SIGN IN SIGN UP

fix(io): keep a replaced file's permission bits in atomicWriteFile

Why:
- atomicWriteFile writes a temp file and renames it over the destination,
  so the result took the umask default (0644) instead of the original
  mode. Droid creates ~/.factory/hooks.json and Devin ~/.config/devin/
  config.json as 0600; install --droid would have left the user's hooks
  file world-readable (CodeRabbit on #198).

What:
- When the destination exists, the temp file is created with its
  permission bits before the rename. New files keep the default mode.

Validation:
- New atomic-write test (0600 destination stays 0600) failed with 0644,
  then passed.
- bun run check passed (3565 pass, 4 skip, 0 fail).

LOC:
  src/     +2 / -2 = net +0
  tests/  +13 / -0 = net +13
  *.md     +0 / -0 = net +0
  Total   +15 / -2 = net +13

Claude-Session: https://claude.ai/code/session_01F7YRzkEF44ALjx8GDvBXaS
K
kenryu42 committed
a4e763fc56aab699cd4daab58da35decd8197e13
Parent: 99c2dc1