media: release ingest before the recording sink's cleanup wait master
Review follow-up. recordTee closed the pipe only once dumpToFile returned, but the copy-error path in dumpToFile runs the sink's Close first — for S3 that commits the upload, flushing a final part and waiting on every outstanding request (bounded only by the s3 package's per-op timeouts). One rejected part plus one hung request therefore still held the live stream for minutes. dumpToFile now reports "stopped reading" the moment io.Copy ends, so the tee unblocks ingest before that cleanup; TestRecordTeeSurvivesRecorderCleanupStall (a rejected part plus a part the fake never answers) hangs >30s without it. Also wait past the node's 30s live-window retention in the web spec's liveness check, so a stream that stopped producing segments can't pass on stale window entries.