Security audit finding SEC-DB-01. The three read-only opens of the
catalog `game.db` (runtime bundle loader, legacy ETI reader and the
catalog publisher) set only `read_only(true)`. SQLite still honours
schema-embedded SQL in that mode: triggers, views, CHECK constraints
and expression indexes may call functions with side effects or virtual
tables unless `trusted_schema` is off.
`harden_read_only_catalog_options` now applies `trusted_schema = OFF`
and `cell_size_check = ON` to those connections. The database is a
bundled application resource, not a remote input, so this is defense in
depth against a corrupted or tampered bundle; it has no effect on the
parameterised queries the code runs.
Test plan: `just test` (the compat tests open real fixture databases
through the hardened options).
Claude-Session: https://claude.ai/code/session_017C3Nbgwpdm3YNwZhhFLHwg