Limit function call depth and fix lint issues (#32339)
This pull request adds validation to enforce a maximum call depth for
model local functions in ONNX Runtime, helping to prevent excessively
deep or recursive function chains that could cause stack overflows or
performance issues. The validation is implemented in the core graph
logic and is covered by new unit tests.
**Core runtime changes:**
* Added a constant `kMaxModelLocalFunctionCallDepth` (set to 100) and
implemented logic to validate that model local function call graphs do
not exceed this maximum depth. This includes the new functions
`ValidateCallGraphDepth` and `ValidateModelLocalFunctionCallDepth` in
`model_helpers.cc`/`.h`.
[[1]](diffhunk://#diff-a53ff461ebc52d6d228c126597a017c9d757b899f3244a795ab2118e41f29444L17-R27)
[[2]](diffhunk://#diff-e1f6b61449afbbdbd824e4eef1019d66b329a821db67db46b9f06e011369a8deR181-R263)
[[3]](diffhunk://#diff-a53ff461ebc52d6d228c126597a017c9d757b899f3244a795ab2118e41f29444L35-R50)
* Integrated the call depth validation into the model loading and graph
resolution process by calling
`owning_model_.ValidateLocalFunctionCallDepth` in `Graph::Resolve`
(guarded by `!defined(ORT_MINIMAL_BUILD)`).
[[1]](diffhunk://#diff-e231a92b40d89409cc8e82436be0a15bc87ef95c93b303b9feaeab6e50c8835cR3810-R3813)
[[2]](diffhunk://#diff-27dfc51b4b723d56e08b54409b60a5d7a689f3908c2208385449435ad3db9641R304-R307)
[[3]](diffhunk://#diff-fe6678da94ab081bad3fc9d2a999be576ba067eeca41cb5d0f474408da2a832bR160-R161)
**Testing:**
* Added comprehensive unit tests for the new call depth validation
logic, including tests for maximum accepted depth, unreachable excessive
depth, excessive shared tail, and integration with model loading.
**Other:**
* Minor includes and code organization for new logic and tests.
[[1]](diffhunk://#diff-e1f6b61449afbbdbd824e4eef1019d66b329a821db67db46b9f06e011369a8deR8)
[[2]](diffhunk://#diff-c78e822207193cf3dbd4c9b5630ed0da508286c156454770d8c8b74d3047d317R7)
[[3]](diffhunk://#diff-e231a92b40d89409cc8e82436be0a15bc87ef95c93b303b9feaeab6e50c8835cR34-R36)
These changes improve the robustness of ONNX Runtime by preventing
models with excessively deep local function call chains from being
loaded or executed.