New learning: docker exec defaults to root, so make targets writing into the ./user bind mount (esp. install-plugins -> gpm) created root-owned files (11,624 accumulated), breaking worktree-rm. Fix: HOST_UID/HOST_GID + `-u` on file-writing execs while the grav container still boots as root. Cross-linked reciprocally with the sibling docker-dev-env upgrade doc. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RDS6t8wcpbwKvvrxykVQ5K