Code quality plan, MR B: one-line correctness fixes

Phase B of the code quality action plan (https://gitlab.com/postgres-ai/database-lab/-/blob/docs/code-quality-action-plan/docs/plans/20260913-code-quality-assessment-action-plan.md). One MR.

Small, isolated correctness bugs. All confirmed on origin/master 8a42a6ef.

Findings

  • retrieval.go:372: || should be &&; both exemptions are dead, so MakeActive and InitBranching are skipped on errNoJobs / SnapshotExistsError
  • ObservingClone.Stop blocks on <-c.done forever when RunSession exits through the metrics error path
  • postgres.go:122 wraps a nil error on start timeout and reports success
  • auth middleware captures the verification token once (server.go:265); reload swaps config only (#29 (closed))
  • splitFlags panics on --extra-config foo / --tags foo (clone/actions.go:583)
  • POST /observation/start with body null nil-derefs; no recovery middleware on the router

Tasks

  • 5. && plus errors.Is(err, errNoJobs); table-driven test
  • 6. defer close(c.done) in RunSession; Stop(ctx) selects on done and ctx.Done(); caller at routes.go:1163 passes r.Context()
  • 7. Real error on Postgres start timeout with the last recovery state
  • 8. NewAuth takes a token accessor that reads under configMu (closes #29 (closed))
  • 9. splitFlags returns an error; nil request after ReadJSON is a 400; mw.Recover around the router

Dependencies