managed_health(
*,
refresh: bool = False,
) -> ManagedHealthReturn both halves of exit 78 for one managed snapshot.
Reading health and violations as two calls is a live bug, not a style
choice. get_managed_snapshot declines to cache a candidate it cannot
enforce, so a refreshed status describes the file on disk while a second,
non-refreshed violation read still sees the last enforceable snapshot and
reports none. Every diagnostic surface then shows ok for the exact file
that just refused to launch. One snapshot, both answers.