v10.1.0 — stop lint-containerfile + detect-changes contending for anvil

MINOR: no input added, removed, or renamed. Two instance jobs move off the
runner_tag input onto a hardcoded SaaS tag; every consumer's own
.gitlab-ci.yml needs no change to pick this up on its next pin bump.

instance's lint-containerfile and detect-changes jobs shared the
runner_tag input with the hardware-bound build job. All 8 instance
consumers set runner_tag: anvil (the estate's single self-hosted qemu
host), so both lightweight jobs queued behind real image builds on the
same single machine. Measured over 30 days: lint-containerfile +
detect-changes were 2.5% of anvil's compute but 49% of its total queue
wait across those 8 consumers. Worst case: roon-bootc's lint queued 52.3
minutes for 1 minute of work, and because stages run sequentially that
dragged build/detect-changes behind it too. Neither job needs anvil:
hadolint is a static lint and detect-changes is a skopeo inspect registry
digest check -- no privilege, no host state, no credential beyond the job
token.

Hardcoded both jobs' tags to saas-linux-small-amd64 rather than dropping
tags entirely or adding a new spec:inputs override. Confirmed via the
runners API that the self-hosted storr runner (id 50689664) registers
itself under every GitLab SaaS size tag AND has run_untagged: true, so a
bare/untagged job is not guaranteed to land on genuine SaaS either -- an
explicit tag is no more or less ambiguous on that axis, but it is
self-documenting and (also runners-API-confirmed) structurally guaranteed
to never touch anvil: anvil's tag_list is [lodestone, qemu, anvil] with
run_untagged: false. small, not runner_tag's large default: both jobs are
sub-minute work, right-sized the way vm_size is for build. No new input
added: neither job has a real per-consumer reason to diverge, so a
lint_runner_tag-style knob would be a moving part no consumer would ever
set. build and promote are untouched.

Verified via POST ci/lint against a real consumer's content
(example-plain), before vs. after: only lint-containerfile and
detect-changes tags changed (anvil -> saas-linux-small-amd64); build
stayed anvil, promote stayed crucible. This catalog's own
consumer-shape-gate child pipeline -- a real pipeline-creation +
detect-changes execution -- passed against the fix branch, and both the
branch pipeline and post-merge main pipeline (seal-self-test,
consumer-test-build/verify/cleanup, release-check,
verify-release-image-toolchain, consumer-shape-gate) were job-level green.

Also folds in the prior Unreleased content: verify-release-image-toolchain
(always-on toolchain check against create-release's image, closing the gap
that let a bad gitlab-org/cli digest bump land unverified until the next
tag), the .release-image/&release-image pin refactor, and the
qcow2-bake/installer-anaconda-iso rootfs default change (xfs -> ext4,
fs-verity requirement). See CHANGELOG.md for the full entry.