1cf3639813
Follow-ups on the salvaged #97797 transport: - Blocker 2 from the #97681 exact-head review claimed near-expiry refresh silently mints against the target's CURRENT policy. On this head the handler DOES refuse drift (_require_unchanged_execution_policy -> 403 room_reauthorization_required), but nothing pinned the handler-level behavior: removing the drift check still passed the entire grants suite (the check was only unit-tested in isolation). New HTTP-level regression test drives /v1/room-members/grants/refresh with a drifted-policy grant and requires the 403; sabotage-verified (check removed -> test fails). - cancel() conflict resolution: keeps our race-retry routing loop from #99099 with this layer's peer-stop acknowledgement body inside it (peer receipt -> settle completion -> local interrupt escalation). - docs: NAT one-way-reachability note in bot-mode.md — Desktop is a viewer, not a relay; put room authority on the host everyone can reach (field finding from /bin/bash on #97681).