* test(#4717): add failing-first coverage for the two runtime-identity marker seams
* fix(#4717): consult the per-install runtime marker at both identity seams
resolveReportedRuntime (agent_runtime) and loadConfigResolved
(config.runtime) both ignored the per-install .gsd-runtime marker that
resolveRuntime and the model-resolver gate already read. On a
multi-runtime machine (e.g. a globally exported CODEX_HOME), host sniffing
misreported every Claude Code session as codex, and a shared
defaults.json stamped by the first non-Claude install leaked its runtime
to every other one.
Seam 1: the reported-runtime ladder becomes explicit > install marker >
host detection > claude. Seam 2: loadConfigResolved fills an empty
config.runtime from GSD_RUNTIME then the marker, copy-on-write (the
builtin-defaults branch returns a shared object). Explicit runtimes and
marker-less trees are unchanged.
* fix(#4717): a marker-detected runtime opts into its tier map (decision a)
* fix(#4717): stamped-defaults leg, marker fail-safe, docs, review fold-ins
* chore(#4717): backfill changeset PR number (4861)
---------
Co-authored-by: sim <sim@local>