Counterparty Reliance Unwind Lens / 相对方信赖撤回 Lens

This lens observes whether 相对方信赖撤回线 and 相对方信赖撤回机制 correctly make sunk reliance playable after a false-clean or overbroad authority is corrected.

The current mesh already knows how to read old authority. 播出合约回读线 prevents a prior contract row from becoming universal permission. 回叫消费证明线 prevents relief with an owed callback from becoming clean closure. 裁定读者冲突线 separates incompatible readers. 复原追偿搁架线 names future recourse holders.

The gap this lens targets is later and more practical: a counterparty already acted because the authority looked clean. A sponsor paid. An archive released a copy. A worker carrier exposed testimony. A claimant waived or claimed a right. A route-asset custodian moved an asset. A public delegate published a receipt. The game must now decide what happens to that reliance action without letting it prove the old source was clean.

Current executable chain

The first source-backed producer is the Seat Map Annotation false default. storyteller.event.false_seat_map_annotation_default.v1 records a false-clean group-consent reading, then arms the later reliance entry. The sponsor recap desk schedules a group-consent recap against that seat map, recap slot time is sunk, and the protected caption-access patron reader is displaced.

The observable runtime chain is:

runtime_chain:
  upstream_default: storyteller.event.false_seat_map_annotation_default.v1
  entry_event: storyteller.event.counterparty_reliance_discovered.v1
  ledger: storyteller.card.counterparty_reliance_ledger.v1
  strict_rite: storyteller.rite.reliance_unwind_conference.v1
  durable_default: storyteller.event.false_reliance_default.v1
  downstream_callable_source_for: storyteller.card.recall_claim_priority_queue.v1
  branch_count: 8
  exact_required_slot_count: 12

The lens still permits other false-clean producers. This one is the executable proof that the generic boundary can be instantiated without turning sponsor scheduling into consent authority.

This lens observes:

It is observed through:

Observable promise

Reliance is not retroactive proof.

When a counterparty has already acted on a false-clean or overbroad authority, implementation must prove:

  • which source authority row induced reliance;
  • what clean or overbroad claim was presented;
  • who relied on it;
  • what action was already taken;
  • what sunk surface now exists;
  • who was harmed, displaced, or explicitly absent;
  • what proof bridge exists or why it is absent;
  • what unwind posture is selected;
  • what cost, boundary, scope, hostility, quarantine, or default follows;
  • how a future reader or route consumes the reliance state.

The lens fails if the result is only sponsor relied, archive accepted, public believed, worker signed, claimant waived, route opened, management closed, or broadcast reality accepted.

Entry oracle

A valid implementation opens only from live state pressure:

entry_state_required:
  trigger_kind: state_pressure
  source_authority_row_present: true
  source_authority_kind: seat_map_annotation_afteruse | broadcast_readback | callback_consumption | sponsor_afteruse | recovery_indemnity | broadcast_signatory | asset_provenance | settlement_aftershock | equivalent
  clean_or_overbroad_claim_present: true
  relying_counterparty_present: true
  reliance_action_already_taken: true
  sunk_surface_visible: true
  harmed_or_displaced_reader_present_or_explicit_absence: true
  future_reader_or_route_effect_possible: true
  player_can_honor_reimburse_convert_escrow_clawback_publish_quarantine_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The lens must fail if entry comes from fixed turn count, day/week interval, chapter quota, raw contract count, raw callback count, raw crisis count, dashboard state, lens health, generic sponsor anger, generic legal review, generic aftermath, or a clean report phase with no reliance action already taken.

For the current runtime, the entry oracle additionally requires all three upstream Seat Map states — seat_map_annotation.default_recorded, seat_map_annotation.state.false_clean_default, and seat_map_annotation.future.recovery_only — plus counterparty_reliance.entry_pending. The real jury floorplan, seat-map docket, protected patron row, Jao Min proof docket, Jao Min custody badge, and Chapter Two future reader must all be in hand. The entry must reject a missing or arbitrary same-type substitute.

