'off' when not asked for, 'gated' on a 404, 'open' when the route answered
whichever Drupal cache headers a plain host sets, when probing a VPS
x-cfw-v, the header contract version.
Bumped by the worker only on a RENAME or a REMOVAL, never on an addition, so a version this probe does not know about means a header it reads by name may have moved. Null means a worker old enough to predate the marker, which is a different thing from a renamed contract.
x-cfw-plan, which the object sets on a MISS; null when the response came from a cache tier
WALL CLOCK around the fetch, never cpuTime; RULE 0 forbids reading this as a CPU figure
every
x-cfw-*header verbatim, because those headers ARE the measurement