Upgrades and migration
A record binds program_id and template_id. An upgrade is a new program
leaf. Migration is a method of the old program that consumes the old
record and, via a flow or a bound-note handoff, a method of the new program
that creates the new one, in one transaction with two fragments authorized
by the record's signatories. Nothing migrates automatically. Retiring a
method VK strands records that only it can consume; weld build refuses to
publish a program whose templates have no consuming method.