SIGN IN SIGN UP

fix(policy): surface unknown policy.yaml keys at default verbosity and in br doctor (GH #515)

Since #302 unknown policy.yaml keys are ignored instead of failing the load,
but the notice was a tracing::warn! that release builds filter out unless -v
is given, so a misspelled close_policy/workflow key silently disabled its rule.

- Print the notice as a warning: line on stderr (stdout stays parseable in
  --json/toon mode), once per distinct unknown-key set per process.
- New doctor check policy.unknown_keys (fm-configs-policy-unknown-keys), emitted
  only when policy.yaml exists; detect-only, never rewrites the file.
- Loads stay non-fatal, keeping the #302 tradeoff.

Tests: doctor unit test, policy_unknown_keys doctor fixture (+ COVERAGE row),
e2e_unknown_policy_key_warns_on_stderr_at_default_verbosity.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
J
Jeff Emanuel committed
e3bc097fb65f4954c536adcbf178e1441d1dea6b
Parent: e8d8475