core: fix cursor position + expose selection body on Snapshot master
primary_cursor_range now derives cursor position from Range::cursor(text) — the same accessor helix-view's CursorCache uses — instead of raw Range::head. After commands like c that delete a selection and enter insert mode, Selection::ensure_invariants width-1-expands the collapsed range, so Range::head lands one grapheme past the visual cursor. Range:: cursor accounts for that; using it fixes an off-by-1 for c specifically and matches Helix's own render path in every mode. New primary_selection_range returns the primary Range body (from, to), so the frontend can draw the actual selection highlight — previously we only exposed the cursor block, so multi-grapheme selections (w, e, x, W, etc.) rendered as if collapsed. Snapshot gains selectionStart / selectionEnd; the JSON-shape test lists them alongside cursorStart / cursorEnd. Three regression tests cover the wire contract: word_selection_reports_ selection_body_range, insert_mode_reports_zero_width_cursor_at_head, and change_command_leaves_caret_at_start_of_deletion (the c off-by-1 reproduction).