Resolve conflicts against the NodeDB signer/key primitives (#11050) and the
admin-key PKI decrypt budget (#11100).
- NodeDB: drop this branch's hasSeenXeddsaSigner in favour of develop's
isKnownXeddsaSigner. They answer the same question, but develop's reads the
dedicated warm signer bit (warmSignerOf) rather than the WarmProtected
category, and TrafficManagementModule already depends on it. Keep develop's
copyPublicKey/copyPublicKeyAuthoritative, isVerifiedSignerForKey and
commitRemoteKey/KeyCommitTrust.
- checkXeddsaReceivePolicy: keep this branch's Strict/Balanced/Compatible
policy, which is a superset of develop's balanced-only downgrade gate, and
call isKnownXeddsaSigner from it. develop's !pki_encrypted term is dropped
because the policy returns early for PKI packets before that check.
- perhapsDecode: keep develop's key resolution (NodeDB then pending-key, only
for real PKI candidates) plus its admin-key token bucket, and re-apply this
branch's pkiAttempted flag feeding the DECODE_OPAQUE verdict. Keep both
passesRoutingAuthGate and adminKeyFallbackAllowed/Refund.
- test_A17: model eviction the way NodeDB actually does it, passing the warm
signer bit as well as the XeddsaSigner category, since isKnownXeddsaSigner
reads the former.
Native suite: 38 suites, 743/743 cases, no sanitizer findings.