b8d91dcc5b
Rewritten from the plan's oldest-crash scenario: empirically, 2-node keep-oldest downs the non-oldest partition, so a hard crash of the OLDEST makes the younger survivor down itself (total cluster loss) — the survivable case is a crash of the younger node. The member-removal assertion has teeth (impossible under the pre-fix NoDowning default). See the test's XML doc for the active/oldest-node-crash gap.