Build on PR #511's explicit bindspace and WG lifecycle contracts
without moving declaration policy into actor runtime params.
Deats,
- define exact-name planning and whole-table resource realization;
- separate parsed identity from local interface and netns policy;
- specify owned vs borrowed lifecycles, recursive canonical
declarations and snapshot-before-checkpoint semantics;
- require explicit routes and actionable privilege diagnostics; and
- order the impl through planning, lifecycle, coordinator,
composition and real WG dataplane patches.
(this patch was generated in some part by `opencode` using `gpt-5.6-sol` (`openai`))