- paskia migrate accepts an rp-id, a legacy *.paskiadb path, or a
current-format *.kantadb path; with an existing target database the
incoming data is merged (uuid-keyed records make conflicts a non-issue,
domains merge per rp-id with a union of origins)
- Migration transactions are labeled migrate:cli:{rp-id} (slash-joined
for multi-domain sources) instead of 'bootstrap'