Follow-up on the sync block:
- Lines stage2 writes carry a `# stage2-managed` marker (both dotenv tokenizers drop an inline
comment after whitespace). A boot without the variable removes only those lines, so moving an
instance back to production no longer leaves the staging URL pinned in every .env — the mirror
image of the quarantine the sync fixes. Hand-set lines are never touched.
- One `rewrite_env_var FILE NAME [LINE]` does the drop-then-append through the existing inode
(owner/mode kept) and refuses to rewrite when `grep -v` could not READ the file (exit 2) —
the old `|| true` turned a read failure into a wipe of every other secret in that .env.
- Loop per file, names inner: one symlink check and one create per .env instead of three.
- Comment keeps the WHY; tests trimmed to two contracts (land everywhere + parsed by the runtime
tokenizer; container-wins → idempotent → removed-when-unset, symlink refused).
- The unset path drops only marked lines (an operator line beside a managed one survives); the
set path replaces every assignment (the platform is the authority when it sets the value).
- Read-only file: warning, rc 0, file unchanged — pinned in the lifecycle test.