fix(opf): run one flush worker per repository
Commit

The 5-minute spawn throttle was the only guard between workers, but a worker can run for hours. A later push could start a second worker that repeated the same model calls on the same refs and then lost the ref CAS. The worker now holds a lock in the git common dir for its whole run, and one that cannot take it exits; the running worker re-reads the backlog after each pass.
Also document chunked OPF calls and the single-worker rule.
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3NDQDZ8GBN9B33NP2DYE00N
Checkpoints
Checkpoint 1