docs: backup system audit, code path findings with questions for measurement
feat(i18n): fail the release on new hard-coded UI text
fix(security-advisor): show the CVE and PHP hints, the scope note and the RFC line in the viewer's language
docs(notes): the demo on stable 2.10.9, with the rendered Security Advisor checked and the worker heal compared
Merge: the backup fixes from the audit — locks, hanging runs, room on disk, panel state
fix(backup): PostgreSQL dumps reach psql through stdin, a key that does not fit an existing repository is named, a failed panel-state run shows as a failure, an unknown database name is reported
fix(backup): the panel state holds roles and the platform's own databases, not the customers' data
docs(notes): measure the backup restore fixes and the panel-state backup on the test box
fix(backup): panel state, node state and the recovery flows work on disk too, and reserve their room first
fix(backup): the lock inspection calls get the same wait bound as the other restic calls
docs(changelog): add the testing pill for v2026.10.07.04
fix(backup): a locked-repository error tells the operator what to do, and a reworded restic retry message is reported instead of silently disabling the stall rule
fix(backup): database dumps go to disk instead of RAM, the room is reserved before the first dump for every target, and a prune keeps a reserve
fix(backup): a run retrying a failing backend is stopped within minutes, the short restic calls are bounded and the agent caps parallel runs
fix(backup): a repository lock is removed only when no process can still hold it