bootstrap: stop reporting exhaustion as a malformed repository master
The engine retires a repository permanently on InvalidCar and attributes it to the remote's CAR, so any OOM collapsed into that verdict silently drops a good repo -- most likely precisely under whole-network memory pressure, where experiment 3 reached 24.3 GB RSS. prepareRepo's Mst.loadLazy catch mapped every error to InvalidCar; the compiler shows loadLazy's error set is exactly {OutOfMemory}, so every non-missing-block failure there was an exhaustion misfiled as bad data. An allocation-failure sweep over the whole prepare/emit path pins the classification, and found two more sites in zat (fixed in v0.3.21/v0.3.22, pin bumped here). Cleanup itself needs no test: the parse arena owns every byte a PreparedRepo references, which is why it has no deinit. Closes the whole-network bootstrap parity row. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>