script/cibuild, script/docker, script/lint and script/test passed the
tag from script/projectname inline to docker build, where a failing
command substitution does not trip set -e. Each now assigns it to `tag`
on its own line first, so the script stops where script/projectname
fails. The comment above it says why; the REPO_POLICIES.md snippets show
the same form.
Model: opus-5-5