The old backend/.golangci.yml declared version "2" but used v1 schema
keys, so under v2 it never validated and its thresholds were inert: the
linter ran at defaults. Replace it verbatim with the org-standard file,
repin the Dockerfile.backend lint stage from golangci-lint v2.7.2 to
v2.12.2, and assert the config's sha256 as the first step of the backend
lint target so it cannot silently drift again -- a local hash check
against a constant, no network. With the config loading, lll flags one
over-long line; wrap it and the two others named on the issue, moving
each //nolint justification above the code line, and drop a dead
//nolint:wsl (wsl is disabled by the standard config). TODO.md updated.
Model: opus-4-8
Introduce the Go backend (netwatch-server) with an HTTP API that
accepts telemetry reports and persists them as zstd-compressed JSONL
files. Reports are buffered in memory and flushed to disk when the
buffer reaches 10 MiB or every 60 seconds.