9e77d83354
The previous gate compared session.user_peer_id against a fresh _resolve_user_peer_id() call on the same manager. Both values come from the same resolver with the same inputs, so a non-owner triggering a new session in a shared channel passed the check and received the owner's MEMORY.md/USER.md under their peer. The owner is now a config fact: _declared_owner_peer_id() returns the sanitized peerName, and migration runs only when the session's user peer is that peer. Without a declared peerName, migration runs only when no runtime gateway identity is present (the single-operator CLI path). Aliases still work: a platform ID mapped onto peerName resolves to the owner peer before the comparison. Tests now derive each session's user peer from the real resolver instead of hand-picking mismatched ids, so the non-owner test fails against the old gate.