#111's second stage.
mr diff-comment --pending holds a comment back; mr review publishes
the batch with the verdict and reports how many; mr review --discard
throws away what was never submitted. The web compose box gains "Add to
review" beside "Comment", and a pending thread is drawn dashed with a
line saying only its author can see it.
Three consequences of pending comments being private, each tested:
- They notify nobody when written. The review is the announcement and names its own size — "reviewed !3: request_changes, with 4 comment(s)" — so one notification replaces a trickle of them.
- They do not gate a merge. An unresolved thread blocks merging, and a thread only its author can see is one nobody else could resolve. Counting pending roots would let any reviewer stall a merge request invisibly.
- Discard deletes only pending rows. A published comment is part of the conversation, not something its author can quietly retract.
Ref #111 — range-diff is the last stage and comes next.