Address review: test-only registration, fwd-compat error, confined reads
Commit

Three reviewer points on the Phase 2 stack:
-
fsstore registration is no longer a public symbol on the production package. The factory, its config, the backend-type name, and registerForTesting moved into register_test.go, so the production fsstore package exposes only the Store — a production binary has no way to register the "fs" backend.
-
The checkpoints loader keeps DisallowUnknownFields (so typos surface instead of being silently dropped), but it is not forward-compatible: a field added by a newer CLI errors in an older one. Documented that adding a field is a coordinated rollout (ship the reader first), and the decode error now tells the user an unrecognized field may mean the file was written by a newer CLI and to confirm they are on the latest version.
-
Settings reads go through an os.Root anchored at the file's parent dir (readConfined) instead of a bare os.ReadFile of an absolute path, so the open cannot be redirected outside that directory by a swapped/symlinked path (TOCTOU). An escaping symlink surfaces as a non-ENOENT error and is handled fail-soft; added a regression test. Note: the rest of the settings package still uses os.ReadFile, so making it consistent is a worthwhile follow-up.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: e9de15786526