Volter World

Co-located readiness follows an all-started receipt

Status: Accepted. Date: 2026-09-30. Card t_94bcd252, task t_a330be32. Supersedes ADR 0011's unconditional multi-port settle.

The owner asks that World startup retain only true serial dependencies. A listening port and its boot identity do not prove that the co-located host has finished starting every factory. The previous runtime therefore waited 300 ms even when every twin had already started. A timer is a guess about that state.

The runtime names a private readiness file unique to its boot. After every factory has returned and each actual port has been validated against its requested port, the host CLI registers shutdown handlers and publishes an atomic receipt containing the boot identity and complete port map. Publication failure stops the host. The receipt never substitutes for TCP or identity probes.

The runtime awaits that exact receipt with a wall-clock deadline, boot cancellation and host-exit observation. Its boot and complete port set must match. Only then do TCP and per-port identity checks complete admission. A matching identity can end its own settle early because no factory startup is still pending. A foreign identity is still refused. ADR 0014 removes the shared host guard for twins without an identity: the matching receipt already proves the host bound every port.

This changes a lifecycle dependency rather than a vendor's behavior. Process services retain their existing port confirmation. The bounded parallel starts and rollback from ADR 0011 remain. World boot remains above the native app reference; no latency is claimed before the independent published-build review. The coding lane runs no tests or walks by the owner's rule. Runtime publication follows main-push CI (CONTRIBUTING.md, ADR 0013).

View Markdown source