check / check (push) Waiting to run
fetch takes --dest (default .) and writes every file there through the existing symlink and hard-link guards, which now work relative to that directory. A file already there with the listed size and hash is skipped; a leftover temp file is still replaced. Once every file verifies, the manifest is saved as index.mf through the same temp file and rename, so check runs on the result. --require-signature is shared with check and enforced through verifyRequiredSigner, on a Checker over the manifest held in memory, before anything is downloaded or written. Model: opus-5-5