CS-09 Duplicate Cue Hardening / CS-09 重复提示固化

Trigger

The event becomes eligible only after accept_duplicate_execution_default sets cue_sheet_initials.default_pending. Its core-compatible trigger has priority 95, and a resolved-event guard prevents recurrence.

Before the event:

  • F-27 has one genuine physical execution receipt;
  • R6 carries two flattened EXECUTE:F-27:RN tokens;
  • the second token has reached the physical bus;
  • the false second movement has not yet been classified.

Outcome A — Trip after partial travel

The emergency interlock catches the second pulse after 280 mm.

Relief:

  • the body-clear zone is restored;
  • full second travel is prevented;
  • both motor-current edges remain measurable.

Cost:

  • the aired recovery contains a set-position discontinuity;
  • the rail needs a manual reset;
  • every restart must present both actuation receipts;
  • operator burden and future-route cost persist.

Durable future effect: manual_reset_and_dual_receipt_required.

Outcome B — Complete second travel

The scenery completes the second movement and the recovery cut airs it.

Relief:

  • the immediate broadcast slot survives;
  • the physical result is no longer ambiguous.

Cost:

  • F-27 now has two physical actuation receipts in one epoch;
  • rail safety decreases;
  • correction duty and public accountability rise;
  • future reruns inherit a movement that was never called twice.

Durable future effect: double_fire_version_fork_required.

Shared irreversible scar

Both outcomes set duplicate_execution_scar. An interlock trip does not make the second pulse nonexistent: partial travel is still a physical execution attempt with measurable motion. Completing the travel does not make the two RN tokens legitimate. Recovery must preserve what moved, when, and under which epoch.

Both outcomes unset the pending trigger, set event_resolved for this event, and cannot retrigger.

Broadcast-reality consequence

If the false second movement is aired, later route readers can treat the doubled scenery path as canonical stage history. Recovery therefore needs either a manual reset with dual receipts or a named version fork that distinguishes the called-once source performance from the double-fired broadcast version.

Authority boundary

The event records physical chronology and execution count. It does not determine caller identity from initials, caller authority, authorship, performer consent, rigging clearance, edit permission, sponsor clearance, archive ownership, blame, or universal broadcast permission.

Runtime source

game-content/storyteller/events/false-cue-sheet-initials-afteruse-default.json5