Revocation is terminal for the current contract ID. A later approval must
use a newly reviewed contract. Revocation is not deletion: fitted state and
exact-row material remain in the private store. Use destroy_generator()
to permanently remove fitted state while retaining the contract, lifecycle
tombstone, and audit receipts.
