noderange() reads a ^file by default. With nofile it opens nothing, yields no
nodes, and flags the rejection, including when a ^file is mixed with a plain
node. A plain range sets no flag. A pipe-shaped name runs no command.
site.excludenodes keeps its own semantics: it does not change the request's
rejection state, and its own ^file is still read.