F1 — `ConnectionReconnectOptions.random?: () => number` lets callers
inject a deterministic source for backoff jitter, threaded through
`computeBackoffDelay`. Default remains `Math.random` so existing apps
are unaffected. Test covers maxAttempts, the new random injection (jitter
+max and -max clamped to minDelay), the disabled case and the
disposed/intentional-close gate.
F2 — `runAuth()` singleflight in the connection request runtime: when an
auth round is in flight, every concurrent caller awaits the same promise,
so only one auth frame goes on the wire. Closes the gap where
`session.changed` + `session.external_changed` could land back-to-back
and produce two auth frames. Tested at the request-runtime level with
fake ack registry + sender (integration-level testing of this through
the mock transport is timing-flaky and adds no extra coverage).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>