read_doc now loads <doc_root>/<slug>.md for the active release (default 'docs', relative to agents/scout) and rejects slugs that aren't plain names. The search index still reads docs/. s3 is s2 with doc_root: docs/v2.
Entire-Checkpoint: 01M4KX3NBN835SRDCEYVFZ7JF0