The test and format scripts regenerated mfer/mf.pb.go whenever
mfer/mf.proto looked newer by mtime, which a fresh checkout often causes,
so make check could rewrite a committed file and needed protoc. Nothing
regenerates it any more except make generate (script/generate), which
also records the hash of mf.proto in mfer/mf.proto.sha256. A Go test
compares that hash with mf.proto and fails, naming make generate, when
they differ; it needs no protoc. The Makefile's mtime rule for mf.pb.go,
make clean's deletion of it and the Dockerfile's touch workarounds are
removed.
Model: opus-5-5