fix(redact): split OPF batches into bounded calls
Commit

A checkpoint ref's unique leaves all went to one opf call. A large ref could need longer than the 3h timeout ceiling, so the call was killed, the breaker tripped, the worker stopped, and the same ref came up first on every later flush, starving every ref queued behind it. Send at most 1 MiB of leaf text per call instead, so each call's adaptive deadline tracks its own size and a large ref finishes slowly rather than blocking the queue. Typical units still fit in a single call.
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3NDQB64RRKFF54TPGYXQQGH
Checkpoints
Checkpoint 1