CS-09 Execution Idempotency Lens / CS-09 提示执行幂等 Lens

Lens question

Can the implementation prove that F-27 already executed once, distinguish Rowan Neri’s RN standby mark from Rhea Noll’s RN execution mark, prevent a lossy R6 import from firing it twice, and preserve the physical scar if prevention fails?

The lens fails if it turns this into a generic signature, authority, consent, custody, cue-overwrite, stale-instruction, or rigging-clearance story.

1. Distinct seam boundary

Passing evidence must state all of the following:

  • cue text CS-09 was not overwritten;
  • both marks are genuine;
  • two different callers and caller keys share RN;
  • one mark means PREPARED and has no physical receipt;
  • one mark means EXECUTED and has exactly one physical receipt;
  • recovery removes source layer, phase, caller key, and receipt;
  • the fault is replay of a consumed physical command, not broad use of an old annotation.

Nearby cue-sheet overwrite, cue-card pencil, prompt-book errata, stale dispatch, cue custody, fly-rail safety, and apparent-signature lanes must be named as non-equivalent.

2. Exact source tuple

The packet must expose eight physical evidence cards:

  1. CS-09 initial-collision docket;
  2. white standby master;
  3. yellow execution carbon;
  4. RN/RN caller handoff roster;
  5. headset and cue-light timecode;
  6. flattened R6 ingest trace;
  7. F-27 physical rail execution receipt;
  8. R6 double-pulse recovery route.

Every card must be starter-reachable, carry this lens ID and source lens path, and be local-authority-only. No selected-branch pseudo-card or virtual slot placeholder is permitted.

3. Exact runtime reachability

The rite must require:

  • eight have.card conditions;
  • eight required slots;
  • exactly one accepted card ID per slot;
  • every assigned card in the current hand;
  • an explicit valid option;
  • the selected option’s exact slot map;
  • repeatable false.

Wrong, duplicate, missing, catalog-only, out-of-hand, omitted-choice, invalid-choice, and selected-option-mismatch attempts must fail without setting completion or branch flags. After one successful resolution, the rite must no longer satisfy conditions or remain available.

4. At-most-once invariant

execution_invariant:
  cue_instance: F-27 / R6
  valid_transition: UNSEEN -> PREPARED -> EXECUTED
  physical_receipts_before_review: 1
  hold_resets_execution: false
  handoff_resets_execution: false
  recovery_import_resets_execution: false
  constructive_branch_max_execution_count: 1
  default_execution_count: 2

The displayed initials RN cannot participate in the stable execution key.

5. Eight branches diverge

The rite must execute all eight branches:

BranchRequired execution stateRequired future effect
bind_single_execution_chronologysingle_execution_chronology_boundcue_instance_checksum_required
cancel_queued_duplicate_pulseduplicate_pulse_cancelled_execution_unprovenmanual_execution_readback_required
rekey_callers_and_reissue_bundleunique_caller_keys_reissuedunique_operator_key_required
split_prepared_and_executed_registersprepared_executed_registers_splitstate_transition_schema_required
lift_and_separate_carbon_layerscarbon_layers_lifted_trace_consumednew_source_stack_required
divert_duplicate_pulse_to_dry_run_sinkduplicate_pulse_diverted_to_sinkdry_run_sink_attestation_required
manual_rail_recall_before_restartmanual_rail_recall_completedoperator_witness_before_restart_required
accept_duplicate_execution_defaultduplicate_execution_pendingduplicate_execution_default_pending

Each branch must carry relief, cost, at least three declared counter deltas, matching executable counter effects, and a unique state/future pair.

6. Destructive evidence is visible

The carbon-lift branch passes only when it raises chronology integrity while lowering source-layer integrity, raising evidence-trace loss, and requiring a new source stack. Stronger proof cannot silently preserve the physical evidence it consumed.

7. Default is executable and closed

The default branch must arm cue_sheet_initials.default_pending. The event must:

  • use trigger.condition true;
  • have priority 95;
  • require the pending flag;
  • exclude its resolved-event flag;
  • expose stable outcomes trip_after_partial_travel and complete_second_travel;
  • unset pending and set duplicate_execution_scar on both outcomes;
  • emit different future effects and counter states;
  • become ineligible after either outcome.

A generic recovery_only marker is insufficient. The event must preserve partial or complete second physical travel.

8. Authority boundary

The docket, rite, and event must structurally assert:

provesExecutionChronologyForNamedCueInstanceOnly: true
grantsCallerAuthorship: false
grantsCurrentCallerAuthority: false
grantsPerformerConsent: false
grantsRiggingSafetyClearance: false
grantsEditReusePermission: false
grantsSponsorClearance: false
grantsArchiveOwnership: false
grantsUniversalBroadcastPermission: false

No branch or runtime result may set any denied authority flag.

9. Canon boundary

All focused card, rite, event, Wiki, lens binding, test, session, and replay surfaces must remain inside source storyteller: the corporate broadcast-reality world of callers, crews, automation, performers, inspectors, sponsors, editors, and route assets. Foreign-canon names are a hard failure.

10. Durable evidence

The gameplay CLI replay must:

  • use a lens-prefixed Storyteller session;
  • put all eight exact lens cards in the current hand;
  • assign each card once to its exact slot;
  • resolve this rite as the first end-turn target with choice 0;
  • set complete for the non-repeatable rite;
  • set bind_single_execution_chronology, single_execution_chronology_bound, and cue_instance_checksum_required;
  • omit the completed rite from latest available rites;
  • pass replay integrity verification.

The session manifest, actions, and state files must remain present. Default closure is proved in the focused runtime test rather than inferred from an unrelated global event queue.

Evidence paths

  • Runtime cards: game-content/storyteller/cards/cue-sheet-initials-afteruse-docket.json5
  • Runtime rite: game-content/storyteller/rites/cue-sheet-initials-afteruse-review.json5
  • Runtime event: game-content/storyteller/events/false-cue-sheet-initials-afteruse-default.json5
  • Runtime test: lens/storyteller-cue-sheet-initials-afteruse.runtime.test.ts
  • Replay: lens/replays/cue-sheet-initials-afteruse-receipt.certify.replay.json
  • Evaluator: scripts/evaluate_lenses.mjs

Progress metric

Satisfied only when authored and public objects deep-match uniquely, the focused Jest test passes all branch and rejection cases, the source-only canon scan passes, the non-repeatable rite closes, both default outcomes execute and close, and the fresh replay proves exact in-hand choice-0 resolution with no virtual cards.