abc0db8cde
The process-wide 4-worker pool retained the stdlib executor's unbounded queue: four hung summaries wedged every slot, a fifth compression queued silently, waited out its whole budget without starting, and remained eligible to run later as an expensive stale job whose fence was already cancelled (the first fence check used to sit AFTER the summary call). - Bounded admission: submission fails fast (messages returned unchanged, loud warning) when all pool slots are occupied; slots are freed by a future done-callback. Recovery contract documented at the constant: new work fails fast while wedged, wedged workers are fence-cancelled and restore service when they return; a worker that never returns costs its slot — bounded, observable degradation instead of unbounded queueing. - Not-yet-started futures are cancel()ed on timeout. - The cancelled fence is checked BEFORE any expensive summary work, both in the pooled wrapper (stale queued job) and inside compress_context (pre-summary gate), so a stale job never burns an LLM call or acquires session state. Saturation regression: 4 event-blocked summaries wedge the pool, a 5th submission fails fast (asserted while the four are provably still blocked), the refused job never runs after worker recovery, and a fresh submission after recovery succeeds. PR #76354 review, blocking finding 6 / merge gate 7.