XML allows a raw `>` and the other quote character inside an attribute
value, so a first-match search for `ref=`/`max=` could be fed a fake
value from an earlier attribute while saxes read the real one:
- <mergeCell>/<col> attributes are now read in order from the tag name
with a sticky regex that consumes each quoted value whole. A tag whose
attributes do not parse up to `>`, or that repeats a name, is refused.
- The chunk carry keeps everything from the last `<`, which can never
appear inside an attribute value, instead of comparing against the
last `>`.
ExcelJS keeps a Row object for every <row>, cells or not, so <row> tags
now count against per-sheet (100k) and total (250k) caps with their own
row-limit code, and the worker passes maxRows as a per-sheet backstop.
styles.xml counts every <xf> without tracking which list it sits in,
since a </cellXfs> inside a comment desynced that state.