Closes the read-privacy gap flagged in plan R1/R5. Rather than fork the
FUSE uid/gid Acl model (whose identity is POSIX uid, incompatible with the
daemon's name-based HELLO identity), read-gating is done owner/grant-native:
- commands.rs: new admit_read(coord) mirroring admit_mutate (owner ->
read-grant -> deny; unowned records world-readable). Wired into
(read+execute) and (metadata read), gated by enforce_owner exactly
like writes.
- Tests: read_gate_blocks_non_owner_and_allows_read_grant (bob denied,
allowed after alice grants read), read_gate_requires_identity_under_enforce
(anonymous stat rejected under --require-identity).
- Full ./check quick green: 39 cubesys lib tests, clippy -D warnings clean.
Note in plan: Acl lift (R1) is NOT a literal fork; the daemon reuses the
owner/grant enforcement concept, not the POSIX Acl struct.