The test and format scripts regenerated mfer/mf.pb.go whenever
mfer/mf.proto looked newer by mtime, which a fresh checkout often causes,
so make check could rewrite a committed file and needed protoc. Nothing
regenerates it any more except make generate (script/generate), which
also records the hash of mf.proto in mfer/mf.proto.sha256. A Go test
compares that hash with mf.proto and fails, naming make generate, when
they differ; it needs no protoc. The Makefile's mtime rule for mf.pb.go,
make clean's deletion of it and the Dockerfile's touch workarounds are
removed.
Model: opus-5-5
Adds .prettierrc and .prettierignore, a single script/prettier entrypoint shared by fmt and fmt-check so the two cannot drift, and prettier 3.9.6 pinned by yarn.lock integrity hash.
Markdown formatting is now gated in the authoritative Docker build via a new mdfmt stage, since the golangci-lint image has no node. REPO_POLICIES.md is ignored so local tooling cannot drift it from upstream.
Removes the || true that made the previous prettier invocation unable to fail.