80aa2b216d
The tenant_id rule was wrong in a way that would have shipped: the plan said reject when strip() is empty, but the design says reject leading and trailing whitespace outright. " t1" survives the weaker rule and then compares unequal to "t1" inside an RLS policy, so a caller who pads the value silently loses rows. Adds the test that guards a promise nothing else was guarding -- same messages and namespace with different meta must still hit the cache. Without it, folding meta into the key passes every other assertion and costs a full cache cold start plus a permanently lower hit rate, which degrades quietly instead of failing. Also pins _record's new parameter positions, splits the backfill-failure setup per backend (ownership check on PG, read-only file on SQLite, and says what SQLite cannot assert), puts the red-green gate on the integration task, and names the two wiki pages.