spec(renderer): add opt-in OSC 22 pointer-shape tracking (§12.6) master
Lets the mouse pointer change shape over the UI, driven by the renderer's existing hit-testing. Elements declare a CSS-style `cursor` shape on open() (renderer-ignored, not packed to wasm); with `trackCursor: true`, render() returns OSC 22 bytes in a separate `cursor` field for the caller to write — kept out of `output` so render content stays pure. Narrows the §11.2 prohibition to the text caret and carves out a single opt-in exception for the mouse pointer shape, preserving INV-1 (renderer produces bytes, caller writes) and INV-7 (capability replies arrive via the input-side PointerShapeEvent; the caller correlates them). All tracking state lives in the TS term layer, so the wasm core stays frame-stateless. Framed as elastic §12 surface, like the pointer event model it builds on.