# Co-located World startup is bounded and parallel

Status: Accepted. Date: 2026-09-30. Card t_94bcd252, task t_eecd4a9d.

Dub's accepted browser trace charges 3.71 s cold and 3.38 s repeat to World
startup. The pinned runtime imports and starts co-located factories in sequence,
then waits for TCP listeners and boot-identity answers in sequence. These twins
have preallocated distinct ports, separate roots and fixed configuration. Their
factories do not consume an earlier twin's discovered environment.

Run up to eight independent startup operations at once. On any failure, stop
beginning new operations and join every operation already begun. Shared-mode
startup records each returned server before checking its bound port, then stops
all started servers if startup fails. Every stop has the existing three-second
budget; rollback errors accompany the original failure. Worker-mode startup
also terminates all owned workers on failure, and exit before readiness rejects
even when its exit code is zero. No crashed worker is restarted.

The runtime allocates ports and checks package pins before starting its host,
then checks TCP listeners concurrently and verifies boot identities concurrently.
These phases preserve their dependency order. ADR 0012 replaces the unconditional
multi-port settle with a boot-bound all-started receipt and per-port identity;
the matching receipt vouches for every co-located port (ADR 0014), and a foreign identity remains a refusal. Other process
and external service declarations retain their ordered environment dependencies; ADR 0015
lets a later twin declaration start once the host's addresses are allocated.
Returned services and environment merging retain declaration order.

The owner prohibits automated tests and walks in this coding lane. This source
decision does not claim a timing improvement. Main-push CI publishes the runtime
under the procedure in CONTRIBUTING.md (ADR 0013); the card's independent review
checks the published package in the unchanged application recipe.
