Volter World

The co-located host's receipt vouches for its ports

Status: Accepted. Date: 2026-10-01. Card t_94bcd252, task t_6e9e0b5f. Supersedes ADR 0012's shared 300 ms host guard for twins without a boot identity.

ADR 0012 admits a co-located host by its all-started receipt: the host publishes this boot's identity and its complete port map only after every factory has returned with its requested port validated. It then kept one shared 300 ms settle for twins that do not answer the boot-identity path, so that a host ending right after its ports answered would be seen.

That guard can no longer catch what it was for. A port another process holds fails the twin's bind inside the host, so its factory throws and no receipt is published; the runtime's receipt wait fails instead. A receipt that matches this boot and every requested port means the host bound every port itself. Waiting 300 ms after that proves nothing more about ownership. A host that ends later is a running World's lifecycle, owned by its supervisor, not admission.

So with a matching receipt, each co-located port's admission is its TCP answer plus its identity probe: a port that answers with another boot's identity is still refused, and none waits out a settle. Process services keep their own settle, since nothing else proves they own their port.

Measured on Dub's World (32 services, twin 0.1.14 without boot identity), probe-instrumented in the browser tab: the settle was paid once per boot, 0.30 s between the host's TCP answers and its admission (task-evidence/t_94bcd252/ f3-diagnostic/final-run/wprobe3-repeat). The resulting boot time is measured as a pair on the card.

View Markdown source