refresh-auth now takes ~/.ssh/authorized_keys as an argument, and
it checks that it wrote it last time before rewriting it.
# WARNING: when these hooks run they will entirely destroy and rewrite
# ~/.ssh/authorized_keys
[hooks]
changegroup.aaaaa_update = hg update -C default > /dev/null
changegroup.refreshauth = ../../admin/hg-admin-tools/refresh-auth ~/.ssh/authorized_keys ./hg-ssh-wrapper