Only `robotd-design.md` conflicted, in §2.4 Safety: this branch rewrote the
section, and main meanwhile removed the fall gate and the fall recovery, made
`limp_fall` the only answer to a fall, and shipped it on.
Both sides are kept. The section keeps this branch's corrections against the
code — non-finite refusal, the actuator range clamp, the deadman — and takes
main's newer facts on top: the verdict is published and gates nothing, and
limp-fall becomes §2.4.1 under the new numbering.
The rest of the page said the old thing in five more places, so it says the new
one instead: the `safety.apply` box and the `driving` line in §1.4, the
bring-up conditions in §3.3 (the "not fallen" gate is gone, and being down is
now called out as deliberately *not* a condition), "fall recovery" in §5.3, and
the safety test in §6. §7 gains the decision itself.
Assisted-by: Claude:claude-opus-5