feat(backup): spb L2 — keys, repo init, BYO destination + backup config schema master
Second lode of sol private backup (spb). Adds the crypto + config layer on top of L1's vendored restic binary and secret-scrubbed runner: - keys.py: daily key (token_urlsafe) + 64-char Crockford recovery key (secrets.choice per char), 16x4 display form, and parse_recovery_key — the single canonical entry parser (folds I/L->1, O->0; the L4 contract for restore + regeneration) plus a delegating confirm helper. - destination.py: Destination model, credential-free RESTIC_REPOSITORY + s3/b2 backend-env assembly, and a sanitized `restic cat config` probe mapping returncodes to fixed owner-safe reason codes (never leaks restic stderr). - repo.py: idempotent two-key repo init — restic init (daily) then key add (recovery) delivered via an os.pipe FD (never on disk, never on argv); probe-the-repo state machine self-heals partial failures and refuses to overwrite a repo the daily key can't unlock. - state.py: backup config-section accessors via journal_config (0600), per-field default-at-read for existing journals, get-or-create that respects a hand-set key, and a secret-free status_view. - runner.py: minimal pass_fds passthrough (default empty; byte-identical for existing callers) enabling the pipe-FD password delivery. - journal_default.json: pinned `backup` section for fresh journals. Contacts no sol-pbc service. Keys/config only — backup/restore/prune execution, scheduling, UI, and CLI verbs land in later lodes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>