feat(custody): log scoped 401 retry decisions and delivered reports
When the vault records a stale 401 report (applied=0), explaining it needs the consumer's side of the timeline: which version the physical request served, which version the re-authorize returned, whether the request retried, and which version was finally reported. The scoped build logged a retry only at four of the five send sites, never logged the no-retry arm, and never logged a delivered report. decideScopedRetryAfter401 replaces the bare rotation predicate at all five sites (model, model-relay, CacheKeep, Prime, quota/profile) and records each decision at debug. reportFailure records a report the vault accepted, with its served record version and reporter source. Neither line carries credential material.
I
iceteaSA committed
ee0bdb5db57c8de7a072e4f9dfc1d37aebf8b7d5
Parent: a042f75