host_authority: per-branch reject breakdown + sampled warn log master
restores the observability piece of ee4e368 (collaterally reverted with host retention on 39a0886). pure counter plumbing — no behavior change. splits failed_host_authority into 6 branches: parse_did, resolve, no_endpoint, bad_url, unknown_host, host_mismatch emitted as relay_host_authority_reject{branch=...}. invariant: sum(branches) == failed_host_authority. needed before acting on the post-attack handoff's ask #2 — the proposed "gate on cache miss" assumes a cache-miss-then-broadcast model that doesn't exist for host_authority (only for signing keys). once this is in prod, host_mismatch rate vs others tells us whether the 740-DID lead is stale-cached forgeries (no_check path) or genuine resolver failures. Co-Authored-By: Claude Opus 4 (1M context) <noreply@anthropic.com>