Merge: the backup fixes from the audit — locks, hanging runs, room on disk, panel state
fix(backup): PostgreSQL dumps reach psql through stdin, a key that does not fit an existing repository is named, a failed panel-state run shows as a failure, an unknown database name is reported
fix(backup): the panel state holds roles and the platform's own databases, not the customers' data
fix(backup): panel state, node state and the recovery flows work on disk too, and reserve their room first
fix(backup): the lock inspection calls get the same wait bound as the other restic calls
fix(backup): a locked-repository error tells the operator what to do, and a reworded restic retry message is reported instead of silently disabling the stall rule
fix(backup): database dumps go to disk instead of RAM, the room is reserved before the first dump for every target, and a prune keeps a reserve
fix(backup): a run retrying a failing backend is stopped within minutes, the short restic calls are bounded and the agent caps parallel runs
fix(backup): a repository lock is removed only when no process can still hold it
feat(backup): the panel-state backup is created by itself and the Security Advisor reports its state
docs: say where the password hashes in the panel-state backup actually live
feat(backup): a restore brings back every database dump of the snapshot, restores PostgreSQL, and reports what it could not
docs: the restore note gets its own section on cross-customer dump import
fix(backup): a full restore imports only its own snapshot's database dumps and leaves no dump folders behind
docs: backup system audit, code path findings with questions for measurement
feat(i18n): fail the release on new hard-coded UI text
fix(security-advisor): show the CVE and PHP hints, the scope note and the RFC line in the viewer's language