112baae665
Reviewer findings from the formal /simplify-code pass, all verified: 1. Scanner blind spots (HIGH): five more locked pure readers were invisible to the v1 gate — get_compression_fallback_streak and get_compression_ineffective_count hid behind `conn = self._conn` aliasing; list_gateway_sessions, find_session_by_origin and search_sessions hid behind SQL held in variables/f-strings (the scanner required unknown == 0 to flag). All five converted to _read_ctx(); the scanner now (a) tracks self._conn aliases and (b) flags lock blocks with NO proven write instead of silently skipping unprovable SQL. Sabotage self-check extended to pin all three detection classes (literal, alias, variable-SQL) plus a mixed variable-SQL writer that must NOT fire. 2. get_meta reverted to the writer lock: its inline comment (present on main) documents a real read-your-writes dependency — fts_rebuild_step reads rebuild progress that a pooled WAL reader cannot see mid-transaction. The blanket conversion had overridden a documented design decision; it is now the single justified _ALLOWED_LOCKED_READERS entry, replacing the dead _enter_fts_fail_open entry (whose lock block counts 3 writes and never needed allowlisting). Strengthened scanner on pre-conversion main: 43 violations (39 pure-read + 4 no-proven-write). This branch: zero. Suites: gate 2/2; tests/test_hermes_state.py + tests/state/ 331 passed (same 3 pre-existing FTS-rebuild reds as clean main); 433 passed across the 12 consumer suites of the five newly-converted methods (compression anti-thrash, session search, status, scheduler).