forked from bchanot/claude
lib/deploy-commit.sh: a rejected `git commit` (pre-commit hook, protected branch, signing failure) now exits 6 (loud stderr, distinct from rc 1's "nothing to do") instead of sharing rc 1 with the no-op cases. Header comment documents the full 0/1/2/3/4/5/6 taxonomy. Closes J4-22 (UNTESTABLE): at client repos, a failed deploy-state commit was indistinguishable BY EXIT CODE from "nothing to do" (rc 1 was shared 3 ways); exit-code-only callers couldn't disambiguate (stderr-parsing callers already could). Caller census (per report's explicit gate): skills/deploy/SKILL.md documents and parses this exit-code contract in TWO places (bootstrap commit + incident-recovery commit). Flagged to the user before committing; confirmed GO to add rc 6 there too (additive — no existing code's meaning changes) so the documented contract stays accurate for live deploy runs. New T10 in lib/tests/deploy-commit.test.sh (+3 assertions, 13→16): rejecting pre-commit hook sandbox — asserts rc 6, empty stdout (no stale hash), HEAD unmoved. GREEN: full `make test` exit 0 (deploy-commit 16/16 incl. T10). shellcheck clean, bash -n clean.