On a Docker / Hermes Cloud image there is no .git; the code identity is the baked
build stamp (build_info.get_code_identity, source == "build-file"). checkout_contains
walked git merge-base regardless and was therefore always False on an image, which
made _marker_only_restart_obsolete and _live_fleet_covers_receipt disagree with the
fleet matrix: the update catch-up printed "Every running gateway already serves the
checkout code" and "gateways are still off the checkout code" in the same run
(found in the s6 update-tail audit for #120516).
With no history to walk, contained collapses to equal-to-the-stamp (either side may be
the short form an older writer recorded). A source install keeps asking git, so a
carried hotfix past the pulled SHA still counts (#119367).
Red on main / green here: tests/hermes_cli/test_update_fleet_checkout_build_stamp.py