v4.1.0: substrate -> instance cascade

Validated against basef + carmine v4.1.0 MRs (both GREEN).

Catalog changes:
- base-build-scratch .heavy-job-rules, instance build rules,
  container-build job_rules: accept ACUTE=true and trigger source

Wires the basef -> carmine cascade pattern with cve-watch acute
trigger (deterministic pre-screen) and operator acute-rebuild
command. AI triage (claude-sonnet) lands in v4.2.0.