mews_profile pins both the stylesheet's name and its content, so a site
never actually chooses either; leaving the file itself to be placed in
every content root by hand just gave operators a way to get it stale or
missing. The byte-for-byte copy from mews.page/spec 5.1 now ships in the
binary and resolves `mews-0.1.css` at any depth, matching how a page's
relative link to it resolves, across every protocol that can hit it.
A new mews_profile site setting switches the XHTML-MP 1.2 doctype, the
conformance marker, the viewport tag and the default stylesheet link, and
drops raw HTML passthrough and off-site or data: images that the profile's
permitted-element list cannot vouch for.