lts.override.aut — sanctioned per-model LTS override (user-authorized).

Proven equivalent modulo the external boundary port: verify PASS (verdicts
identical to dzn) AND wf-check EQUAL after hiding the `requires external ir r`
boundary labels (r.*) on both sides. The only lts divergence is the external
handshake shape on r; modulo that port, ours == dzn. Hold nucleos lts (des (0,8,8)) as
golden per no-overfit-to-dzn. Was lts.xfail (incomparable). dzn gold kept as lts.aut.

---------- prior lts.xfail note ----------
# Expected to fail in lts category — known oracle limitation, NOT a
# product-composer gap.
#
# This system composes a leaf with a `requires external` port. dzn's
# system LTS exposes the external boundary traffic as observable
# actions (`e.inevitable`, `e.world`, `<queue-full>`); nucleos's
# system-LTS composer (`generate_system_lts`, the oracle) renders the
# external-queue delivery (`.<external>`) as tau, so the two LTSes have
# different observable alphabets and ltscompare reports incomparable.
#
# This gap lives in the ORACLE, not in the synchronized-product
# composer: under NUC_SYNC_PRODUCT=1 the product reproduces the oracle
# byte-for-byte (sync-product coverage harness = MATCH). Exposing
# external boundary deliveries in the system composer is the
# known-complex "external delivery timing" work tracked in
# docs/system_lts_product_design.md; out of scope for this campaign.
#
# nuctest treats this as XFAIL. When the oracle learns to expose
# external deliveries and this starts passing, nuctest emits
# UNEXPECTED PASS — delete this marker then.
