Pull a fresh checkout's documents

navigator project sync also fills a fresh clone: it downloads each committed pointer's own revision into the staging path it already names, and discovers live documents the checkout has no pointer for. A fresh clone carries pointers but no bytes; sync is what fills them back in without a manual document get per pointer.

The dry run compares each pointer's recorded sha256 against the local file — no login, no network call — and lists what would change:

The real run downloads through the same authenticated API sync uses, verifies the bytes against the pointer's own sha256, and writes them to the staged path. A file whose digest already matches is left alone, so running pull again after a full checkout prints 0 pulled. It hydrates only: a live document the checkout carries no pointer for is sync's lane, not pull's. A pointer the signed-in account cannot read is reported, not silently skipped.

pull is all-or-nothing for document bytes. It first downloads every missing or stale revision into a task-owned temporary staging area, then publishes the staged files only after every pointer is present, authorized, downloaded, and verified against its sha256. If a pointer vanishes, access is denied, a download fails, or a digest mismatches, the command fails without changing any pre-existing target bytes and without creating any newly hydrated target. The documents/.gitignore file may still be created or retained; that file is outside the document-byte guarantee. Correct the failure and rerun pull: a successful run hydrates the complete set, and the next run reports 0 pulled.