Ordered model specs and provider wildcards the policy permits.
Three states, and the difference between the last two matters:
None -- no policy is active; every model is allowed.() -- a policy is active and permits nothing. Model construction
and default resolution both fail closed._get_default_model_spec walks the tuple in declaration order). An
entry is either an exact provider:model spec or a provider:*
wildcard permitting every model from that provider; a wildcard is never
selected as a default itself, but models it admits remain candidates.Test is None, never truthiness: if not config.allowed_models conflates
"unrestricted" with "deny all" and inverts the policy.