Release 3.5.1 -- the documentation was wrong in ways that mattered

A patch release with no intended behaviour change to the codec: a full decode is
byte-identical to 3.5.0 on all 11 decodable corpus files, with all 11 refusals
unchanged. What changed is what the project SAYS, which in several places was
false, and one public function that refused files it should have accepted.

Three false statements in the clean-room record. CLEANROOM.md claimed no PGF
decoder binary was ever obtained or run, and that verification therefore rested on
round-trips rather than differential comparison -- while eight harnesses invoke the
reference decoder and the digest's strongest evidence is 48/48 files exact against
it. docs/SOURCE-LOG.md had no entry at all for the reference binary, despite its
own entry 1 promising one would be added when a binary was obtained; the entropy
coder was derived through that binary. SPEC-DIGEST.md's front matter said no source
other than the two Stamm papers was consulted, which was untrue of some 5,800 of
its 6,325 lines. All three are corrected with explicit withdrawals rather than
silent replacements, and the backfilled log entries are labelled as backfilled.
Attestation clause 5 now says "compiled encoder and decoder output"; the signature
block remains unsigned.

Four defects in the published format specification, each sufficient to produce a
broken implementation (docs/PGF-FORMAT.md 1.13): the bit-plane count documented as
a 4-bit nibble when it is 5 bits, misdecoding every 16-bit-per-channel file; the
retracted 45/32 deadzone constant still standing in the quantizer pseudocode, with
the prose that corrects it directly beneath -- stale for nine document versions and
wrong on the |v| = 359 case the v1.3 changelog names; the deliberate int32 deadzone
overflow unspecified, without which qualities 29-31 disagree with the reference;
and a quality-18 ceiling in the shift pseudocode, refusing 13 valid values.

One real bug. parseMacroblock enforced "bit 4 clear" as an invariant after section
7.5.86 had shown bit 4 to be the bit-plane count's high bit, so it rejected
legitimate RGB48 and CMYK64 payloads with PGF_SPEC_GAP -- claiming the format was
undetermined about a field this project had measured. decodeToPixels never used
that path and was unaffected. Fixed, with a regression test; the existing test
named for the invariant turned out to exercise only bit 5.

tools/roundtrip.js ran its whole sweep on import, the only harness lacking
import.meta.url gating.

The supported quality range, stale in roughly forty places -- README, types, the
npm description, the specification and a dozen source comments still said 0..18 or
0..19 where the code has done 0..31 since 3.4.0, and two comments claimed quality 3
was refused when it is among the best-verified values. Every corrected figure was
re-derived from harness output rather than copied; two numbers no shipped harness
produces were dropped instead of reattributed.

Recorded rather than guessed: four mis-keyed gap tags in bitstream.js, types
declarations that no type-checker has compiled, and one reference tool that cannot
be hashed or dated, whose contribution is now stated as unknown.

618 tests. roi-check, progressive-check, formats-check (420/420 each direction),
encode-check, pgfa-quality-check (960/960 over qualities 0..31), and the bitmap,
indexed, gray, lab, untransformed and gray8-step harnesses all pass.