atproto git client

fix(output): exit a knot's refusal as what it is, not as an unclassified 1 master

`Refused` carried the knot's status and its error tag and `classify` read neither, so `pr merge`, `stack merge`, `repo delete-branch` and `api` all exited 1. It reads the tag now, because a knot spells one refusal with three different statuses — `AccessControl` is 401, 403 or 400 depending on the handler — and defers to `from_status` for the tags it does not name. Change-Id: Ib33dd34ab0935ebb8cba00db4758d5ba4537149e


+206 -15
4 changed files