3ae40083f1
Plan for the second hardening wave. Six findings closed in one PR: W2-1 router rejects forced non-local under local-only; W2-2 persist store consults IncognitoMode + 0o600/0o700 perms; W2-3 TUI seeds incognito from firewall; W2-4 quality/outcome gates read firewall instead of CLI flag; W2-5 session perms 0o600; W2-6 remove dead IncognitoMode.LocalOnly field.