fix(service): _up trusts wait_ready as authoritative; _status is informational master
The readiness primitive (wait_ready) is the contract for service-up readiness on darwin per AC-3 of the solstone-macos installer spec. _up() was calling _status() at the end and returning ITS exit code — but _status() ends with a 10s health_check() callosum-status timeout that fires DURING normal supervisor warmup (convey/cortex/link bring up the callosum bus over ~30-90s post-readiness). This re-introduced the same premature-failure that the readiness primitive was meant to retire. wait_ready returning a valid marker means the supervisor has signaled itself ready; further status probes are noise. Diagnosed during solstone-macos installer cold smoke 2026-05-12: marker file written at +33s, supervisor process alive and healthy, sol setup reported service_up_failed. Trace: wait_ready succeeds -> _status() prints "Service: installed" + "State: running (launchd)" -> health_check() times out at 10s -> _status returns 1 -> _up returns 1 -> setup emits service_up_failed. After fix: _up returns 0 once wait_ready succeeds; _status() runs for the human-readable Service/State output but does not gate the exit code. Bumps version to 0.3.1 for the solstone-macos installer fix-and-ship cycle. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>