backup() is a Library method: it refreshes, fetches each pending original
(and optional thumbnails) through the content cache and pools, then rebuilds
the sidecar, symlink, and per-collection JSON views from the model. The
downloadDirectory layout and exit-code contract are unchanged.
An original already on disk is complete and never re-fetched, so runs are
idempotent and resume after interruption. Per-file download and symlink
failures go to a durable failures.json and no longer abort the run
(subsuming #8); a file failing more than one way in a run counts one attempt
and is listed once.
Each run reconciles the ledger against the files it attempted, so a failure
for a since-deleted or out-of-scope file clears instead of failing every
future backup.
Model: opus-4-8