Common-Source Corroboration Audit Lens / 同源佐证审计 Lens
This lens observes whether 同源佐证审计线 and 同源佐证审计机制 distinguish six authentic derivative surfaces from six independent origins.
The oracle is:
A report, checksum, archive copy, memorial-voice sample, public clip, and carrier receipt may all be real while contributing only one independent root. Surface count, holder count, format count, signature count, and rebroadcast count are not source-family count.
The lens fails if the implementation merely labels the packet corroborated, assigns a high-rank handler, proves that copies match, proves that a carrier moved one copy, or records that the public repeated the clip. It must expose and consume the lineage graph.
1. Primary binding oracle
The bound pack consists of:
- 同源佐证审计线;
- 同源佐证审计机制 with canonical ID
storyteller.mechanic.broadcast_proof_lineage_independence.v1; - 同源佐证证据行;
- 同源佐证复核;
- 证据谱系冲突;
- 自证广播默认.
Runtime evidence must come only from source: storyteller objects carrying this lens ID and the local authority boundary.
2. Seven exact cards oracle
review_assignments:
lineage_docket: storyteller.card.proof_lineage_docket.v1
inspector_report: storyteller.card.inspector_report_lineage_row.v1
editor_checksum: storyteller.card.editor_checksum_lineage_row.v1
archive_copy: storyteller.card.archive_copy_lineage_row.v1
memorial_voice: storyteller.card.memorial_voice_lineage_row.v1
public_clip: storyteller.card.public_clip_lineage_row.v1
carrier_receipt: storyteller.card.carrier_receipt_lineage_row.v1The seven roles are non-substitutable:
- the docket carries requested use, apparent count, root count, harmed reader, selected posture, and future effect;
- the inspector row proves only that a named clip received a named inspection procedure;
- the checksum row proves only bit continuity with the named last-air edit;
- the archive row proves only custody after intake;
- the memorial row proves only derivation from the archived copy;
- the public clip proves distribution and reception, not independent witness count;
- the carrier receipt proves transfer, not content truth.
The lens fails if a generic evidence card, selected-posture card, authority stamp, sponsor object, or duplicate lineage card fills one of the slots.
3. Source-family schema oracle
Every lineage row must expose these exact semantic fields or an explicit equivalent:
proof_lineage_row_required:
rowCardId: storyteller.card.<lineage-row>.v1
proofId: <stable proof row id>
apparentSourceId: <stable apparent source id>
surfaceKind: inspector_report | editor_checksum | archive_copy | memorial_voice | public_clip | carrier_receipt
sourceFamilyId: family.lyra.last-air-edit.017
lineageRootId: slot.last_air_edit
rootSourceIdOrExplicitAbsence: slot.last_air_edit | explicit_absence
parentCopyIdOrAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
parentSourceIdOrExplicitAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
custodian: <named inspector editor archivist memorial desk fan public or carrier>
custodianOrExplicitAbsence: <same named custodian or explicit_absence>
derivationKind: inspector_summary | checksum | archive_copy | memorial_mix | public_clip | carrier_receipt
originFingerprintOrExplicitAbsence: sha256:lyra-last-air-edit-017 | explicit_absence
claimFragment: <exact proposition traced through this row>
authorityScope: inspection | editor_continuity | archive_custody | memorial_voice | public_receipt | carrier_transfer
captureOrIssueTime: <stable time row>
versionId: <stable version id>
futureReaderOrRoute: reader.memorial-archive-route-clearance
harmedReaderOrClaimantIfOvercounted: lyra_voice_and_memorial_route_claimant
provesScope: <one exact local proposition>
doesNotProve: [<explicit denied authorities>]
independenceState: shared_root
localAuthorityOnly: trueThe current concrete packet must additionally expose:
concrete_lineage_summary:
requestedUse: authorize_memorial_voice_archive_route_as_independently_verified
requestedCorroboratedClaim: the_named_voice_phrase_has_six_independent_confirmations_for_memorial_archive_route_use
futureReader: reader.memorial-archive-route-clearance
harmedFutureReaderOrRoute: reader.memorial-archive-route-clearance
lineageRootId: slot.last_air_edit
sourceSessionIdOrAbsence: session.lyra.last-air-edit.017
claimedCorroborationCount: 6
apparentSourceCount: 6
distinctLineageRootCount: 1
establishedRootCount: 1
unknownRootCount: 0
circularFamilyCount: 0
circularFamilyCountAfterFalseBroadcast: 1
corroborationWeightBeforeReview: 6
corroborationWeightIfDisclosed: 1
independentWeightAllowed: 1
overcountedWeight: 5
independenceStateBefore: common_root_unreviewed
broadcastClaimStatus: proposedThe exact values make the causal conflict testable. A pass cannot rely only on generic provenance present metadata.
