Identity comparison against the four interned sentinel singletons —
mizu_full, mizu_timeout, mizu_closed, mizu_peer_gone — that the
verbs of mizu return to tag terminal states. inherits(x, "mizu_sentinel") tests the class alone, which any payload can carry.
This includes a genuine sentinel forwarded over a channel, which arrives
as an ordinary copy. mizu_is_sentinel() is provenance: TRUE only for
the exact objects that the own calls of mizu return in this process.
So code that relays untrusted values can distinguish its terminal states
from look-alike payloads.