test: community strangler — first pipeline contracts, 2:1 deletion, template set master
Phase 4 task 11. community_e2e_test.go (1,787 LOC, 20 sequential subtests) and community_update_e2e_test.go die; their 22 verified behaviors move to named homes: new T1 handler/repo/service tests (update boundary, sort ordering with disambiguating fixtures, write-forward record shape, provisioning handle→DID binding, response envelopes with credential canaries) and two T2 contracts. The ingestion contract self-registers the community's PDS repo so no AppView write ever occurs — proving the consumer's unannounced-repo path through the real container wiring, create/update/delete with Holds. Two strategic findings: sealed-session minting makes authenticated T2 writes impossible today (spec §3.4b amended with the known limitation), and a filed production defect — unverifiable community handles collapse to handle.invalid where a UNIQUE constraint silently drops every subsequent federated community, with pds_url left permanently empty (BridgeTrust denies bridged votes). Two-stream reviewed; 9 fixes. make ci green: 3496 tests, 0 skips. Two of nine serial firehose files retired. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>