# Co-located readiness follows an all-started receipt

Status: Accepted. Date: 2026-09-30. Card t_94bcd252, task t_a330be32.
Supersedes ADR 0011's unconditional multi-port settle.

The owner asks that World startup retain only true serial dependencies. A
listening port and its boot identity do not prove that the co-located host has
finished starting every factory. The previous runtime therefore waited 300 ms
even when every twin had already started. A timer is a guess about that state.

The runtime names a private readiness file unique to its boot. After every
factory has returned and each actual port has been validated against its
requested port, the host CLI registers shutdown handlers and publishes an
atomic receipt containing the boot identity and complete port map. Publication
failure stops the host. The receipt never substitutes for TCP or identity probes.

The runtime awaits that exact receipt with a wall-clock deadline, boot
cancellation and host-exit observation. Its boot and complete port set must
match. Only then do TCP and per-port identity checks complete admission. A
matching identity can end its own settle early because no factory startup is
still pending. A foreign identity is still refused. ADR 0014 removes the shared
host guard for twins without an identity: the matching receipt already proves
the host bound every port.

This changes a lifecycle dependency rather than a vendor's behavior. Process
services retain their existing port confirmation. The bounded parallel starts
and rollback from ADR 0011 remain. World boot remains above the native app
reference; no latency is claimed before the independent published-build review.
The coding lane runs no tests or walks by the owner's rule. Runtime publication
follows main-push CI (CONTRIBUTING.md, ADR 0013).
