[backfill] keep a repo queued until the shard has drained its buffer master
the task took the repo off the queue as soon as its records were written and sent BackfillFinished without waiting. a crash before the shard drained, a failed send or a drain error left the commits buffered during the fetch in resync_buffer with nothing queued to apply them, and a live commit landing in that gap was applied directly and then rolled back by the drain. the queue entry now stays until the shard drains and drops it in the same batch, and the task waits for that answer. a failed drain goes through the usual retry, and a shutdown leaves the repo queued for the next start. the shard only drains while the task's key is still the one the repo is queued under, and it also drops that key when metadata names another. the drain applies buffered commits through apply_checked_commit, since handle_commit would buffer them again while the queue entry is there, and RepoProcessResult drops the state nothing reads anymore.