543c85acbf
Session hygiene auto-compression runs inline on the incoming-message path and awaits the summary worker with a progress-aware inactivity budget (hygiene_timeout_seconds) that extends up to hygiene_total_ceiling_seconds (default 600s). A summary model that keeps streaming tokens keeps resetting the inactivity slice, so the wait can stretch toward the ceiling while zero bytes reach the user — chat transports (Telegram ~30s idle-timeout) drop the connection and the turn appears frozen, even though the gateway is healthy. Add hygiene_max_turn_hold_seconds (default 10), a turn-hold budget that caps the wall-clock the incoming message waits on hygiene compression. The wait slice is additionally capped at the remaining budget so the budget is re-evaluated even when the worker keeps the inactivity slice large. On exceeding the budget the gateway abandons the inline wait and proceeds on the uncompressed transcript via the existing timeout path, which revokes the worker's commit admission (CompressionCommitFence) and defers cleanup — so a stale compression finishing later can never overwrite the turns appended after the wait was abandoned. Well under the typical transport idle-timeout, this guarantees the message is answered promptly while the detached compression completes in the background. Configurable via compression.hygiene_max_turn_hold_seconds. Adds a regression test: a worker that streams progress continuously (so the inactivity slice never fires) must be abandoned once it exceeds the turn-hold budget, the turn proceeds uncompressed, and the stale commit is fenced (no session mutation, role alternation intact).