The previous commit tightened the install-script gate so a PR cannot
add new allowlist entries on its own head branch -- they must already
exist on the base ref. That created a chicken-and-egg problem for the
very PR that introduces studio/frontend/.install-script-allowlist:
base does not have the file yet, so every head entry is "new" and the
gate refuses to land.
Resolve by making the head-only rejection conditional on the base
ref actually having the allowlist file. The workflow signals
"missing on base" by removing the temp file after a failed git show
(previously it was always truncated to empty, which the checker
could not distinguish from an empty-by-intent base). The checker
treats a missing base allowlist path as bootstrap mode and accepts
the head allowlist as-is for that single run. Once the file exists
on base, every subsequent PR is back under the strict head-only
rejection rule.