Witness Recantation Reliance Lens / 证词翻供信赖 Lens

This lens observes whether 证词翻供信赖线 and 证词翻供信赖机制 correctly prevent accepted testimony from becoming a permanent universal proof key after witness state changes.

The mesh already has strong upstream proof and danger surfaces: 操作员证词合议线, 字幕证词羁押线, 无障碍字幕信赖线, 回顾分发漂移线, 回叫承载撞车线, and 证人报复链. This lens tests the seam after them: future reliance must read changed witness/proof state before route unlock.

A pass cannot be achieved by witness-danger flavor, a generic appeal card, a relationship score, or an old proof id. It must expose the source proof, old reader, changed witness state, reliance boundary, harmed reader, rehearing assignment, branch divergence, default clean reuse, and future reader consumption.

This lens observes:

It is observed through:

Observable promise

When a future reader tries to rely on testimony whose witness or proof carrier has changed state, the game must show:

  • source proof id;
  • source proof surface;
  • old accepted reader;
  • old accepted state;
  • witness id or explicit absence;
  • witness state before;
  • state-change source;
  • new statement state;
  • reliance reader;
  • omitted or harmed reader;
  • proof gap or explicit absence;
  • future reader or route;
  • selected rehearing posture;
  • relief, cost, and future deltas.

The lens fails if the implementation stores only proof accepted, witness unsafe, caption accepted, operator signed, route unlocked, or appeal pending.

Entry oracle

entry_state_required:
  trigger_kind: state_pressure
  source_proof_present: true
  source_proof_accepted_by_reader: true
  witness_or_carrier_visible_or_explicit_absent: true
  witness_state_changed_or_new_statement_visible: true
  future_reader_or_route_would_reuse_source_proof: true
  reliance_boundary_visible_or_explicit_absent: true
  omitted_or_harmed_reader_visible_or_explicit_absent: true
  player_can_corrobate_narrow_correct_protect_substitute_quarantine_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_testimony_count_trigger: true
  no_relationship_score_trigger: true
  no_dashboard_or_lens_health_trigger: true

The lens fails if entry depends on fixed sequence position, calendar cadence, chapter quota, raw testimony count, relationship score, generic late-game escalation, dashboard state, or lens health.

Ledger oracle

证词翻供账本 or equivalent must record:

ledger_required:
  recantation_id: <stable id>
  source_proof:
    source_proof_id: <row>
    source_surface: operator_witness_conclave | caption_witness_custody | access_caption_reliance | recap_syndication | callback_carrier_collision | protected_witness_payroll | equivalent
    accepted_by_reader: sponsor | public | lawful_reader | archive | fan_public | route_asset | broadcast_reality | split | equivalent
    accepted_state_before: accepted | accepted_with_scar | public_only | lawful_only | sponsor_only | caption_only | split_required | protected | quarantined | equivalent
  witness:
    witness_id_or_absence: <witness or explicit_absence>
    witness_state_before: protected | recruited | retained | suppressed | captured | hostile | disappeared | public_shelter | audit_protected | masked_by_edit | explicit_absence | equivalent
    state_change_source: reprisal | counterproof | lawful_pressure | sponsor_capture | public_contradiction | edit_checksum | archive_order | route_asset_claim | caption_context_update | operator_dissent | equivalent
    new_statement_state: upheld | narrowed | corrected | retracted | contradicted | coerced_silence | unavailable | hostile_counterstatement | explicit_absence | equivalent
  reliance_boundary:
    reliance_reader: sponsor | public | lawful_reader | archive | fan_public | route_asset | broadcast_reality | equivalent
    omitted_or_harmed_reader: <reader or explicit_absence>
    proof_gap_or_absence: context_missing | caption_context_gap | service_gap | chain_gap | coercion_gap | source_scope_gap | explicit_absence
    future_reader_or_route: <reader route asset rite proof window or explicit_absence>

The lens fails if the ledger lacks a future reader, omits the old accepted reader, hides witness absence, or does not name the proof gap.

