- handle_call(:shutdown, _, state): split into a shutting_down=true
fast-path clause and a normal initiate_shutdown clause. No more
`if state.shutting_down` inside the callback body.
- terminate/2: extract graceful_shutdown_needed?/1 (four function
heads on the reason tag) and maybe_graceful_drain/2 (guarded on
state.shutting_down) so the shutdown side-effects are isolated to
a single, pattern-matched entry point.
Adds 4 unit tests for the pure callback paths
(shutting_down?, shutdown-already-in-progress, EXIT pass-through,
rescue fallback on unavailable GenServer).