fix(backup): degrade offload summaries on skipped ledger records
A malformed/truncated offload-ledger line was counted as skipped_records but did not mark a summary degraded, so a corrupted ledger could present a clean zero to teardown/restore surfaces. Degrade at segment/day/journal levels on skipped_records > 0, propagate into segments nested under a degraded day, give ledger_degraded its own restore guidance, route the offload_restore operation banner through the offload-restore reason map (never the recovery-key error_intro), swap five owner-copy `recordings` strings, and strengthen the copy lint to a noun-form surveillance guard.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>