Box Office Stamp Pad Impression Provenance Lens / 票房印台印迹溯源 Lens
This lens observes whether a historical receipt impression remains properly bounded when a reusable box-office ink pad is re-inked or replaced. It must expose the upstream intake, the state-triggered challenge, all seven review postures, the false-continuity default, and durable terminal cleanup without confusing impression provenance with authorization of the underlying transaction.
1. Canon and non-overlap oracle
All eleven observed objects and all canonical pages are source: storyteller. Content from any other source is forbidden from satisfying an oracle.
| Adjacent surface | Its authority | Stamp-pad lens authority |
|---|---|---|
| Box-office comp stamp | one comp-seat relief authorization | historical pad impression provenance only |
| Claimant stamp | notice or representation scope | historical pad impression provenance only |
| Refund-window name correction | corrected identity and refund acceptance | historical pad impression provenance only |
| Box-office ticket stub | one named admission | historical pad impression provenance only |
The lens fails if any unrelated prop, venue record, performer claim, or receipt lane substitutes for the pad/impression/changeover question.
2. Exact object-set oracle
The binding contains exactly eleven game objects:
storyteller.card.box_office_stamp_pad_afteruse_docket.v1;storyteller.card.box_office_stamp_pad_source_impression.v1;storyteller.card.box_office_stamp_pad_original_ink_profile.v1;storyteller.card.box_office_stamp_pad_afteruse_request.v1;storyteller.card.box_office_stamp_pad_changeover_trace.v1;storyteller.card.box_office_stamp_pad_challenged_patron.v1;storyteller.card.box_office_stamp_pad_future_receipt_verifier.v1;storyteller.rite.box_office_stamp_pad_impression_intake.v1;storyteller.event.box_office_stamp_pad_impression_challenge.v1;storyteller.rite.box_office_stamp_pad_afteruse_review.v1;storyteller.event.false_stamp_pad_afteruse_default.v1.
Generic state labels, counters, dashboard rows, or adjacent-lane cards must not inflate this list.
3. Intake oracle
The first gameplay transition after lens-scoped creation is an end_turn for storyteller.rite.box_office_stamp_pad_impression_intake.v1.
| Exact slot | Exact card |
|---|---|
source_impression | storyteller.card.box_office_stamp_pad_source_impression.v1 |
original_ink_profile | storyteller.card.box_office_stamp_pad_original_ink_profile.v1 |
changeover_trace | storyteller.card.box_office_stamp_pad_changeover_trace.v1 |
challenged_patron | storyteller.card.box_office_stamp_pad_challenged_patron.v1 |
The selected option must be record_impression_changeover_conflict. It sets box_office_stamp_pad.intake_recorded plus the four exact visibility pressures for source impression, original ink profile, re-ink/changeover, and challenged patron. Missing a card, assigning the wrong slot, omitting the option, or possessing the cards without resolving intake must fail.
4. Entry oracle
storyteller.event.box_office_stamp_pad_impression_challenge.v1 becomes reachable only after intake and all four intake pressure flags while all seven lane cards remain in hand. Its open_forensic_impression_review option sets only:
box_office_stamp_pad.impression_challenge_opened;box_office_stamp_pad.pressure.current_pad_identity_unproven;box_office_stamp_pad.state.forensic_review_pending.
The lens must demonstrate that deleting any intake flag or removing any lane card blocks entry. A fixed turn, elapsed day, raw stamp count, incomplete card bundle, generic queue pressure, dashboard, or lens-health state must not open it.
5. Seven-card review oracle
The review requires all intake and entry flags plus these seven exact assignments:
| Exact slot | Exact card |
|---|---|
afteruse_docket | storyteller.card.box_office_stamp_pad_afteruse_docket.v1 |
source_impression | storyteller.card.box_office_stamp_pad_source_impression.v1 |
original_ink_profile | storyteller.card.box_office_stamp_pad_original_ink_profile.v1 |
afteruse_request | storyteller.card.box_office_stamp_pad_afteruse_request.v1 |
changeover_trace | storyteller.card.box_office_stamp_pad_changeover_trace.v1 |
challenged_patron | storyteller.card.box_office_stamp_pad_challenged_patron.v1 |
future_receipt_verifier | storyteller.card.box_office_stamp_pad_future_receipt_verifier.v1 |
All assignments must be in hand, all slots are exact, one option is required, and the rite cannot repeat after resolution.
