Run C2 of manual-push mode (BDR-111/BDR-112). The four flows that pushed
on their own, or claimed the branch was on origin, now read the truth
after the fact and hand the user the exact command:
- client-handover-writer: the "Push to origin now?" question and its
push block are gone (the hooks had already pushed in auto-push mode;
push-guard denies it in manual mode). A reusable PUSH STATE READ
(branch, origin probe, `git rev-list --count origin/<br>..<br>`, the
verb only to word the reason) runs after commit-change, at the top of
the deploy pause, after "Deployed" and before each end report. The
branch name is validated against an allowlist before it is placed in
any command or hint (a hostile branch name is otherwise a shell
injection). Pending → the user pushes BEFORE the deploy pause; the
deploy brief says "after your push". `Push:` line in both reports.
- release-candidate STEP 6: two ahead counts + the verb; anything other
than auto with both counts 0 prints one user command
`! git push --atomic origin main develop v<X.Y.Z>` and stops; the tag
gate stays for auto mode; `hold` notes --follow-tags; version regex.
- release-executor: push claims qualified (auto-push mode, best effort).
- tour: mode-agnostic rule; STEP 3 reads one `git -C <project>` fact per
project (suffix-aware branch, --remotes=origin, origin probe) and the
summary row says on origin / local only with the user command.