Third review cycle on the ownership model, every item reproduced against a
fixture before the fix:
- Runtime assets (sections/, templates/, checklist.md, ...) were refreshed
with rm -rf regardless of who owned the directory, so an unclaimed or
weakly-owned directory lost the user's same-named real files. Real assets
are now replaced only in a directory gstack created or strongly owns
(marker, or SKILL.md symlink into gstack), plus the legacy Windows
real-copy shape; elsewhere they are kept and reported. Symlinks are never
content and are always refreshed.
- The prefix-flip cleanup deleted a customized banner-bearing SKILL.md that
the link pass would have backed up. Both cleanups now compare the file
against the source (raw, or with its name: line rewritten to the entry
name, which is how alias and prefixed copies legitimately differ) and
move a differing file to the backup root.
- A failed backup (unwritable root) returned success and the caller linked
over the file anyway. It now fails, and the entry is left untouched and
reported.
- A foreign DIRECTORY symlink whose target had no SKILL.md fell through to
the "unclaimed directory" rule and was replaced by a real directory. A
symlink that does not resolve into gstack is foreign, full stop.
- The alias installers stamped .gstack-owned into pre-existing directories;
they now follow the same created-or-already-marked rule.
- A directory counts as "only links" only when every link resolves into
gstack: a user's own symlink makes it mixed, so their link survives.
- The gstack-tree heuristic requires bin/gstack-relink, not just a VERSION
file, a setup script and a bin/ directory.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>