The envelope signer selected a cached .NET ZIP as DOTNET_ROOT. Its local
cache walker included archive and state files beside the extracted runtime.
The payload signer already filters these entries correctly.
Reuse the payload signer's runtime and dlib resolvers. Remove both duplicate
cache walkers and cover archive/state siblings in the shared resolver tests.
The actual bundle script failed before this change and passed afterward
with the same published packages and real Azure signing. The 4.9 GB bundle
passed native signature verification. All 34 focused tests pass. Remote
publication still needs a release run containing this fix.