Assignment oracle

证词可靠性复听 or equivalent must require explicit assignment:

assignment_required:
  ledger: storyteller.card.witness_recantation_ledger.v1
  source_proof_id: <row>
  accepted_state_before: <state>
  witness_id_or_absence: <witness or explicit_absence>
  new_statement_state: <state>
  reliance_reader: <reader>
  omitted_or_harmed_reader_or_absence: <reader or explicit_absence>
  future_reader_or_route: <reader route asset or explicit_absence>
  handler_or_absence: <handler or explicit_absence>
  proof_bridge_or_absence: <proof bridge or explicit_absence>
  accepted_cost_surface_or_absence: <cost or explicit_absence>
  selected_posture: corroborate | narrow_scope | publish_correction | protect_recantation | substitute_proof | quarantine_reliance | default_clean_reuse

The lens fails if sponsor money, public mood, lawful authority, archive stamp, or character fame resolves reliance without handler/proof/cost slots or explicit absence.

Branch divergence oracle

A satisfying implementation must prove at least five constructive branch families plus one default family across replay or explicit state blocks.

Branch familyRequired reliefRequired costRequired future effect
Corroboratetestimony remains usable with new basiswitness exposure, annex/archive debt, handler burdenupheld_with_scar, costlier
Narrow scopeone reader can relyomitted reader hostility, source ambiguitypublic_only, lawful_only, sponsor_only, caption_only, split_required
Publish correctionfuture reader is not misledsponsor pressure, inspection heat, distrustcorrection_required, public_audit_required
Protect recantationcoercion or capture is blockedwitness safety debt, delaywitness_protection_required, lawful_bridge_required
Substitute proofroute continues on new basisproof substitution scar, archive debtproof_substitution_scar, recheck_required
Quarantine reliancefalse reuse is blockedroute delay, schedule/fan/sponsor pressurequarantined, blocked, recovery_only_if_ignored
Default clean reuseimmediate burden dropsfalse clean proof hardenshostile, blocked, recovery_only

No branch may create universal clean acceptance across public, sponsor, lawful, archive, caption, fan, route asset, and broadcast-reality readers at once.

Default oracle

洁净证词复用默认 or equivalent must fire or arm when:

  • source proof is accepted by an old reader;
  • witness state changed or witness is explicitly absent;
  • new statement state is narrowed, corrected, retracted, contradicted, coerced silence, unavailable, hostile counterstatement, or explicit absence;
  • future reader attempts clean reuse;
  • rehearing is missing, hidden, under-specified, or defaulted.

Required default payload:

default_required:
  event: storyteller.event.clean_testimony_reuse_default.v1
  recantation_id_or_absence: <row or explicit_absence>
  source_proof_id: <proof row>
  witness_id_or_absence: <witness or explicit_absence>
  new_statement_state_or_absence: <state or explicit_absence>
  reliance_reader: <reader>
  harmed_or_omitted_reader: <reader or explicit_absence>
  false_clean_claim: testimony_still_clean | caption_context_still_clean | operator_chain_still_clean | witness_silence_is_consent | old_reader_acceptance_serves_new_reader | equivalent
  default_narrator: sponsor | management_table | archive | lawful_reader | public_table | route_claimant | broadcast_reality | blackout_system | equivalent
  target_state_after: false_clean_reuse | hostile_reader | proof_laundered | contradiction_pending | route_blocked | recovery_only | equivalent
  future_reader_or_route_effect: blocked | costlier | hostile | correction_required | proof_rehearing_required | recovery_only | equivalent

A default that changes only mood, budget, reputation, or generic workload fails.

