2a94ca80e7
Should-fix - _is_genuine_nous_rate_limit: the structured rate_limited verdict counts only on the welcome host; a paid-host 429 keeps main's exhausted-bucket rule. - _nous_welcome_tier: the route-keyed dark-tier 403 applies only to a 403 that matches neither the content-policy nor the billing patterns, so a safety refusal or billing wall on the welcome host keeps its own recovery. - free_tier.provision joins _LONG_HANDLERS (a forced mint + lock waits + re-inventory no longer block the RPC reader). - retry_bootstrap_mint: under the lock, a build that found no identity never overwrites a record that has one (the loop racing the user's click). Simplifications from the review - _raise_for_anon_status is a (status, error) table; retryable derives from ANON_TERMINAL_CODES once (a bare 401 on sign-up now rides the ladder instead of dying for the process). - classify_mint_exception is public and pure; the hand-built failure dict in free_tier.provision is gone (the memo is the one source). - SetupRecord carries the memo payload as one `failure` dict instead of three unpacked fields. - _welcome_surface_kind is a closed table with a "refused" default; _welcome_outage_copy excludes the classifier's `unknown` catch-all. - FREE_TIER_RATE_LIMIT_CHAT is CARD + the sign-in tail, not a slice. - Copy tests assert the contract (model named, tail present/absent) instead of freezing whole sentences. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>