SIGN IN SIGN UP

fix: [ENG-2883] address PR #690 review — surface warnings in MCP envelope, race-guard stat calls

Two real issues from review:

- MCP curate path was dropping warnings. CurateHtmlDirectResult gained
  an optional `warnings?: readonly string[]` field and renderEnvelope
  now appends ⚠ lines under the ✓ confirmation when present, matching
  the CLI text-mode + JSON envelope behavior.
- The warner used existsSync + statSync, which is race-prone — a target
  deleted between the two calls would throw and bubble out of
  writeHtmlTopic, turning a successful curate into a reported failure
  even though the topic is already on disk. Switched to a single
  swallow-on-error statSync helper (safeStatIsFile / safeStatIsDir).
  Both return false on any error, so a transient FS error surfaces the
  ref as "broken" rather than failing the post-write check. Added a
  test that chmods a parent dir to 0 to exercise the EACCES path.

The reviewer's "lower priority" suggestion to also plumb warnings into
the legacy curate-executor.ts in-daemon path is deferred — that surface
is being phased out and the fix would expand CurationStatus shape.

Other reviewer notes filed as follow-ups (not addressed here):
- lstatSync vs statSync for symlink handling (today the comment overstates
  the symlink guarantee; the resolved-path check only validates the input
  string, not the link target)
- case-insensitive FS edge case on macOS/Windows
- skip ambiguity warning when ref carries an explicit .html suffix
- .md legacy-extension strip for the dwindling MD topics
N
Nguyễn Thuận Phát committed
f6ec3c2a12575c99b2c82429d632bc459ee3bdcf
Parent: 8d5ded0