Document turn-end session state and remove shadow-branch docs
Commit

The architecture, implementation-contract, security and README docs described the shadow branch as working storage, line attribution, the post-todo incremental checkpoints, and content-matched linking of new files. They now describe what the code does:
- turn end records StepCount, FilesTouched and TouchedFileHashes in session state and writes no git objects;
- linking is by name, with the recorded-deletion exception, and carry-forward compares recorded hashes;
- State.HasPendingWork is the pending-work predicate, with the FullyCondensed exclusions the sweep, IsCondensableEndedSession and doctor keep;
- legacy shadow branches are deleted once at session start, and by
entire clean,entire clean --alland uninstall.
The security doc records that older versions' shadow branches held raw code-file snapshots and that deleting them leaves objects until git gc. docs/architecture/attribution.md is removed; the stash and migration scenarios that only existed because of the shadow branch are deleted rather than rewritten, and the commit-hook performance analysis is marked historical.
Verified on this tree: mise run fmt, go build/vet (also GOOS=windows), mise run lint, mise run test (only e2e/agents TestOpenCodeSeedRepoPlantsDeps fails, on a stale local opencode cache), mise run test:integration, mise run test:e2e:canary, and go test ./docs/development.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com Entire-Checkpoint: 01M49BRDVVV32R9K1DS7AB7E98