fix(strategy): make checkpoint_remote authoritative when seeding metadata ref
main·
Commit

Address trail-review findings on how entire enable seeds the local
metadata branch, so a device never seeds STALE checkpoints (issue #1374).
- EnsurePrimaryRef now short-circuits on a configured checkpoint_remote and never consults origin's (possibly stale) primary tracking ref: on a repo migrated from origin-hosted checkpoints to a dedicated checkpoint_remote, the stale origin ref no longer shadows the real remote.
- Replace the literal empty-tree check (isEmptyMetadataBranch) with metadataBranchHasData, which treats an orphan carrying only known init files (vercel.json) as data-free. This lets the re-enable heal fire on vercel-enabled repos whose orphan tip is not literally empty.
- Guard the bootstrap/heal fetch with urlTargetsCheckpointRepo: remote.FetchURL silently falls back to the origin URL in several paths, so verify the resolved URL's owner/repo match the configured checkpoint repo before fetching; a mismatch falls through to the orphan instead of adopting origin's data.
- Heal a data-free orphan by force-setting the local ref to the fetched tip rather than safe-advancing it, which would replay the orphan and leave a stray empty commit.
Tests: TestURLTargetsCheckpointRepo, TestEnsurePrimaryRef_CheckpointRemoteTakesPrecedenceOverOrigin, TestEnsurePrimaryRef_HealsVercelOnlyOrphanFromCheckpointRemote.