Follow-up to #981, which fixed the stop-versus-bind races on connectAndBind and proved them for the start() caller. This files the one gap that PR discloses deliberately, so it is on record as known rather than an oversight.
The stopped guard before the readiness emit (and the transport seed guard in watchStatus) is a single unbranched statement both callers await. The broker suite proves it for start(): the mid-bind cell gates armPlane3 and the pending-dial cell holds a real dial open, and both mutations kill red-and-named. Nothing races a stop against doRebuild's call of the same method. That path is covered today by shared-line reasoning, recorded in a comment at the guard site in packages/core/src/endpoint.ts, together with the condition that voids it.
The condition that turns this issue from optional into mandatory: if connectAndBind's tail ever becomes caller-aware, or the readiness emit splits per path, the shared-line reasoning expires and the rebuild race needs its own cell. Whoever makes such a change should treat this issue as part of its acceptance.
Why it was not built in #981: a rebuild-race cell needs to force a terminal close and then land stop() inside the rebuild's bind window, which is timing-heavy on a CI shard, while proving only that doRebuild awaits connectAndBind, which tearDownIfStopped sitting beside it already shows. The review panel on #981 examined the trade and endorsed disclose-not-build (its condition is the sentence above).
Scope if built: deterministic control of the stop-versus-rebuild-bind window in the broker companion suite, one cell, one mutation with a code-only anchor.
Follow-up to #981, which fixed the stop-versus-bind races on connectAndBind and proved them for the start() caller. This files the one gap that PR discloses deliberately, so it is on record as known rather than an oversight.
The stopped guard before the readiness emit (and the transport seed guard in watchStatus) is a single unbranched statement both callers await. The broker suite proves it for start(): the mid-bind cell gates armPlane3 and the pending-dial cell holds a real dial open, and both mutations kill red-and-named. Nothing races a stop against doRebuild's call of the same method. That path is covered today by shared-line reasoning, recorded in a comment at the guard site in packages/core/src/endpoint.ts, together with the condition that voids it.
The condition that turns this issue from optional into mandatory: if connectAndBind's tail ever becomes caller-aware, or the readiness emit splits per path, the shared-line reasoning expires and the rebuild race needs its own cell. Whoever makes such a change should treat this issue as part of its acceptance.
Why it was not built in #981: a rebuild-race cell needs to force a terminal close and then land stop() inside the rebuild's bind window, which is timing-heavy on a CI shard, while proving only that doRebuild awaits connectAndBind, which tearDownIfStopped sitting beside it already shows. The review panel on #981 examined the trade and endorsed disclose-not-build (its condition is the sentence above).
Scope if built: deterministic control of the stop-versus-rebuild-bind window in the broker companion suite, one cell, one mutation with a code-only anchor.