gitconfig template: [gitflow] autopush = @AUTOPUSH@ (exact true/false, the
hooks fail closed on anything else) and a fixed core.hooksPath =
~/.claude/githooks (created by `make link` in claude-config, git expands ~).
install.sh: resolve_autopush at the identity step. A true/false already in
~/.gitconfig wins silently, else DOTFILES_GITFLOW_AUTOPUSH (any other value
aborts before a file is touched), else a prompt that re-asks until the
answer is exactly true or false (Enter = true), else true. render_gitconfig
refuses to write when the mode is not a boolean or @AUTOPUSH@ survives.
Fix: deploy_gitconfig received the repo bashrc template, so every install
wrote `name = @USER@` / `email = @EMAIL@`. It now takes the resolved
identity directly. patsub_replacement is turned off so an `&` in a name is
not expanded on bash >= 5.2.
Git never expands $VARS in its config, so gitconfig carries @USER@ and
@EMAIL@ placeholders that install.sh fills from the deployed bashrc's
USER/EMAIL exports. A differing ~/.gitconfig is kept as
~/.gitconfig.backup-<date>; an identical one is left alone. A repo's
.git/config still overrides it. excludesfile uses ~ (git expands it,
not $HOME).
The rc files now override $USER, so the installer takes the login name
from id -un for dscl and the code-server unit.