check / check (push) Failing after 3s
fetch takes --dest (default .) and writes every file there through the existing symlink and hard-link guards, which now work relative to that directory. A file already there with the listed size and hash is skipped; a leftover temp file is still replaced. Once every file verifies, the manifest is saved as index.mf through the same temp file and rename, so check runs on the result; a manifest that lists index.mf or its temp name at the top of the tree is refused, since saving would replace that file. --require-signature is shared with check and enforced through verifyRequiredSigner. Both refusals come before any file is downloaded or anything is written. Model: opus-5-5