## Why
Guardian review sessions must not gain access to paths that the parent turn is
not allowed to read.
## What changed
- Derive Guardian permissions by intersecting managed parent filesystem rules
with read-only access, preserving denied paths and restricting network access.
- Offer Guardian execution tools only when a managed sandbox can enforce those
rules.
- Include the selected environment IDs in the review-session reuse key so a
session is not reused across different environment sets.
## Testing
Update the Guardian reuse integration test to verify that a review cannot read
a parent-denied file or write a local file while consecutive reviews still
reuse the same session.
GitOrigin-RevId: 20f17a6c379f1eda651e8508459d642a51e4ce94