- Remove compose-level user: 0:0 override from manifest_compiler.py so the
entrypoint can start as root, fix mount ownership, and drop privileges to
the container user internally.
- Add get_manifest_container_user() helper to resolve the manifest-declared
container user (with uid:gid fallback).
- Pass container user through TerminalSession, TerminalManager, and the
terminal WebSocket handler so docker exec is invoked with --user <user>.
- Update and add unit tests for the manifest compiler and terminal session.
- Record the additional root-user fix in the fix-pi-container-mount-permissions
OpenSpec change/tasks.
Quality gates: pytest tests/unit/ (226 passed), pytest tests/services/test_terminal_manager_multi.py (7 passed), ruff check on changed files (clean), mypy on changed files (clean)