Previously, the AI Vault only blocked resume actions for workspaces with
an active SSH connection (checking `connectionId`). This allowed resume
actions to run on runtime-owned workspaces, which are non-local but do
not use SSH.
To resolve this:
- Introduce `getAiVaultResumeWorkspaceTargetStatus` to classify targets
based on both `connectionId` and `executionHostId`.
- Restrict AI Vault panel actions, session resume checks, and drop layers
to local workspaces.
- Preserve the `executionHostId` on project groups during normalization to
ensure runtime-owned groups retain their execution host status across
persistence reloads.
Uses a new `getEffectiveProjectGroupManualRank` helper to ensure that
drag-and-drop midpoint calculations and sidebar list rendering remain
aligned. When a project's `projectGroupOrder` is unset, it now falls back
consistently to its global repo order instead of defaulting to infinity in
the list but a scaled rank during drag-and-drop.