* fix: scope policy evaluation to the import closure
A policy is now analysed and evaluated together with the policies it
imports (transitively), instead of every policy connected to it by imports
in either direction. Importers and siblings no longer leak into each other:
compiled evaluate() of an imported policy used to run its importers' and
siblings' blocks.
- Evaluation gate analyses the entry's import closure as one unit, so a
child may read fields and reference entities its importer declares when
evaluated through that importer
- compile() reports a policy that is only valid through an importer with
kind "policyImportOnly" instead of failing it as a plain "policy"; errors
are computed once per key
- Scope diagnostics (duplicate writers, input overrides, data model and
dictionary collisions, cycles) are reported for the whole closure, and
conflicts introduced by combining imports are reported on the importer
- Single-entity scope checks run per import closure instead of workspace-wide
* fix: unknown import relationship targets and renames across imports
- An unresolved relationship/reference target inside an imported policy now
blocks the importer's evaluation and compile(), as on master; the check was
still limited to the policy being analysed, so the importer compiled and
the broken child was reported as "policyImportOnly"
- Rename and find-references analyse each policy's expressions in every
importer's context too, so reads of a field declared by an importer are
found in the imported policy again