Plugin in-use markers now live in their own folder and cannot escape the plugins directory.
What's wrong with this entry?
The per-process marker that records a linked plugin as in use is now written under a dedicated .in_use-links directory whose resolved path must stay inside the plugins directory.
- Each path component is created and re-resolved against the real filesystem path; if any step resolves outside, the marker is not written and the scan is skipped, with a log naming the offending path.
.in_use-links
Strings lifted out of the shipped bundle, so the claim above can be checked against them.