Ledger oracle

相对方信赖账本 or equivalent must record:

ledger_required:
  source_authority:
    source_row_id: <stable id or explicit_absence>
    source_surface: audience_jury_seat_map_annotation_afteruse | broadcast_contract_readback | callback_consumption | sponsor_afteruse | recovery_indemnity | broadcast_signatory | asset_provenance | settlement_aftershock | equivalent
    source_state_before: accepted_inside_scope | accepted_with_addendum | split_required | callback_required | public_only | lawful_only | sponsor_only | escrowed | quarantined | false_clean | explicit_absence | equivalent
    clean_or_overbroad_claim: <claim>
    proof_bridge_or_absence: readback_docket | callback_docket | sponsor_release | archive_stamp | public_receipt | edit_checksum | route_asset_copy | explicit_absence | equivalent
  relying_counterparty:
    counterparty_kind: sponsor | archive_queue | lawful_reader | public_delegate | fan_table | claimant_row | worker_carrier | route_asset_custodian | management | editor | pirate_relay | equivalent
    counterparty_id_or_absence: <id or explicit_absence>
    reliance_action_taken: paid | scheduled | aired | released_copy | moved_witness | accepted_custody | waived_claim | promised_route | exposed_worker | published_receipt | equivalent
    sunk_surface: money | slot_time | witness_safety | custody_copy | public_trust | sponsor_package | worker_testimony | claimant_body | route_asset | producer_license | equivalent
    reliance_state_before: pending | spent | exposed | captured | hostile | protected | disputed | explicit_absence | equivalent
  displaced_reader:
    harmed_or_displaced_reader: public | lawful_reader | sponsor | archive | artist_boundary | fan_public | claimant | worker | route_asset | broadcast_reality | explicit_absence | equivalent
    harm_or_displacement: cost_shift | custody_loss | proof_loss | public_misread | callback_erased | signature_implied | route_asset_captured | worker_exposed | claimant_burdened | equivalent
  selected_unwind:
    posture: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance | false_reliance_default
    accepted_cost_surface_or_absence: money | sponsor_heat | archive_debt | public_distrust | inspection_heat | producer_license_encumbrance | handler_burden | route_delay | explicit_absence | equivalent
    future_reader_effect: accepted_with_reliance_cost | public_only | lawful_only | sponsor_only | split_required | contradiction_pending | blocked | hostile | recovery_only | false_reliance_hardened | equivalent

The lens fails if the ledger lacks source authority, clean claim, relying counterparty, reliance action, sunk surface, harmed/displaced reader, unwind posture, cost, or future effect.

Conference oracle

信赖撤回会 or equivalent must require explicit assignments:

assignment_required:
  ledger: storyteller.card.counterparty_reliance_ledger.v1
  source_authority_row: <row id or explicit_absence>
  source_surface: <source surface>
  clean_or_overbroad_claim: <claim>
  relying_counterparty: <counterparty>
  reliance_action_taken: <action>
  sunk_surface: <surface>
  harmed_or_displaced_reader: <reader or explicit_absence>
  proof_bridge_or_absence: <proof or explicit_absence>
  handler_or_absence: producer | shen_luo | yu_lan | han_yanshuang | baiya | sponsor_counsel | archive_clerk | public_delegate | worker_carrier | claimant_representative | explicit_absence | equivalent
  support_or_absence: money | sponsor_release | public_bulletin | lawful_annex | archive_escrow | worker_protection | route_asset_return | claimant_receipt | explicit_absence | equivalent
  selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance | false_reliance_default
  accepted_cost_surface_or_absence: <cost or explicit_absence>
  future_reader_effect: <effect>

The lens fails if sponsor money, archive approval, public sympathy, lawful language, edit checksum, management urgency, famous handler, or broadcast reality erases the reliance without these assignments.

The first runtime rite must expose exactly twelve strict slots: ledger, false group-consent claim, sponsor recap counterparty, already-scheduled recap action, sunk recap slot, source floorplan, source seat-map docket, protected displaced reader, Jao Min proof bridge, Jao Min handler, matching posture bundle, and Chapter Two reader. Exact accepts, in-hand ownership, selected-option presence, and option/posture matching are mandatory. Each branch posture card carries the accepted cost and future-reader effect for that branch.

Branch divergence oracle

A satisfying implementation must prove at least six branch families, including one default or quarantine branch.

