fix(checkpoint): fail fast on interactive SSH prompt during pre-push
Commit

Checkpoint sync runs inside the user's git push pre-push hook. When the
push remote uses SSH with a passphrase-protected key and no ssh-agent is
running, git's ssh blocks on a passphrase prompt that can't be answered in
the hook, hanging the user's push until the checkpoint push budget expires.
Mark the pre-push context non-interactive and have every checkpoint git
subprocess spawned under it run with GIT_SSH_COMMAND set to ssh -o BatchMode=yes, so ssh fails fast instead of hanging. This covers the whole
pre-push flow (metadata fetch, policy sync, checkpoint push and its recovery
fetch), not just the push, since any of them can trigger the same prompt.
An existing GIT_SSH_COMMAND is preserved and extended rather than replaced, the flag is only added when absent (idempotent), and foreground commands (resume, explain) leave the context interactive so they can still prompt. Checkpoint sync is best-effort, so failing fast is the correct behavior.
Closes #1523
Co-authored-by: Cursor cursoragent@cursor.com