* fix(crabbox): verify witness objects without ref-database hygiene
Staging recovery rejected intact witness repositories whenever Git 2.50+
fsck's reference-database check found unrelated files such as Finder
.DS_Store under .git/refs, and large stores exceeded the fixed 120 s
budget; both surfaced as "could not verify local objects".
Pass --no-references on Git 2.50+ (older Git never checks refs for
explicit objects), classify fsck exit bits and spawn timeouts into
distinct reasons, and derive the verification budget from measured
object-storage allocation (120 s + 30 s/GiB, capped at 30 min) with a
fresh base budget for revalidation. Missing or unconnected objects still
fail closed.
* fix(crabbox): keep automatic staging recovery on the base witness budget
Automatic recovery runs before a successful wrapper command exits, so it
keeps the 120 s witness bound; only explicit `staging recover` uses the
measured object-storage budget. A test pins both paths.
* fix(crabbox): keep automatic witness rechecks inside the original bound