WIP: Disconnect ran two blocking writes to the victim's socket on the
killer's goroutine with the full 30s writeTimeout each, so a victim that
stopped reading stalled the killer up to ~60s -- wedging the operator's
serve() loop or the HTTP KILL request. Move the notify-and-close to its
own goroutine and bound both writes with a short killWriteWindow.
WIP: the apply loop issued independent UPDATEs, so a failure partway
through '+w-o' left '+w' persisted while the caller reported total
failure, contradicting the doc comment. Collapse the parsed ops to the
final value of each flag and write them in one transaction via the new
db.SetSessionUserModes.
WIP: c.cfg.ServerName defaults to "", so the three new wire handlers
emitted an empty server-name parameter under the shipped default config.
c.serverSfx already carries the same "neoirc" fallback the HTTP path
uses, and sendNumeric uses it for the prefix. Empty-ServerName test
follows.