A marker cookie is a tiny flag you can read before starting a session. Its only job is to decide whether to start a server-side session at all. Normally PHP has to start a session before it can tell whether one is needed — and starting a session sends Set-Cookie plus no-cache headers, which makes the response uncacheable. A separate plain cookie (just a presence flag, holding no auth value) lets the app ask "is this maybe-logged-in visitor worth a session?" before it touches any session machinery. Anonymous visitors carry no marker, so they get no session and fully cacheable pages. The real login state stays server-side in $_SESSION.
In Lamb (bootstrap.php), should_start_session() returns true only if lamb_logged_in or LAMBSESSID is present. The marker holds a random UUID that's stored nowhere on the server. Losing it doesn't log you out (the server session still has you), and having it doesn't keep you logged in (an expired session gives you an empty $_SESSION). It's a caching gate, not authentication.
should_start_session() and the one call site that uses its result. Confirm an anonymous request never reaches session_start().
Done when: you can name the file/line where the decision is made and what happens on each branch.curl -I and check there's no Set-Cookie and no no-store; then with the marker cookie present, confirm both appear.
Done when: you have two curl -I outputs side by side showing the header difference.