4. Intake oracle
intake:
rite_id: storyteller.rite.common_source_corroboration_intake.v1
repeatable: false
choice: 0
option_id: record_common_source_collision
assignments:
inspector_report: storyteller.card.inspector_report_lineage_row.v1
editor_checksum: storyteller.card.editor_checksum_lineage_row.v1
archive_copy: storyteller.card.archive_copy_lineage_row.v1
public_clip: storyteller.card.public_clip_lineage_row.v1
required_outputs:
- common_source_corroboration.intake_recorded
- common_source_corroboration.pressure.inspector_report_visible
- common_source_corroboration.pressure.editor_checksum_visible
- common_source_corroboration.pressure.archive_copy_visible
- common_source_corroboration.pressure.public_clip_visible
required_counter_deltas:
lineageIntakeProgress: 2
institutionalCopyVisibility: 3
claimedCorroborationPressure: 2
sourceIndependenceUncertainty: 2The intake must succeed only with its four exact cards in hand, exact slots, and selected option. It must fail with one missing card, a substituted archive/public row, no option, or after resolving once.
Intake does not open the review directly and does not set any branch, terminal, aired, or default flag.
5. Entry event oracle
entry:
event_id: storyteller.event.proof_lineage_collision.v1
option: 0
option_id: open_common_source_corroboration_review
requires_all_five_intake_flags: true
requires_all_seven_cards_in_hand: true
required_outputs:
- common_source_corroboration.collision_opened
- common_source_corroboration.pressure.shared_lineage_root_visible
- common_source_corroboration.pressure.independence_unproven
- common_source_corroboration.state.review_pending
required_counter_deltas:
proofLineagePressure: 3
sourceIndependenceUncertainty: 2
memorialVoiceExposure: 1
futureRouteReliancePressure: 2The event must fail before intake, with any intake flag missing, with any of the seven cards absent, or after it resolves once. It opens lineage review; it does not declare fraud, resolve independence, or arm the default.
6. Review gate oracle
storyteller.rite.common_source_corroboration_review.v1 is nonrepeatable. It must require all seven exact assigned cards in hand plus all nine gate flags:
review_gate_flags:
- common_source_corroboration.intake_recorded
- common_source_corroboration.pressure.inspector_report_visible
- common_source_corroboration.pressure.editor_checksum_visible
- common_source_corroboration.pressure.archive_copy_visible
- common_source_corroboration.pressure.public_clip_visible
- common_source_corroboration.collision_opened
- common_source_corroboration.pressure.shared_lineage_root_visible
- common_source_corroboration.pressure.independence_unproven
- common_source_corroboration.state.review_pendingThe lens fails if the review opens from starter-card availability, a raw source count, a fixed turn/day/week, dashboard state, lens health, generic provenance metadata, or an unrelated rite.
