d6ef0c8013
isLive treated any RuntimeException from the liveness probe as "the lead is gone", which forgetDelegation then acted on destructively and permanently. That made a transient herdr hiccup (socket blip, decode error) on a perfectly live lead indistinguishable from the lead actually being dead — the same one-bad-reading mistake #359 shipped a guard against for lead-tab liveness. Narrow isLive to match AgentControl.agentCall's own rule: only an affirmative HerdrException("agent_not_found") counts as gone. Every other failure is treated as still live and the binding is left alone. Adds aTransientLivenessFailureMustNotForgetABindingToAStillLiveLead, which fails with the bare RuntimeException catch and passes with the narrowed one.