passwords commit --allow-csv` path in the sandbox VM and assert the security-critical, unattended machinery: the new-password CSV is written to a real tmpfs (/dev/shm), in the correct per-browser column layout, carrying the staged strong passwords with the OLD ones absent, then securely shredded once the human confirms — and the user's own export CSV is left untouched. The final re-import into the browser remains a human step (no programmatic import API), so the proof is scoped to staging, not end-to-end browser write. No adapter code changed; only the validation-status DATA in §8. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>