Extended-stable hardening for Gateway boundaries and recovery
- Sandboxed browser routes, trusted DNS targets, custom browser origins and loopback provider endpoints reject unsafe access paths
- Retained session writes, provider fallbacks, stream progress handling and stdio failures recover without silently ending active work
- Pending channel work, acknowledgements, delivery evidence, Gateway queues and overload handling recover more cleanly across retries and restarts
- SQLite checkpoints, workspace reads, process probes, plugin responses and dependency handling tolerate expected transient host failures