const StageOpen, StageClosed, StageFrozen
The stage ladder, copied in shape from Sui's UpgradeCap: compatible, additive, dependency-only, immutable, where a policy can only ever become MORE restrictive and make_immutable discards the cap. CosmWasm (a contract with no admin) and Solana (an upgrade authority set to None) reach the same place with one bit; the ladder is better because the interesting states are between "anything may take this over" and "nothing may ever change again".
This pattern has an owner and a candidate list, so it has a middle rung the owner-less selfreg cannot express: no new code, but still free to roll back among what is already deployed.
What the top rung does NOT do on its own: freezing this realm ends changes to the POINTER, not to the code behind it. A private implementation realm can be re-added at its own path, which would swap behaviour under a frozen facade. It holds here only because every implementation is public by construction: handing the facade its own object is exactly what forbids private (see ../../README.md).
