feat(spl): relay pair-window v2 (0x06) + sol CLI relay-pairing client master
Hard cutover from the rotating-TOTP 0x03 relay pair-link to the home-opened pairing-window 0x06 link, and add the client half of relay pairing as a sol CLI command. - relay_link.py: one derive_rk (HKDF-SHA256, info=spl-pair-window-v1) + one 0x06 encode/decode, imported by both home and CLI. Conformance vectors inlined as the byte-identity gate. - pair_start (spl posture): mint 8-byte S, store S.hex() at 300s TTL, derive RK, emit the 0x06 link, and open+hold a /session/pair-window connection via a convey-hosted single-slot pair-window manager (Sec-Pair-Key + Bearer service token; replaced/torn down on new start / 300s / cancel / close). - sol link join: parse 0x06, derive RK, dial /session/pair-dial, run the inner pinned TLS + CSR + POST /app/network/pair, verify the CA SPKI pin + live-leaf binding + instance_id == jid_from_spki(pinned CA), enroll a device token as the round-trip proof, then write the PL bundle. - Delete TOTP entirely: compute_current_totp, totp.json, generate/load/save_totp _secret, the totp_secret enroll field, the dead generate_relay_nonce minter, and the TOTP keying of is_spl_enabled (now posture + service token). - Drop the now-always-false rotating field (PairStartResponse, OpenAPI contract + regenerated artifact, CLI freshness hint, the workspace rotation ring/auto-refresh UI); expires_in is 300. The 5-minute pairing window UI is retained. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>