`@source not "./src"` followed by `@source "./src"` scanned nothing:
in the auto/external walker, `@source not` directives were registered as
explicit gitignore layers, but plain directory sources emit no layer at
all, so there was nothing a later directive could win with — the exclusion
applied regardless of order. (A counter-whitelist layer would be wrong
too: it would rank above the `.gitignore` files on disk and bypass them
inside the re-included directory.)
Handle `@source not` in the auto/external walker with a filter closure
instead, mirroring how the pattern walkers already resolve ordering: the
last directive that covers a path wins. When that is a `@source not` the
entry is excluded; when it is a later auto/external source the entry falls
through to the normal gitignore + default rules handling, so re-included
directories keep their regular auto source semantics. Excluded directories
can still be pruned safely, because every auto/external base is its own
walk root and stays reachable even when it is nested inside an excluded
directory.
While moving the exclusion out of the gitignore layers, directory-shaped
directives now also have to exclude their base directory itself (the
normalized `/**/*` pattern only matches the directory's contents), so the
directory is pruned and doesn't widen the generated watch globs.