Registered repository migration — transaction tooling

The fleet migration now has a tested, resumable transaction boundary. No registered mount is omitted and no repository changes unless it is explicitly selected.

The mount registry feeds snapshot, preflight, staged migration, verification, installation, and ledger evidence.
The registry hash and one content-bearing snapshot anchor every repository row before mutation.

Delivered contract

Verification

GateResult
Focused migration transaction tests5 passed
Affected storage, project-state and MCP tests93 passed
Complete repository suite1,378 passed in 34.65 seconds
Ruff lint and formatclean
Implementation commitf39a4cb

Injected installation failure restored the original Git worktree exactly. The next gate is the real Reckon canary, followed by explicitly authorised repository waves.