* Move provider process supervision and stream reading out of Codex
* Preserve teardown behavior with checked mock types after move
* Apply provider launch environment and caller teardown labels
* Give provider child env one owner and gate Codex contract on the shared reader
resolveProviderChildEnv is now the only place that overlays and strips a
provider's environment; the spawn spec and the request-scoped Codex session
both call it. supervisedPosixLaunch only accepts a launch without env fields,
so an override can no longer be silently ignored there. Edits to the shared
stream reader or the env rule now run the real-binary Codex contract job.