[tests] pin the stream engine's starts and replay chunks master
the representation audit lists every crate-visible function in src/control/stream as a boundary, and the shared engine landed with none of them inventoried. Start::live and Start::replay had no test of their own: nothing checked that a live start skips rows through its head, that a replay resumes after its cursor, or that a cursor already at the head reads nothing. ReplayChunk::read, which turns stored keys into positions for every stream, had no direct test of its scan bound, its skipping of keys that aren't positions, or how last_seen follows filtered rows. the jetstream outbox, JetstreamEphemeral::to_json and stored_event_to_bytes also had nothing checking that the json a live subscriber gets is the json a replay renders for the same commit. live_json_is_what_a_replay_renders compares the two and pins the commit shape, record body and cid. it needs the jetstream feature, like the rest of that module.