Branch familyRequired reliefRequired costRequired future effect
Honor limited reliancecounterparty remains usable or route pressure fallsscope boundary, public distrust, sponsor heat, archive debt, or route costaccepted-with-cost, public-only, lawful-only, sponsor-only
Reimburse and unwindfalse-clean claim or displaced-reader pressure fallsmoney, producer license encumbrance, route delay, or handler burdenaccepted-with-cost, costlier, contradiction-pending
Convert to scoped licensecurrent route partly openssource ambiguity, correction pressure, or reader splitpublic-only, lawful-only, sponsor-only, split-required
Escrow relianceunsafe clean citation is blockedroute delay, archive debt, or inspection heatblocked, lawful-only, recovery-only
Clawback with noticeoverbroad benefit is removed visiblycounterparty hostility, sponsor pressure, or public distrusthostile, contradiction-pending, recovery-only
Publish reliance debthidden reliance becomes public/lawful/archive memorypublic confusion, sponsor pressure, or inspection heataccepted-with-cost, split-required, contradiction-pending
Quarantine reliancefraud, worker exposure, or false-owner pressure fallscurrent route blocks and recovery cost risesblocked, recovery-only
False reliance defaultimmediate pressure may dropfalse reliance hardens and displaced reader hostility risesfalse-reliance-hardened, hostile, blocked, recovery-only

The first runtime implementation fixes one exact cost/effect bundle per branch:

Runtime branch IDAccepted costFuture-reader effect
honor_limited_reliancereader_scope_narrowingaccepted_with_reliance_cost
reimburse_and_unwindproducer_license_encumbrancecontradiction_pending
convert_to_scoped_licensesource_ambiguitysponsor_only
escrow_relianceroute_delayrecovery_only
clawback_with_noticecounterparty_hostilityhostile
publish_reliance_debtpublic_confusionsplit_required
quarantine_reliancerecovery_costblocked
false_reliance_defaultfalse_reliance_hardenedrecovery_only

No branch may produce clean acceptance across public, lawful, sponsor, archive, worker, claimant, route asset, management, producer-license, and broadcast-reality readers.

Default oracle

虚洁净信赖默认 or equivalent must fire or be armed when:

  • a reliance action is hidden while future routes consume the benefit;
  • reliance action is treated as proof that the source authority was clean;
  • source authority is hidden or summarized as clean;
  • the relying counterparty is hidden;
  • the sunk surface is hidden;
  • the harmed or displaced reader is hidden without explicit absence;
  • the proof bridge is missing without explicit absence;
  • a worker, claimant, public delegate, or route asset is treated as silent carrier;
  • clawback or waiver proceeds without notice, receipt, compensation path, or named harm;
  • management files reliance as closed while future reader effect remains possible.

Required default payload:

default_required:
  event: storyteller.event.false_reliance_default.v1
  source_authority:
    source_row_id: <stable id or explicit_absence>
    source_surface: <surface or explicit_absence>
    clean_or_overbroad_claim: <claim or explicit_absence>
  reliance:
    relying_counterparty: <counterparty or explicit_absence>
    reliance_action_taken: <action or explicit_absence>
    sunk_surface: <surface or explicit_absence>
  hidden_damage:
    harmed_or_displaced_reader: <reader or explicit_absence>
    harm_or_displacement: <harm or explicit_absence>
  default_capture:
    default_actor: relying_counterparty | sponsor | archive | management | public_table | lawful_reader | route_asset | editor | broadcast_reality | producer_license | claimant | worker | equivalent
    false_reliance_claim: <claim>
    reliance_state_after: false_owner | hostile | captured | accepted_as_clean | coerced | recovery_only | contradiction_pending | equivalent
    future_reader_effect: false_reliance_hardened | blocked | hostile | contradiction_pending | public_only | lawful_only | sponsor_only | split_required | recovery_only | equivalent

The lens fails if default produces clean reset, generic bad state, or route failure without source authority, relying counterparty, sunk surface, displaced reader, false claim, and future effect.

Downstream consumption oracle

The content is not complete until at least one later reader consumes the reliance state.

Every runtime result arms recall_claim_priority.counterparty_reliance_pending. The current downstream consumer is storyteller.rite.recall_claim_priority_hearing.v1, reached through storyteller.card.recall_claim_priority_queue.v1, whose callable-source metadata names storyteller.card.counterparty_reliance_ledger.v1.

Valid consumers include:

  • public reader consuming a published reliance debt;
  • lawful reader requiring annex or proof rehearing;
  • sponsor reader accepting only sponsor-scoped reliance;
  • archive reader refusing a missing bridge;
  • worker or claimant reader becoming protected, hostile, or recovery-only;
  • route asset reader requiring return, escrow, or quarantine;
  • management reader losing clean closure;
  • broadcast reality hardening or contesting the relied version.

