Safe, blocking public engine primitives.
TtsEngine owns the one async runtime used below the synchronous public
facade. Model work is intentionally absent in Phase 0, but the admission,
cancellation, budget, observer, and bounded-streaming contracts are real so
later model stages cannot introduce a second orchestration path.