Async source and error ownership

The package presents persistent errors by default. Turn on application ownership to see the explicit "handled" path.

Failure controls

Extension failure mode rebuilds the instance because quarantined extensions are not retried.