feat: doc — warren's vault+render absorbed onto the git-object read path warren scanned a directory (filepath.WalkDir + os.ReadFile). There is no checkout here, so Scan walks a git tree through gitx instead and feeds the FromPages seam: the approved head, a pinned sha and a proposal branch are one code path with a different revision, and nothing downstream of Archive knows where its pages came from. Frontmatter is core's, not warren's. Front embeds core.Frontmatter and adds only what core deliberately does not model — parent, aliases, planned, and the ordered key list used for display and search text. Two parsers that disagree about a document header is a bug that surfaces in the ID registry months later. Documents key on their frontmatter id, falling back to their path: paths move and ids do not, and a duplicated id resolves to neither document rather than letting one win silently, matching what the merge already does with the approved branch. A header core rejects degrades to "no frontmatter" instead of failing, because --push-option=skip-validation means such a document can exist and refusing to render it would turn a typo into an outage.