c4ed1614eb
Replace the login-shell-name allowlist in `ensurePosixRemote` with a
capability check against a newly probed `transferShell`. The host probe
runs `sh -lc` / `bash -lc` / `zsh -lc` against the remote and records
the first candidate whose printf marker round-trips; `uname -s` from the
same probe also refines the OS classification when the first probe could
not resolve it.
Three compounding problems fixed:
- The host probe parsed only the first stdout line, so login-shell
banners or any startup noise would land ahead of the payload and
classify the host as `shell: "unknown"`. The probe now frames its
payload with a `PI_HOST_PROBE=` marker (see `extractProbePayload`)
and scans both streams for the marker line.
- `shouldRefreshHostInfo` did not treat `{os: "linux", shell: "unknown"}`
as stale, so a single bad classification stuck and kept failing
later `ssh://` operations. It now refreshes any non-Windows cache
entry without a verified `transferShell`.
- The transfer guard refused the host on the self-reported login-shell
name. It now gates on `info.transferShell`, which is the shell OMP
actually verified can run `head`/`cat`/`mv`/`test`/`ls`. The
refusal message names the capability we couldn't confirm.
`HOST_INFO_VERSION` bumped 3 → 4 so existing caches re-probe and pick
up `transferShell`. `parseHostInfo` exported so the cache round-trip
of `transferShell` is testable without touching disk.
Fixes #3719