## Summary
Adding a second member interface to an existing bond re-assigns the bond's MAC address to that new member. The bond changes its identity on the wire, breaking ARP/ND and LACP for peers that already learned it.
## Steps to reproduce
```
set interfaces bonding bond0 mode 802.3ad
set interfaces bonding bond0 member interface eth1
commit
run show interfaces bonding bond0 # note link/ether of bond0
run show interfaces bonding bond0 slaves
Interface RX: bytes packets TX: bytes packets
bond0 0 0 0 0
eth1 0 0 0 0
```
```
set interfaces bonding bond0 member interface eth2
commit
run show interfaces bonding bond0 # link/ether is now eth2's MAC
run show interfaces bonding bond0 slaves
Interface RX: bytes packets TX: bytes packets
bond0 0 0 0 0
eth2 0 0 0 0
```
## Actual
`bond0` and `eth2` share `aa:c1:ab:c3:62:48`; the address the bond had from `eth1` is gone.
If both bond members are added simultanously, no issue exists.
## Expected
`bond0` keeps the MAC it adopted at creation time. Appending a member must not change it, nor remove it from the slave list.
T7571 made the bond adopt its first member's MAC, since newer kernels assign a synthetic one. In `BondIf.update()` the driving flag is initialised `True` unconditionally, and an already enslaved member hits continue without clearing it, so the adoption re-runs on every append.