overBudgetAddressedSendIsRefusedNotLeaked

A payload one byte over the budget is refused by the seam with us.tractat.kuilt.core.PayloadTooLarge, not leaked as the fabric's own frame error.

The distinction is the whole point of publishing a budget: PayloadTooLarge names the number the caller should have respected, whereas a fabric-level error names a limit the caller had no way to read — and, in the two in-tree fabric seams before #2069, arrived only after the send had reported success, having torn the seam down or evicted a healthy peer on the way.

Gated on SeamCapabilities.supportsSendTo: broadcast is best-effort and drops an over-budget payload by contract, so only the addressed send has a refusal to observe.

Both ends are checked (#2601), each against its OWN published number, for the reason payloadOfExactlyTheBudgetIsCarried gives: maxPayloadBytes is a Seam member, so a role-split fabric publishes it from two implementations and enforces it in two places.

Where the joiner arm can fail, and why it is the sharper half. The failure this row exists to forbid is published but unenforced: the send returns success and the frame dies later in the write loop, which cannot tell an oversize frame from a dead wire and tears the whole session down — the shape LinkSeam's own comment records. LinkSeam is the joiner on every role-split harness here, so the guard whose absence is most destructive is the one this row never asserted. Nothing in a fixture supplies a refusal; it is the joiner's own oversizeOrNull check, ahead of its enqueue.