Local package tarballs are generated from the current checkout, but depends caches them alongside downloaded archives in SOURCES_PATH. When checkouts share that directory, a cached local tarball can be newer than another checkout's source files, causing depends to build the wrong sources with a valid checksum and build ID.
Store local package tarballs and their checksum stamps in WORK_PATH/local-sources instead. WORK_PATH is per-checkout by default, so generated snapshots stay with their checkout while downloaded sources remain shareable through SOURCES_PATH. Existing mtime-based invalidation is unchanged.
This also handles contrib/guix/guix-build, which mounts each checkout at /bitcoin. Distinguishing local tarballs by absolute source path cannot isolate those builds when SOURCES_PATH is shared.
Validation: focused checks reproduced the same-path collision with the path-hash approach and verified isolation with this change. Host/container source checksums and build IDs match; archive reuse, refresh after an edit, and downloaded-source paths were also checked. No full Guix build was run.
Addresses #35764.