Introduces the foundation for isolated task execution (Phase 3a of #12330):
- TaskContext: immutable snapshot of mode, API config, and workspace for
each task, replacing runtime reads from shared ClineProvider state
- TaskPermissions: fine-grained permission boundaries (file patterns,
command restrictions, read-only mode, tool allowlists) that the
orchestrator can attach when spawning subtasks
- TaskContextBuilder: factory functions to build TaskContext from provider
state and to derive child contexts with merged permissions
- Task constructor now accepts optional taskContext, using it for mode
and API config initialization instead of provider.getState()
- delegateParentAndOpenChild builds and passes a TaskContext to child tasks
- Permission merging follows most-restrictive-wins semantics
This is a pure refactor with no behavioral change -- tasks still execute
sequentially, but they now carry their own isolated context. Enforcement
of permission boundaries is deferred to Phase 3b/3d.
Ref: #12330