Bug fixes
Enrichment select guard runs once per upsert (issue #912)upsert_company ran _drop_unwritable_enrichment to collect warnings for
its reliability envelope, then delegated to add_company/update_company —
which ran the guard again. The writability probe is cached per
(token, slug), but failed option probes are deliberately never cached, so
the second guard could observe a different option set than the first: the
envelope’s guard saw a transient probe failure (option set unknown → field
kept, no warning), while the writer’s guard saw the recovered probe report
the mapped option renamed (select write dropped, its warning discarded). The
record was then written without the select value and the envelope reported
partial_success=False with no trace of the drop.
The write bodies now live in internal helpers (_write_new_company,
_write_company_update) that take the guard’s skip set as an argument. The
public add_company/update_company remain guarded thin wrappers for direct
callers (CLI/export paths, the accounts backfill), and upsert_company
guards once and calls the helpers directly — so the envelope’s warnings
always describe the body actually written. A regression test drives a full
no-match → create upsert with a flaky option probe and pins one probe per
source per upsert.