A client upgrade can leave lifecycle capability unavailable despite matching the recommended version. Investigating how signed rollout settings, native hook verification, root binding and long-lived MCP authorization interact, and which read-only checks distinguish the causes.