feat(link): admit LAN-direct cert-less connections to the pairing window master
A brand-new device pairing over the LAN has no client cert yet — the ceremony is how it earns one. Make LAN-direct cert-less pairing first-class on the secure listener, with the same structural confinement the loopback/relay path already has and truthful per-origin provenance. - window_open() is now posture-agnostic: the live, unconsumed nonce bounds the cert-less window in both direct and spl postures (fail-closed on unreadable nonce state preserved). Posture no longer gates the window. - Secure-listener admission collapses to "window open" for any PL peer via a pure certless_admission_mode() seam; a closed window keeps the strict, client-cert-required context. PeerMode is threaded through the classifier and pump so the stamp is type-true. - The admitted cert-less identity is stamped with its true origin (pl-direct for LAN, pl-via-spl for relay), so _rough_network records LAN pairs as "network" and relay pairs as "anywhere". - The HTTP login-gate pairing exemption covers both cert-less origins; the non-pairing surface stays fully gated (keys on fingerprint is None). This widens which peers/posture may host an in-window pairing, not what a cert-less peer may do: the relaxed TLS context stays certificate-optional (unauthorized cert => TlsError, never cert-less), wsgi confines cert-less requests to app:link.pair, and CERTLESS_TUNNEL_CAP is unchanged. Reaping is now driven by nonce expiry/consumption, not posture. disable_spl()'s docstring is corrected to match. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>