joinerRosterOrigin

Where this harness's joiner gets the remote peer in its Seam.peers — i.e. whether the joiner half of peersReportsSelfIdAndAtLeastTwoAfterJoin can fail here at all.

Abstract on purpose, and non-nullable — there is no default arm. A default would be an "I cannot reach this state" opt-out, and an opt-out moves the vacuity one level up where it is harder to see: the next fabric added would inherit whichever arm the base picked without anyone deciding, which is precisely how #2591 stayed invisible. Two arms, no default, forces the one sentence of thought that catches it — would this obligation still be green if my join path did nothing? JoinerRosterOrigin carries the full argument and states what each arm cannot detect.

This is a harness fact, not a fabric SeamCapabilities flag: the same fabric folded into one process declares JoinerRosterOrigin.FilledByConstruction while its two-device deployment would be JoinerRosterOrigin.TheJoinPath. Nothing about the transport changes; only what the fixture can prove does. joinerRosterOriginIsDeclaredAndHonest charges each arm the price of a sentence — the declaration itself is not machine-checkable, and that KDoc says why.