feat(spp): add AMD-rooted CPU attestation leg with pure-Python TPM quote verifier master
Add the pure, read-only, side-effect-free solstone/think/services/spp_attest/ subpackage for the CPU leg of the composite attestation appraiser. It parses SEV-SNP reports, verifies AMD certificate chains and report signatures, adds a net-new pure-Python TPM2 quote verifier with no tpm2-tools or subprocess reachability, decodes SPPGPU1 TLV envelopes, and checks the composite binding. The binding is SHA-256(domain || owner_nonce || channel_binding || SHA-256(TLV)) with domain sol-spp-option-a-bind-v1. channel_binding is injected so the V4 TLS exporter can use the same code path. The splice check binds the TLV field-1 nonce to the nonce carried structurally inside the SPDM report at a fixed offset, never through substring search. Add intentional binary and PEM fixtures plus vendored AMD roots from real captured attestation evidence from a live Genoa SEV-SNP + Hopper run. These are device/report bytes and public certificates, not user content. This is library, fixtures, and tests only. _CONFIDENTIAL_ATTESTATION_VERIFIER remains None and the confidential lane stays fail-closed; wiring is left for a later arc.