2f5abb6a55
Fail-closed governance backend failures are semantically scope-level unavailability, yet GovernanceBackendError sits directly under PolyGatewayError, so callers writing only `except GatewayUnavailableError` drop them into the catch-all bucket and burn their failure budget on a fault that a restart would clear. The design reparents it under GatewayUnavailableError with a new governance_backend_down reason, splits the two "unknown source" sites into a separate assembly-defect error so a misconfiguration still reaches the dead letter queue, and picks a non-zero retry_after_s to avoid a zero-delay retry storm against a backend that is already down.