7. Exactly seven branch oracle
| Choice | Branch | State after | Future route effect |
|---|---|---|---|
| 0 | commission_distinct_origin_capture | distinct_origin_capture_commissioned | distinct_origin_capture_required_before_clean_corroboration |
| 1 | disclose_common_source | common_source_disclosed | corroboration_weight_capped_at_one |
| 2 | split_by_authority | authority_scopes_split | reader_specific_proof_required |
| 3 | reopen_root_capture | root_capture_reopened | root_capture_required_before_route_unlock |
| 4 | quarantine_memorial_voice_use | memorial_voice_quarantined | memorial_voice_use_blocked_pending_lineage |
| 5 | publish_lineage_notice | lineage_notice_published | public_lineage_addendum_required |
| 6 | false_independent_corroboration | false_independent_corroboration_pending | self_corroborating_broadcast_default_pending |
disclose_common_source must record the reduction from six apparent sources to one allowed root as corroborationWeightReduction:+5. Each option must independently set:
- clear
common_source_corroboration.state.review_pending; - exactly one
common_source_corroboration.branch.<branch>flag; - exactly one
common_source_corroboration.state.<state>flag; - exactly one
future_route.<future-effect>flag; common_source_corroboration.review_resolved;- exactly four declared counter deltas.
The first six branches make the default unreachable. Only choice 6 may set the harmful gate:
harmful_gate:
common_source_corroboration.state.false_independent_corroboration_pending: true
common_source_corroboration.default_pending: true
event.self_corroborating_broadcast_default.armed: true
future_route.self_corroborating_broadcast_default_pending: true
broadcast_reality.false_independent_corroboration_aired: trueNo branch may produce two lineage states, two future effects, or universal proof authority.
8. Reachability and missability oracle
All seven review choices must resolve from the same exact post-collision packet. Focused evidence must prove negative gates for missing flags, missing cards, substitutions, wrong slots, out-of-hand assignments, absent choice, and repeat resolution.
Because review is once-only:
- each selected branch makes the other six missable for the incident;
- choices 0–5 make the self-corroborating default permanently missable;
- choice 6 makes constructive resolution missable and opens exactly one default event.
Catalog visibility or a successfully parsed rite does not prove branch reachability.
9. Exactly three terminal oracle
自证广播默认 exposes exactly three options:
| Choice | Terminal | State after | Future route effect |
|---|---|---|---|
| 0 | record_circular_proof_scar | circular_proof_scar_recorded | future_routes_require_distinct_lineage_roots |
| 1 | force_root_source_reaudit | root_source_reaudit_required | root_source_reaudit_required_before_memorial_or_archive_use |
| 2 | freeze_derived_route_assets | derived_route_assets_frozen | derived_route_assets_recovery_only_until_lineage_rebuilt |
The default event metadata must record circularFamilyCountAfterFalseBroadcast: 1; the pre-broadcast docket remains circularFamilyCount: 0.
Every terminal must:
- clear
common_source_corroboration.state.false_independent_corroboration_pending; - clear the exact three pending/armed/future flags;
- clear
broadcast_reality.false_independent_corroboration_aired; - set
common_source_corroboration.default_resolved; - set
common_source_corroboration.self_corroboration_scar; - set exactly one terminal state and its matching future effect;
- set exactly four declared counter deltas;
- resolve the event and prevent retrigger.
Selecting one terminal makes the other two missable. The scar remains even though the live aired flag clears.
10. Five-action replay oracle
lens/replays/common-source-corroboration-audit.false-multiplicity-default.replay.json must contain exactly five actions in order:
- lens-scoped
createwithsource: storyteller; - intake
end_turnwith four exact assignments and choice 0record_common_source_collision; - entry
event_choiceforstoryteller.event.proof_lineage_collision.v1, option 0open_common_source_corroboration_review; - review
end_turnwith seven exact assignments and choice 6false_independent_corroboration; - default
event_choiceforstoryteller.event.self_corroborating_broadcast_default.v1, option 0record_circular_proof_scar.
