0aa6b44917
Review feedback on this PR: without --no-checkout, the blob fetch runs inside git clone's own checkout step, so when the repo-scoped 429 hits that fetch the whole clone exits non-zero, the else branch removes the directory, and the fallback degrades to one more failed clone under exactly the condition it exists for. - Clone with --no-checkout (commits+trees only — small, passes the throttle); the blobs are then fetched by a separate 'git reset --hard HEAD' the retry can actually wrap. Verified on a local file:// filtering remote: the no-checkout clone materializes nothing and the reset alone produces the full working tree. - Fail closed: both reset attempts failing now removes the checkout and reports 'Failed to clone repository' instead of the previous '|| true' + unconditional clone_ok=true handing the installer a half-materialized tree printed as a success. - The reset runs under a subshell cd so a failed materialization never leaves the shell in a deleted cwd, and the direct-retry loop bound now derives from $max_attempts (seq) instead of a hardcoded 1 2 3 4 that could drift from the reported attempt count.