- Plan is a pure function (inventory, manifest, disk facts, injected path
mapping) emitting exactly six actions: deploy, update, skip+warn,
leave+warn, remove, keep — deterministic order, no filesystem access
- full 3x3 matrix (disk unmodified/user-modified/never-managed x upstream
added/changed/removed) table-tested plus missing-disk restore cases,
a mixed fixture and a purity/determinism guarantee test
- executor applies plans item by item (atomic deploy/remove per item),
rewrites the manifest once, appends timestamped SKIP/LEAVE lines with
item name and reason to the sync log
- sync now plans before mutating: unmanaged occupants block new deploys,
upstream deletions remove only unmodified copies, local modifications
always win and are warned about