Refuse source refs that collide with side outputs
Commit

writeRefs lands the source ref set on the target, then writeOriginNotes and signBranchTips publish their own refs on top. A source repo that already advertised refs/notes/sha1-origin (under --all-refs) or any refs/tags/converted/* (always, since tags are mandatory) would have those refs silently clobbered.
Add checkSideOutputCollision: run after planner.BuildDesiredRefs and before any object work, refusing with an actionable message that names the offending ref(s) and points at --no-origin-notes / --exclude-ref-prefix / dropping --sign as escapes.
Also tighten --check to skip only the side-output refs we actually wrote: pass the {origin notes, signed tags} set into runChecks instead of pattern-matching by prefix, so a legitimate source ref that happened to share a namespace is not silently hidden from the resolved/expected fraction.
Entire-Checkpoint: 250149a84f90