#803 folded the mitm-bypass match into shouldSplice (checked BEFORE ad-block),
so ad networks that also live in the bypass seed (adform/amazon-adsystem/
rubiconproject/smartadserver…) started SPLICING instead of being 204-blocked —
silently disabling ad-blocking for them. Move the bypass match OUT of
shouldSplice into Decide AFTER blockedByAd: explicit tls-splice → ad-block →
bypass-splice (cert-pinned apps only). Signal/banks still splice; ad nets in the
bypass list block again. New regression-guard case (adform.net→block). Live gk2.