Read Restrictions and Catalog Labels: Unifying governance across engines and catalogs

The Apache Iceberg community advanced spec additions for read restrictions and catalog labels in the REST Catalog. These changes allow governance policies to be delegated to external engines like Spark and DuckDB, ensuring consistent enforcement of row filters and column masks. The update makes governance context portable across different data catalogs, supporting unified access control in open lakehouse architectures.