7afac122ef
ui_meta (#85440) syncs compact roster metadata but is 64KB-capped because it rides every profiles.list — image avatars stayed per-client. set_asset writes a validated image (data URL or base64; PNG/JPEG/WebP by magic bytes, 2MB cap, atomic write) to assets/avatar.<ext> in the profile dir; get_asset returns it as a data URL on demand; profiles.list gains a cheap has_avatar flag so rosters know to fetch without probing. Server-side, so every client machine paints the same profile picture.