After much fruitful discussion and evolution, this proposal is now a series of "Bitcoin Improvement Proposals" -- see BIP 11, 12 and 13: https://en.bitcoin.it/wiki/Bitcoin_Improvement_Proposals
Sincere thanks to everybody who contributed improvements, ideas and code.
@Mesmer : good idea.
All: So I feel like we started wandering down a path, looking for a way to combine hashed signatures together. We ran into a dead end, so we started wandering through the forest looking for second-best solutions, learned a lot, but eventually got lost among the trees.
Mesmer's comment seems right to me: why not just do m-of-n OR master-key ?
If we need to, maybe in the future we could expand to a second: m-of-n OR p-of-q, which would also be simple. We could even do that now (m-of-n OR master key is the same as m-of-n OR 1-of-1)....