snapshot_download's resume trusts an existing file by size, so a present-but- corrupt blob is never re-fetched: the resume-repair 'succeeds' yet the reload still raises the truncated-cache OSError, and the user was sent to a manual delete-and-reinstall. Add a force=True path (force_download) and wire it as a last resort — on the post-resume reload failure, force a full re-download once (replacing corrupt blobs) and retry the load before falling back to the actionable message. Force is reached only after a plain resume-repair didn't fix it, so the common missing-file case still avoids re-downloading everything. Tests: corrupt cache force-repairs on the 2nd failure (resume then force), force_download is set only when force=True, and an unfixable cache still surfaces the 'could not be auto-repaired' message. Co-authored-by: mergetest <test@local> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>