- wants_json: true only for an exact `application/json` entry with q > 0.
Absent, empty, wildcard, application/*, near misses, q=0 and malformed
headers all fall through to the 303.
- The four mark routes share one exit, _mark_done: 204 with no body for the
in-place client, otherwise _mark_redirect unchanged.
- back=view lands on /b/<name>/view?f=<rel>#rail, only for a media item of
this booth. It is built from the resolved rel and never echoed. Anything
else takes the no-`back` landing.
- tests/golden/r2_mark_303.json: 108 responses recorded from the PRE-R2
code (6 route cases x back absent|marks x 9 non-JSON Accepts), replayed
byte for byte (INV-4). Two mutations (q>=0, substring match) turn it red.
- The contract now states the q=0 rule.
- Item.ordinal: the 1-based position in booth_items over the items that
render. It is appended, and set in the resolver. Tiles print it padded to
the whole set's width, and a filter never renumbers.
- review_chain: the item order filtered to media. It replaces image_chain as
the zoom route's ring, so a set of pictures and sound steps through both.
image_chain stays importable.
- .seen: which media items were looked at full size, written by the review
route under record_view's gate. It is rewritten whole: deduplicated, pruned
to live items, sorted. The temp file is created with O_EXCL and swapped in
with os.replace, so a planted symlink is replaced, never written through.
It never raises.
Nine new tests. The contiguity and symlink tests are mutation-checked.
669 passed.