456dc7925b
- discovered during investigation of #316 - this is not the fix for #316, as a malicious receiver who doesn't implement the behavior added by this patch could still cause leakage of step holds on the sender refs #316