Review fixes on the provider-catalog matrix:
- KNOWN bugs go through tests.e2e.core._pending_fixes.known_failure again (strict_known and the
"now green -> drop KNOWN" asserts are gone), so a fix PR landing first simply turns its cells
green. Each KNOWN is gated on the bug's OWN observed signature via a dedicated CatalogGap raised
only at the gated assertion: xai = no inference at the fake + api.x.ai CONNECT; listing = vendor
host hit with no probe error; nebius switch = vendor-host validation error; fallback = fallback
fake untouched + its vendor host CONNECTed; OAuth patterns anchored. Unlisted red cells still fail.
- CatalogFake answers only exact routes (configured base path + dialect endpoint / listing path),
404 otherwise; reached_own_endpoint and the listing cells assert the exact path.
- Turns run with agent.auto_recovery_cycles: 0 (the documented post-exhaustion ladder parked the
xai/fallback rows for minutes: 14 CONNECTs over 118 s, bounded by design, not a retry bug) and a
watchdog kills a child 8 s after a vendor-host CONNECT with no inference at its fake.
- An unknown api_mode fails the row instead of skipping; only explicit auth types and the named
keyless provider skip.
- Usage cell asserts the exact sum the fake reported for answered main-turn calls.
- Listing 404 / hang degradation cells for the rows that already list from the configured endpoint.
- Shard body moved into the helper; fallback key check uses the dialect's auth header; the three
unconditional-skip OAuth params dropped (kept under NOT COVERED).