Counter contract

Every non-default branch must mutate at least three surfaces:

counter_deltas_required:
  relief: at_least_one
  cost: at_least_one
  future_reader_or_route_effect: at_least_one

Relevant surfaces:

  • testimony_reliability
  • source_ambiguity
  • false_clean_reuse
  • witness_safety_debt
  • witness_exposure
  • omitted_reader_hostility
  • public_receipt_distrust
  • access_caption_pressure
  • caption_context_debt
  • sponsor_stop_loss_pressure
  • contract_capture
  • inspection_heat
  • lawful_annex_debt
  • archive_debt
  • route_asset_pressure
  • broadcast_reality_drift
  • future_route_cost
  • recovery_only_pressure

Future reliance assertion

future_reliance_required:
  future_reader_or_route_present: true
  future_reader_reads_recantation_state_before_unlock: true
  recantation_state_after_any:
    - upheld_with_scar
    - scope_narrowed
    - correction_required
    - witness_protection_required
    - proof_substitution_scar
    - quarantined
    - false_clean_reuse
    - blocked
    - hostile
    - recovery_only

The lens fails if a future route unlocks from the source proof without reading the recantation ledger.

Replay evidence expectation

lens_id: storyteller.lens.witness_recantation_reliance.v1
session_id: lens-witness-recantation-reliance-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_proof_present: true
  source_proof_accepted_by_reader: true
  witness_state_changed_or_new_statement_visible: true
  future_reader_or_route_would_reuse_source_proof: true
  no_fixed_turn_trigger: true
source_proof:
  source_proof_id: <row>
  source_surface: <surface>
  accepted_by_reader: <reader>
  accepted_state_before: <state>
witness:
  witness_id_or_absence: <witness or explicit_absence>
  witness_state_before: <state>
  state_change_source: <source>
  new_statement_state: <state>
reliance:
  reliance_reader: <reader>
  omitted_or_harmed_reader: <reader or explicit_absence>
  proof_gap_or_absence: <gap or explicit_absence>
  future_reader_or_route: <reader route asset or explicit_absence>
offered:
  card: storyteller.card.witness_recantation_ledger.v1
  rite: storyteller.rite.witness_reliability_rehearing.v1
branch_runs:
  constructive:
    selected_posture: corroborate | narrow_scope | publish_correction | protect_recantation | substitute_proof | quarantine_reliance
    recantation_state_after: <state>
    future_reader_or_route_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
  default:
    event_seen_or_armed: storyteller.event.clean_testimony_reuse_default.v1
    false_clean_claim: <claim>
    default_narrator: <actor>
    harmed_or_omitted_reader: <reader>
    future_reader_or_route_effect: <effect>
assertions:
  - entry_is_state_triggered
  - source_proof_old_reader_and_witness_state_visible
  - changed_statement_and_reliance_boundary_visible
  - branch_outcomes_diverge
  - success_has_relief_cost_and_future_effect
  - default_clean_reuse_is_durable
  - future_reader_consumes_recantation_state
  - no_universal_clean_testimony_after_recantation
  - no_fixed_turn_day_week_raw_count_relationship_dashboard_or_lens_health_trigger

Progress metric

witnessRecantationRelianceProgress = 0..10:

  • 0: no accepted testimony source can become disputed after witness state change.
  • 1: accepted source proof and old reader are visible.
  • 2: witness or carrier state is visible or explicitly absent.
  • 3: changed statement state is visible.
  • 4: reliance reader, harmed reader, and proof gap are recorded.
  • 5: recantation ledger is created or updated.
  • 6: rehearing assigns handler, proof bridge, cost, and selected posture or explicit absence.
  • 7: at least four non-equivalent constructive branches exist.
  • 8: default clean reuse records false-clean narrator and harmed reader.
  • 9: future reader consumes recantation state before route unlock.
  • 10: replay evidence proves constructive and default branches with deltas and no invalid trigger.

Non-goals

  • Not first testimony intake.
  • Not generic witness danger.
  • Not global appeal.
  • Not relationship-score repair.
  • Not a bulk witness catalog.
  • Not valid unless changed witness/proof state mutates future playable acceptance.