A community based topic aggregation platform built on atproto

feat(posts): rematerializer skips instance-removed legacy posts master

Implements Q-REMAT (user, 2026-09-28: skip). Without it, the one-shot rematerializer would turn an instance-removed legacy post into a fresh accepted postv2 URI with unblocked media. Changes: - Rematerializer requires a posts-local removal-lookup seam (satisfied by posts.Repository.ActiveRemovalsByURIs) and InstanceDID. A post is skipped only when it has an active removal with scope instance and authority InstanceDID; other authorities and scopes do not skip. - The check runs in the census pass before Ledger.Discover and at the top of RematerializeOne before its own Discover, covering the source pass, ledger resume, direct callers and rows reopened by -reopen-fallbacks. A post the census skipped is not retried later in the same run. - A skipped post gets no ledger row or advance, no author repo resolution, blob upload, postv2 write, acceptance, legacy delete or tombstone. It stays legacy and counts in RemainingLegacy, so ScopeComplete and Complete stay false. SkippedRemoved counts distinct URIs once per run. - Scoped runs never report Complete; main.go sends the operator to an unscoped run before PRD_AUTHOR_OWNED_POSTS section 11 step 6. - The removal is rechecked right before WriteAcceptance; a hit leaves the row at postv2_written and names the postv2 in the progress note. - Active removals that do not match (INSTANCE_DID, instance) are counted as UnmatchedRemovals and the census prints a warning, to catch INSTANCE_DID drift. - A removal-lookup error stops the run before mutating the record being checked; progress on earlier records is kept. - DryRunOf copies the new fields and walks the same path. - cmd/rematerialize-posts wires the post repository and cfg.Instance.DID, prints skipped-removed in the census and final verdict, and documents that a removal made after a postv2 was written does not carry to the new URI. - Tests: T0 coverage for P1 removed / P2 migrated in real and dry runs, other-authority and other-scope removals, resumed rows past discovered, reopened fallback rows, and lookup errors on the first and a later record; cmd census output tests. Reviewed with /second-opinion; findings fixed in review round 1. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>