pub(super) async fn repair(
services: &Services,
scan: &Scan,
chains_cleared_this_boot: bool,
) -> Result<Verdict>Expand description
Applies whatever repair the scan cleared, in hazard order.
The cache-clearing lane runs when the deep scan finds dirt or a verdict skips that scan, and is unconditionally safe. The destructive lane runs only when no anomaly impugned the scan. A decline logs its residue and names its reason, so the caller’s stamp records the counters; only an error withholds the stamp.