import: match repo paths by identity and fail closed on a bad trust file
Commit

- repoMatches requires absolute paths, so a relative recorded cwd can never be read against Entire's own working directory.
- repoMatches and samePath fall back to comparing directory identity, so a differently-cased spelling of the repo on a case-insensitive filesystem matches instead of being skipped or reported as another workspace.
- A .workspace-trusted file that exists but cannot be read, or names no workspace, now makes the Cursor check refuse rather than pass.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Entire-Checkpoint: 01M47M963D2FFZ7FFDFX3C8XCE
Checkpoints
Checkpoint 1