Addresses the PR #100 review round 3.
pmacs.buffer.from_file does not dedup, so two buffers can visit one path.
Ownership was tracked as a path-wide `owned: HashSet<path_hash>`, which
made the duplicate case silently corrupting: both dirty buffers queued a
write to autosave/<same hash>, the later write won on disk, and BOTH were
recorded in `written` --- so the loser skipped future sweeps while its
contents were unrecoverable. The path-wide set also let either buffer's
save/kill retire the other's recovery.
A recovery file must stay keyed by path (a later session knows only
paths, never old BufferIds), so two divergent buffers cannot both be
protected under one key. Ownership is now `owner: path_hash -> BufferId`:
- the first modified buffer to reach a free slot claims it, including
within a single pass (the write loop updates `owner`, so the gather
loop tracks slots queued this pass --- otherwise two duplicates both
queue a write);
- any other buffer on that path is counted `conflicted` and reported
("autosave paused for N buffer(s): another buffer is visiting the same
file"), never silently mis-protected. It records no `written` entry, so
it re-attempts each sweep instead of believing itself saved;
- `discard_buffer` (save/kill) retires ONLY slots this buffer owns, which
now enforces both invariants at once: an unowned slot is unclaimed
crash data (Q#AS12), and a slot owned by another buffer is that
buffer's recovery;
- saving or killing the owner releases the slot; the duplicate claims it
on the next sweep;
- `recover-file` adopting into a buffer makes that buffer the owner --- the
file's contents are now its contents, and the previous owner truthfully
becomes conflicted.
sweep() now returns (written, blocked, conflicted). Its gather phase is
extracted into `gather()` (clippy too-many-lines).
This is honest rather than clever: pmacs cannot protect two divergent
buffers over one file, and now says so instead of pretending.
Tests (autosave_acceptance now 27):
duplicate_buffers_on_one_path_conflict_instead_of_corrupting (owner's
copy on disk; the dup never wins the slot by editing),
a_duplicate_buffers_save_does_not_retire_the_owners_recovery,
killing_the_owner_frees_the_slot_for_the_duplicate.
Gates: fmt + workspace clippy clean; lib 1499; crdt 1670; autosave 27 + 8
units; desktop 11; persistence 5; m7_8 5; GPU 58; git diff --check clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>