4734d4a132
localapi.DiskInfo gains durable_id (from StorageTarget.DurableID, "uuid:<fs-uuid>" for usb/local-dir). The de-privileged controller can't read a device's fs UUID but assign mounts strictly by UUID — this read-only field is the only way it learns the assign key. No new privilege, no gate change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>