payloadOfExactlyTheBudgetIsCarried
A payload of exactly Seam.maxPayloadBytes crosses. Sent with broadcast so the obligation does not also depend on SeamCapabilities.supportsSendTo.
This is the edge a fabric gets wrong by publishing a number bigger than its wire really takes — the frame is then refused by the fabric's own machinery, at a limit the caller could not see and did not agree to. null means unknown, so a fabric that names nothing skips: it promised nothing to break.
Both ends are checked (#2601), and each reads its OWN published number. maxPayloadBytes is declared on Seam, so a role-split fabric publishes it twice, from two implementations, and the two need not agree: a LinkSeam joiner forwards its connection's maxFrameBytes while a MeshSeam host folds every ply's. A joiner whose own number overstates its own wire is invisible to any assertion that sends the host's budget, which is what this row did.
The joiner phase gates on joiner.maxPayloadBytes separately, for the same reason the row gates on the host's: a fabric whose joiner names nothing has promised nothing on that end. payloadBudgetObligationIsTrackedWhenUnpublished reads the host, so an end that publishes nothing would be a silent skip — this row's own gating shape, one end over, and #2601's named failure mode. It is measured rather than assumed: a probe reversing the gate (red when the joiner does publish) named every harness that reaches these arms — TcpConformanceTest (16777215 B), NwConformanceTest (jvm and macosArm64), NwBridgeLoopbackConformanceTest and NwLoopbackConformanceTest (16777216 B) — and the complementary probe (red when the host publishes and the joiner does not) reddened nothing, so no in-tree fabric is asymmetric and no joiner arm is silently skipped. Widening the accountability hook to both ends is its own change; asserting symmetry here would make this row depend on a contract claim Seam does not make, which is the prescription #2601's terminal-state slice refused.
Where the joiner arm can fail. Nothing in a fixture carries a frame — the at-budget payload has to traverse the joiner's own outbound framing, which is where a fabric truncates, splits, or refuses at a ceiling one byte below the one it published. On a harness whose two ends share one in-process backend both directions run the same code and the arm is weak (joinerRosterOrigin records that shape); every harness that actually reaches these arms is real-IO — a TCP socket or Network.framework, role-split or loopback — so the joiner's write path is its own.