Proposals 1 - 4: my votes

#1: YES, as amended by SEF.  I would prefer to leave two levels
(0 and 1) for the unsafe state and two (2 and 3) for the safe
state with respect to this, so that implementors could distinguish
other things for each case.  However, the requirement that 1 be
the default value is persuasive.  (I might recommend deleting this
requirement, but prefer not to stir things up.)

#2: YES

#3: YES for 3A

#4: NO.  I favor having a way to get at this information, but this
proposal isn't the best way.