Review follow-up: the boot lock's mkdir/os.open ran in the context manager's __enter__, outside the body's try/except, so a read-only runtimes dir or a foreign-owned boot.lock raised OSError out of ensure_local_runtime — the function main documented as never raising into session start. Catch OSError around acquisition, warn, and yield unlocked (the contention-timeout shape).