Pinning is one rule — strip the key from the branch layer — but the keys
fall into two groups by where they are meant to live: what only the
machine can know, and what belongs in the repository yet must not be
decided per branch. docker.enabled/network moves from the first group to
the second once the committed config carries it.
The KDoc says explicitly that the distinction is documentary, so nobody
looks for two mechanisms in stripPinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>