6. Branch divergence oracle
Each ordered review choice must independently leave one state and one future route effect:
| Choice | State after | Future route effect |
|---|---|---|
certify_source_impression | source_impression_certified | source_impression_may_support_named_refund |
bind_impression_to_ink_batch | ink_batch_bound | matching_ink_batch_required |
split_pre_and_post_reink_claims | pre_post_reink_split | post_reink_receipts_require_new_profile |
reopen_pad_access_log | pad_access_log_reopened | current_access_holder_signoff_required |
publish_pad_changeover_notice | changeover_notice_published | changeover_notice_required_before_recap |
quarantine_unmatched_impression | unmatched_impression_quarantined | impression_quarantined_until_match |
false_current_pad_continuity_default | false_current_pad_continuity_pending | false_stamp_pad_afteruse_default_pending |
The first six branches make the false-default route missable. Only choice index 6, false_current_pad_continuity_default, may set the pending triple and broadcast_reality.false_stamp_pad_continuity_claim_aired.
7. Reachability, missability, and negative-gate oracle
The observable surface must prove all of the following:
- intake succeeds with exactly four cards, four slots, and its selected option;
- intake fails with one card missing, one slot substituted, or no option;
- entry succeeds only after intake with all seven lane cards in hand, and fails when any intake pressure or lane card is removed;
- review succeeds only after entry, with seven assigned cards in hand and one selected branch;
- review fails before intake, before entry, with any pressure missing, with one wrong slot, with one absent card, or with no choice;
- each constructive branch resolves the review and permanently misses the false-default event;
- the false branch becomes durable only after a separate terminal event choice;
- the default fails when any pending member, the aired flag, false-pending state, or unresolved condition is absent.
No branch may leave two review states or two future effects true at once.
8. Default closure oracle
storyteller.event.false_stamp_pad_afteruse_default.v1 exposes exactly three terminals:
| Terminal choice | Durable state | Durable future effect |
|---|---|---|
record_false_pad_continuity | false_current_pad_continuity | future_receipts_require_continuity_challenge |
force_forensic_reimpression | current_pad_retest_required | forensic_reimpression_required_before_recap |
restore_challenged_patron | challenged_patron_restored | patron_refund_restoration_required |
Every outcome clears the pending triple, aired flag, and false-pending state; sets the resolved-event flag; preserves box_office_stamp_pad.false_continuity_scar; and leaves exactly one terminal state plus one matching future effect. The event cannot retrigger.
9. Five-action replay oracle
lens/replays/box-office-stamp-pad-afteruse.default.replay.json must contain exactly five actions in this order:
- lens-scoped
createwithsource: storyteller; - intake
end_turnwith four exact assignments andrecord_impression_changeover_conflict; - challenge
event_choicewithopen_forensic_impression_review; - review
end_turnwith seven exact assignments and choice6; - default
event_choicewith one terminal option.
Acceptance requires integrity and session evidence, no pending or aired flag left true, the false-continuity scar, exactly one terminal state, one matching future effect, and parity with the latest session state. A replay that stops after review proves only false-branch reachability.
10. Docket and authority oracle
The docket must expose source impression id and timestamp, source receipt or absence, original pad and ink batch or absence, colour, density, edge wear, fibre bleed, access holder, re-ink/changeover trace, current pad/batch/profile or absence, requested afteruse, future verifier, challenged patron, proof bridge, selected posture, forensic state, future effect, and counter deltas.
The packet proves only a historical impression profile. It denies current pad identity, refund validity, patron consent, sponsor immunity, clean public recap, archive ownership, voice custody, and universal box-office authority.