1f4cdcbbbb
Two defects in the ceiling work, both found in review. The local backend shared the online ceiling, so with `autoThinkingMaxEffort: max` and a sparse ladder the clamp could snap a `hard` bucket up to `max` — a tier the 3-bucket on-device classifier can never select. The local branch now pins `xhigh`. Applying the ceiling before the Low floor also broke the floor's contract: on `["minimal", "max"]` under an `xhigh` ceiling the intersection hid `max`, the code concluded the model "maxes out below Low", and it fell through to `minimal`. The floor is now resolved against the model's own ladder first and the ceiling filters that pool, so an excluded top tier yields no level instead of a sub-Low one. Docs and changelog now scope the guarantee to what `auto` resolves: a `thinking.requiresEffort` model whose ladder holds nothing under the ceiling still receives its lowest supported effort from the transport, because it accepts nothing else. The test that claimed to prove billing is renamed to say what it checks. Prompt assertions now cover the `max` criteria and the tie-break exception, not just the label, since the label alone is inert. Drops the duplicated pool-level assertions in favour of the contract-level sparse-ladder case.