Address two codex P2s on cross-session/late-arrival races:
1. Cancel dictation during the final transcribing window. The draftKey
cancel effect only checked isRecording/isStarting, but stopRecording()
keeps the transcript listener alive (isTranscribing=true) until the
native stopped event. A channel/thread switch during that grace window
didn't cancel, so a late transcript leaked into the newly restored
draft. Include isTranscribing in the ownership check.
2. Scope push_dictation_audio to the owning session. Late flush chunks
from a just-stopped session could be fed into a newer session's engine
and transcribed into the new draft. Prepend an 8-byte LE u64 session
header to each raw audio payload; native only feeds audio whose header
matches the active session_id and drops stale chunks.