Mint an artifact ingest session for delivering a content-addressed bundle
to one serving device. The returned grant carries the one-time
sessionToken the caller streams the bytes with (no later read returns it).
Optionalopts: RequestOptionsThe content-addressed digests a DEVICE currently holds on disk (ADR-0008
WP4.1). The agent reports its store contents after every delivery and at
startup; the backend keeps them as DEVICE--ARTIFACT--> edges.
This is the per-device idempotency signal. get cannot serve that
purpose: ArtifactsTable is keyed by digest ALONE, so a registration made
by any earlier application or device answers "yes" for a device whose store
is empty — which is how a deploy came to skip delivery to a device that then
failed closed forever (CA-4).
Optionalopts: RequestOptionsRead an ArtifactRecord by digest (presence / idempotency probe). digest is
URL-encoded into the path (sha256: contains a :).
Optionalopts: RequestOptionsPoll an artifact ingest session (the delivery waiter's poll target). The artifact session is an IngestSessionRecord, so it is read through the shared storage-session route; the session token is never returned here.
Optionalopts: RequestOptionsRegister (put-if-absent) the ArtifactRecord for a delivered digest.
Idempotent — the first writer persists {digest, kind, size, source:'ingest', refCount:0}; refCount is driven up later at release cut.
Optionalopts: RequestOptions
sdk.artifacts — mint/poll the artifact ingest session, register the delivered digest, and probe presence (see module doc). Idempotent by digest.