Why acknowledgement loss requires stable operation identity, an explicit unknown state, reconciliation, and fault injectionânot blind retries.