- MobileUserSocket: cap new socket connections per IP at 30/min via
Aprsme.RateLimiter. Denials log and return :error at handshake.
Tests bypass the check (no real peer_data).
- MobileChannel: rate-limit the expensive client-initiated handlers
(subscribe_bounds, subscribe_callsign, search_callsign) at
30/minute per socket. Streaming packet delivery is unaffected.
- MobileChannel: historical packet loads now arrive as a batched
`packets` event (100 per frame) instead of one `packet` frame per
row. Live streaming still uses the single `packet` event.
- Updated docs/mobile-api.md with the `packets` event and rate-limit
semantics; migration note preserves compatibility for clients that
only handle live `packet` events.