Passing effects include:

  • accepted_with_reliance_cost;
  • public_only;
  • lawful_only;
  • sponsor_only;
  • split_required;
  • contradiction_pending;
  • blocked;
  • hostile;
  • recovery_only;
  • false_reliance_hardened.

Oracle assertions

A check should fail unless all assertions below are true.

  1. Primary links exist — the lens has populated observes and observed_through arrays pointing to concrete Storyteller pages.
  2. State entry is non-sequential — the surface opens from reliance action already taken, not fixed count, interval, chapter quota, dashboard, or lens health.
  3. Source authority is visible — source row, source surface, source state, clean or overbroad claim, and proof bridge or explicit absence are recorded.
  4. Reliance is concrete — relying counterparty, action already taken, sunk surface, and reliance state are visible.
  5. Harm is assigned — harmed or displaced reader and harm/displacement are visible or explicitly absent with cost.
  6. Conference is assignable — handler, proof bridge, support, selected unwind, cost, and future effect are required.
  7. Branches diverge — honor, reimbursement, scoped license, escrow, clawback, publication, quarantine, and default cannot collapse into one clean result.
  8. Success has cost or boundary — any branch that preserves reliance must narrow scope, spend resource, publish debt, escrow proof, delay route, or raise pressure.
  9. Reliance is not proof — no branch may let the reliance action prove the source authority was universally clean.
  10. Default is durable — invalid reliance creates 虚洁净信赖默认 with actor, false claim, sunk surface, displaced reader, and future scar.
  11. Downstream reader consumes state — at least one future route or reader reads ledger_state_after or future_reader_effect.
  12. No forbidden trigger — no fixed turn, day, week, raw count, dashboard, or lens-health trigger.
  13. First producer is source-backed — the entry reads the Seat Map false-default flags and six exact surviving source cards.
  14. Runtime conference is strict — all twelve exact cards must be in hand and the selected option must match its posture bundle.
  15. Runtime handoff is durable — every result arms recall_claim_priority.counterparty_reliance_pending, and the existing priority queue accepts the exact ledger ID.
  16. Replay paths are independent — reimbursement and false-default evidence begin from ordinary runtime state and cannot share an injected checkpoint.

Replay evidence expectation

The anticipated independent evidence files are:

  • lens/replays/counterparty-reliance-unwind.reimburse.replay.json;
  • lens/replays/counterparty-reliance-unwind.false-default.replay.json.
lens_id: storyteller.lens.counterparty_reliance_unwind.v1
session_id: lens-counterparty-reliance-unwind-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_authority_row_present: true
  clean_or_overbroad_claim_present: true
  relying_counterparty_present: true
  reliance_action_already_taken: true
  sunk_surface_visible: true
  harmed_or_displaced_reader_present_or_explicit_absence: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
offered:
  card: storyteller.card.counterparty_reliance_ledger.v1
  rite: storyteller.rite.reliance_unwind_conference.v1
branch_runs:
  constructive_branch:
    selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance
    ledger_state_after: <state>
    relying_counterparty_state_after: <state>
    displaced_reader_state_after: <state>
    future_reader_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
  default_branch:
    selected_unwind: false_reliance_default
    event_seen_or_armed: storyteller.event.false_reliance_default.v1
    false_reliance_claim: <claim>
    default_actor: <actor>
    future_reader_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
downstream_read:
  reader: public | lawful_reader | sponsor | archive | claimant | worker | route_asset | management | broadcast_reality | equivalent
  consumed_state: <ledger_state_after>
  route_effect_after_read: <effect>
assertions:
  - primary_links_exist
  - entry_is_state_triggered_from_reliance_action_already_taken
  - source_authority_visible
  - reliance_action_and_sunk_surface_visible
  - displaced_reader_visible_or_explicit_absence
  - conference_assignment_complete
  - branches_diverge
  - every_success_has_cost_or_scope_boundary
  - reliance_not_clean_proof
  - false_reliance_default_durable
  - downstream_reader_consumes_reliance_state
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Non-goals

  • Not a new verdict.
  • Not a generic indemnity ledger.
  • Not a settlement epilogue.
  • Not raw content growth.
  • Not a fixed-turn aftermath.
  • Not a replacement for readback, callback, reader collision, claimant intake, signatory counterclaim, asset provenance, or indemnity shelf.
  • Not valid if nobody has already changed position in reliance.
  • Not valid if future route offers remain identical after resolution.