Run D2 of manual-push mode (BDR-114).
- push-guard sources lib/gitflow.sh once (absolute path) and reads each
candidate dir through gitflow_push_mode; a missing lib denies.
- Dir tokens are extracted as whole shell words: a fully quoted token
(inner apostrophe allowed) is resolved, a backslash-escaped space is
unescaped deterministically, a token mixing quoted and unquoted parts
is refused (fail closed) instead of resolving to its parent.
- A payload jq cannot parse is scanned as raw text with its JSON escapes
folded; a push-looking one gets the static deny through the trap.
- The 20-token cap runs before any per-token classification (a flood of
20 000 tokens is refused in 0.13 s; T58 locks it under 5 s).
- `case "$mode"` has a deny default; missing core tools warn and allow.
- T42 compares the deny list against main (the last release) instead of
HEAD; literal-true, mixed-token, broken-payload, lib-missing and
banner-on-bad-value cases added (98 checks).
- session-start banner reads the mode through the verb and shows
`push : manual (autopush bad)` on an unparseable value.
- tour hints quote "<abs project>".