Wires the quota seam to its producer, so enforcement tracks RLN rather
than only the wall clock.
- Waku.currentRlnEpochQuota (waku/api/publish) reads RLN's current epoch
index and the epoch's user message limit together, returning none when
RLN is not mounted (or its limit is unset).
- MessagingClient.new builds a QuotaProvider closure over that accessor
and hands it to the RateLimitManager. The closure is late-binding: it
queries the kernel on each admission, so a node whose RLN mounts after
construction upgrades from the wall-clock fallback to RLN's epoch and
limit automatically, with no reconstruction.
With this, admit() rolls its window on RLN's epoch and clamps the
configured cap to RLN's user message limit; without RLN it still falls
back to the absolute wall-clock window and the configured limit.
Also switches the quota seam from std/options to results `Opt`, matching
the kernel surface it now bridges (`groupManager.userMessageLimit` is
`Opt`) and the rest of the messaging layer post-Opt migration.
Tests: currentRlnEpochQuota is none unmounted and reports epoch + the
configured userMessageLimit when mounted (anvil-backed).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>