1. Military callsigns (aircraft.js): callsigns matching CONFIG.aircraft.
militaryPrefixes tint red regardless of altitude band and bump larger. New
"Military filter" HUD row (default off) shows only military aircraft when on;
status "N military of M". Pick overlay shows Military/Civil class.
2. Satellite ground track (satellites.js): selecting a satellite draws its
sub-satellite path (height 0, ±half orbit around now) as a dashed polyline in
the sat's colour; deselect hides it; one track at a time. Recomputed on
demand from the satrec (no upfront precompute of 97 tracks).
3. Shareable URL state (main.js + ui.js): camera / mode / layer toggles / clock
offset serialize to location.hash (replaceState, 1 s cadence, only on change)
and are restored on boot; malformed hashes ignored silently.
4. Screenshot endpoint (serve.py): dev-only POST snap?name= writes a base64 PNG
body to docs/<name>.png (name sanitized to [a-z0-9-], can't escape docs/).
Captured docs/screenshot-data.png + screenshot-photo.png (render() called
synchronously before toDataURL — the preserveDrawingBuffer pitfall).
README rewritten for Wave 2: quakes/fires layer rows (marked REAL), replay,
shared cache, shareable links, ground tracks, military, screenshots, updated
architecture + roadmap.
Verified in browser: 11 military of 6062 + filter; ground track 180 pts on
select / hidden on deselect; URL round-trips camera+mode+layers+clock; both
screenshots written as valid 1280x720 PNGs; subpath audit clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>