hold every laptop-to-server write behind one .sync-off file master
Three scripts write to the server — bootstrap.sh, laptop/sync-config.sh and laptop/push-project.sh — and all three overwrite rather than merge, so all three can land on work that exists only in the copy they replace. check_sync_hold() in lib/common.sh refuses all of them while .sync-off exists at the repository root, printing that file's first five lines as the reason. Checked in one function rather than three times, so the hold cannot be lifted halfway. A file rather than a variable in local.conf: load_laptop_conf() sources local.conf after the environment is set, so a command-line FLIT_SYNC_OFF=0 would be overwritten silently and the hold would read as lifted while still in force. A file also carries its own reason, which is what is needed when it is hit weeks later. No override flag. push-project.sh --force already overrides the dirty-tree check, and this exists for the case that check cannot see, so a flag here would defeat it. Deleting the file lifts the hold. SYNC_HOLD_FILE names the file rather than hard-coding it so that lib/common.test.sh can invoke the three scripts for real without the suite's result depending on whether syncing is currently held off. It is a seam for that, not a bypass.