When multiple releases in a helmfile use the same remote chart, concurrent
helm upgrade/diff calls race on helm's internal repository cache file rename,
causing intermittent 'cannot rename: Access is denied' errors on Windows.
This fix introduces two layers of serialization:
1. withChartOperationLock (operation-level): wraps SyncRelease/DiffRelease
calls with a per-chart+version mutex. Only applies to remote charts
(release.ChartPath is empty); local/pre-fetched/OCI charts bypass the
lock entirely. Different charts remain fully parallel.
2. Per-chart+version download mutex in forcedDownloadChart/getOCIChart
(download-level): uses double-check locking to ensure only one
helm fetch runs per unique chart+version within a process.
The fix does NOT change chart paths passed to helm, preserving backward
compatibility with all existing behavior and tests.
Trade-off: same-chart releases are fully serialized (the entire helm
operation including deployment, not just download). This is unavoidable
without pre-fetching because helm downloads and deploys atomically.
Releases with different charts are unaffected.
Fixes#768
Signed-off-by: yxxhero <aiopsclub@163.com>