f7e0ae2aff
Answers the open review ask on #109359 with the corrected contract: a hung remote add_memory is bounded by the SDK timeout (empirically 1.03s at timeout=1.0, max_retries=0), so shutdown's flush waiting on the capture lock is bounded, not forever. The guard: while the worker owns the write (blocked inside add_memory), a concurrent shutdown must wait and must not re-send the same pending batch. Mutation-checked: lock -> nullcontext makes this test and the session-switch interleaving test fail.