v0.10.0 — track aicodebox v0.8.3 + adapter logging + single-source versioning

aicodebox v0.8.2 backfilled reconstruction-grade logging on the
schema-mode path. v0.8.3 adopted single-source versioning. This pibox
release pulls both into the project end-to-end.

Highlights
- BASE_IMAGE bumped to psyb0t/aicodebox:v0.8.3 (Dockerfile, Makefile,
  tests/common.sh in lockstep). Tag-only pin — digest pending registry
  push.
- PiAdapter logging brought from zero to reconstruction-grade per
  ~/.claude/rules/06-logging.md. Decode errors, provider errors, schema
  bolt-on, build_argv decisions, parse_output summary — all logged.
  Security-aware: never logs tokens / secrets / full prompts / full
  schemas; only schema keys + truncated samples.
- Single-source versioning per ~/.claude/rules/49-versioning.md:
  pyproject.toml is THE version; __init__.py reads via
  importlib.metadata; Makefile derives the docker tag from pyproject
  and tags both :v0.10.0 AND :latest. Eliminates the version-drift bug
  that had __version__ stuck at "0.1.0" across every release since
  v0.1.0 itself.
- New Makefile targets: ``make version`` prints the derived tag.
  ``pull-base`` honors SKIP_BASE_PULL=1 for local-only base builds.

PiAdapter functional contract is unchanged. No wire-level changes to
/run / OAI / MCP / files-API. Tests: 46/46 green.

Built against psyb0t/aicodebox:v0.8.3 (tag pin). Older base images are
incompatible — the adapter's logging assumes the base's JSON formatter
is the configured handler at startup.