personal memory agent

fix(release): bind the macOS ONNX Runtime pin through the native record master

The shipped macOS speakers-analyze dylib cannot be compared directly to the upstream ONNX Runtime pin because codesigning rewrites the Mach-O bytes, and the pre-signing digest is not recoverable byte-reproducibly from the signed binary. The signing helper now records unsigned_binary_sha256 before codesign, and record_macos_native_wheel carries that into an unsigned_members map. validate_macos_native_record requires the unsigned member set to match members and requires the speakers-analyze dylib entry to match the imported macos-arm64 staging pin. The release driver reaches that validator through both _revalidate_macos_wheels call sites, before staging promotion and again in the post-promote hook. The staged-to-pre-signing link is a build-host attestation, not an operator-verifiable proof; Q4 makes that unavoidable. The operator side verifies the signed wheel member against the native record and verifies the recorded unsigned dylib digest against the pin. Linux in-wheel ONNX Runtime digest enforcement is unchanged. The retained ledger and wheel payloads do not carry unsigned_members; the new field remains an operator-side native-record input. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>