feat(df): add fsx temp-file helper

Adds internal/dependencyfirewall/fsx, a small df-local atomic temp-file helper (unix/windows variants) used to write the end-of-run CI log (.gitlab/df/ci-log.json) with deterministic owner-only permissions. This is a separate, slimmer helper from the shared internal/fsx (which stays in place for dockercredhelper); the df variant always enforces 0o600 on overwrite so a rewritten log can't retain a looser pre-existing mode on a shared CI runner.

Also lands the cilog/summary trims that the plan grouped with the proxy MR: they are moved here because cilog repoints from internal/fsx to the new internal/dependencyfirewall/fsx, so the trim only compiles once this package exists.

Part of the dependency-firewall breakup. Stacked on df-mr-04-proxy.

Testing

  • make build (whole module; internal/fsx still intact for dockercredhelper)
  • go test on fsx/cilog/summary/cisummary/dockercredhelper
  • golangci-lint run on the changed packages (0 issues)

Merge request reports

Loading
Loading