Completes the `host_functions/` layer: reads, nested objects, arrays,
nested arrays, and the two emit paths, each against a real ledger.
What the shapes turn out to mean, now asserted rather than assumed:
- An account has one data object, and the first write decides whether it
is a map of keys or a list of elements. Mixing them is refused rather
than silently replacing one with the other.
- The two string arguments of a nested write are the outer key then the
inner one. Reading under the swapped pair finds nothing, which is what
a contract that got the order wrong would see.
- Two arrays under two keys are two arrays.
- A stored integer reads back big-endian, the opposite of the
little-endian a parameter answers with.
Two more defects are pinned rather than fixed, both the same shape as the
one in the previous commit: reconstructing an `STTx` re-runs its format
check, and the throw lands outside the guard that would have answered
`SubmitTxnFailure`. `emit_txn` cannot emit a transaction that does not
already carry `tfInnerBatchTxn`, because setting the flag means rebuilding
it, and an ordinary Payment's defaulted `sfPaths` is rejected on the way
back in. The contract is told `InternalFatal` and the run stops.
`ContractLedger` now gives each host a transaction of its own; two
identical ones share an id, which a ledger refuses to record twice.