Eventually, our 6 day certs will not contain CRL URLs. Not having to contain revocation information is the whole point of short-lived certs.
Those short-lived certs probably will continue to appear on our CRLs anyway. So if you're getting your CRLs from a system like Mozilla's CRLite, then you can still get revocation updates for short lived certs. But clients that try to download CRLs directly won't be given a URL to do so, because a) that reduces traffic to our CRL servers, and b) it would have little worst-case security benefit due to the lifetime of the CRLs outliving the certificates themselves.