keep the spl revision in one declared source master
The root [workspace.dependencies] table is now the sole declaration of the SPL Git source and revision; both shipping entries inherit it. validate_spl_pin derives its expected source and revision from those workspace declarations and checks source, selector kind, revision shape, a single shared revision, leaf inheritance with no override, lockfile agreement on both the rev= query and resolved fragment, and every local route ([patch], [replace], path, root .cargo source replacement, and a tracked in-tree copy) by package identity rather than dependency key. The guard runs against the real checkout inside make ci through the rust-release-manifest suite, and 25 Git-tracked fixture repositories exercise the production entrypoint at a real process boundary. The pinned revision and Cargo.lock are unchanged. Mutation proofs covered a reintroduced leaf rev, a shortened workspace revision, desynchronized workspace revisions, a root [patch], and a root .cargo/config.toml source replacement. Cargo preempted cargo run for four of the five mutations, so the guard binary was invoked directly for those cases. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>