Acceptance requires:
replay_final_required:
schema: loremaster.replay.v1
generated_by: game-cli
source: storyteller
lens_id: storyteller-lens-common-source-corroboration-audit-v1
seed: common-source-corroboration-20260718a
integrity_schema: loremaster.replay.integrity.v1
integrity_algorithm: sha256
action_count: 5
common_source_corroboration.default_pending: false
event.self_corroborating_broadcast_default.armed: false
future_route.self_corroborating_broadcast_default_pending: false
broadcast_reality.false_independent_corroboration_aired: false
common_source_corroboration.default_resolved: true
common_source_corroboration.self_corroboration_scar: true
common_source_corroboration.state.circular_proof_scar_recorded: true
future_route.future_routes_require_distinct_lineage_roots: true
exactly_one_terminal_state: true
exactly_one_terminal_future_effect: true
latest_state_matches_final_action: true
unresolved_target_event: falseA replay that stops after review proves only harmful-branch reachability, not default closure.
11. Authority boundary oracle
The packet tracks lineage roots and derivative relationships only. It requires distinct roots for independent corroboration and preserves inspection, editor, archive, memorial, public, and carrier scopes.
It explicitly does not grant:
- underlying event truth;
- independent corroboration without distinct roots;
- universal inspector all-clear;
- editor source truth;
- archive pre-intake origin;
- memorial-voice consent;
- voice custody;
- route-asset content truth;
- public-clip independent witness status;
- sponsor immunity;
- universal broadcast authority.
Authentic derivatives remain authentic within their named scopes. The lens fails if lack of independence automatically destroys custody history or if authenticity automatically creates independent weight.
12. Exact non-overlap oracle
| Neighboring lens | It passes by proving | This lens cannot borrow as a substitute |
|---|---|---|
| Broadcast Asset Provenance Afterlife | which derivative copy owns or serves a future route | copy custody or ownership does not determine independent root count |
| Broadcast Reality Drift Audit | an aired version conflicts with later proof and receives reconciliation | the six rows may agree; contradiction is not required for lineage dependence |
| Custody Oracle Crossread | concrete oracles give scoped answers to an already-scarred custody state | selecting an oracle does not prove its inputs have independent roots |
| Reader Recusal Record | a conflicted reader is disclosed, replaced, split, or defaulted | a neutral reader can still consume dependent evidence |
| Recap Syndication Drift | fragment scope and omitted recap scars remain visible | a complete copy can still share one root; completeness is not independence |
| Operator Witness Conclave | conflicting low-rank operator rows and dissent remain separate | all six lineage rows can agree because one upstream source supplied the agreement |
| Ruling Reader Collision | incompatible readers consume one source with scoped results | this lens counts roots behind several apparent sources supporting one requested claim |
| Proof Board Snapshot Custody | hidden, stale, summarized, ordered, or omitted board rows remain visible | a complete accurate board can still falsely count six derivatives as six roots |
13. Progress metric
commonSourceCorroborationAuditProgress = 0..10:
0: no requested corroborated claim or lineage row exists.1: four apparent cross-desk surfaces are assignable to intake.2: exact intake resolves and records five intake flags.3: all seven cards expose a shared root and distinct authority scopes.4: Proof Lineage Collision resolves and sets four review flags.5: seven-card review becomes assignable only through all nine gates.6: all seven branches are independently reachable and exclusive.7: constructive branches preserve authenticity while scoping independence.8: only false independent corroboration arms the harmful gate.9: exactly one terminal clears the gate and preserves the scar.10: the five-action integrity replay reexecutes with final-state parity.
Non-goals
- Not a generic provenance score.
- Not a raw evidence-count milestone.
- Not an automatic rule that derivatives are false.
- Not a board, recusal, witness-disagreement, reader-collision, fragment, custody, or drift substitute.
- Not a universal proof, consent, clearance, ownership, or broadcast-authority mechanism.
- Not valid without future-route consumption and durable branch/default state.