3933bbd0f4
Capping the classifier result before `clampAutoThinkingEffort` was not enough. The clamp seeds `chosen` with `pool[0]`, so a sparse ladder whose tiers all sit above the request snaps upward instead of down: on `thinking.efforts: ["max"]` an `xhigh` request returned `max`, letting the default setting bill the top tier with no opt-in. The same upward snap made `resolveProvisionalAutoLevel` hand back `max`, breaking the invariant its doc comment had just claimed. `clampAutoThinkingEffort` now takes the ceiling and intersects it with the model's supported tiers, returning `undefined` when nothing is eligible so auto leaves the current level alone instead of billing an excluded tier. The classifier passes its configured ceiling and the provisional level passes XHigh.