Box Office Stamp Pad Impression Provenance / 票房印台印迹溯源机制
This mechanism compares a historical ink impression with a reusable physical pad across a documented re-ink or pad-changeover window. It asks which impression profile can be attributed to which pad state at which time. It does not decide whether the underlying refund, comp, claimant notice, or admission was authorized.
Evidence separation
box_office_evidence_boundaries:
comp_stamp: seat_relief_authorization
claimant_stamp: notice_or_representation_scope
refund_name_correction: corrected_identity_and_acceptance
ticket_stub: named_admission
stamp_pad_impression: historical_impression_profile_within_named_changeover_windowA matching ink profile does not validate a refund; a valid refund does not identify the pad that made its impression.
Forensic provenance tuple
stamp_pad_impression_provenance:
source_impression_id: required
source_impression_timestamp: required
source_receipt_or_absence: required
original_pad_id_or_absence: required
original_ink_batch_or_absence: required
original_ink_profile:
colour: required
density: required
edge_wear: required
fibre_bleed: required
original_access_holder_or_absence: required
reink_or_pad_changeover_window: required
changeover_actor_or_absence: required
current_pad_id_or_absence: required
current_ink_batch_or_absence: required
current_impression_profile_or_absence: required
requested_afteruse: required
future_receipt_verifier: required
challenged_patron: requiredAn absent value is evidence of a gap, not permission to infer continuity. Desk location, stamp design, or matching text cannot replace pad identity, ink profile, access custody, or changeover time.
State machine
four exact intake cards
-> impression intake end_turn + record_impression_changeover_conflict
-> intake_recorded + four intake pressure flags
-> impression challenge event_choice
-> impression_challenge_opened + current_pad_identity_unproven + forensic_review_pending
-> exact seven-card nonrepeatable review end_turn
-> one constructive state/future pair
OR false_current_pad_continuity_pending + pending triple + aired claim
-> if false: exact default event_choice
-> pending and aired flags cleared + false_continuity_scar preserved
-> exactly one durable terminal state + exactly one matching future effectIntake contract
storyteller.rite.box_office_stamp_pad_impression_intake.v1 is the required upstream gameplay rite:
slots:
source_impression: storyteller.card.box_office_stamp_pad_source_impression.v1
original_ink_profile: storyteller.card.box_office_stamp_pad_original_ink_profile.v1
changeover_trace: storyteller.card.box_office_stamp_pad_changeover_trace.v1
challenged_patron: storyteller.card.box_office_stamp_pad_challenged_patron.v1
option: record_impression_changeover_conflict
sets:
box_office_stamp_pad.intake_recorded: true
box_office_stamp_pad.pressure.source_impression_visible: true
box_office_stamp_pad.pressure.original_ink_profile_visible: true
box_office_stamp_pad.pressure.reink_or_changeover_visible: true
box_office_stamp_pad.pressure.challenged_patron_visible: trueThe intake resolves through end_turn, requires all four assigned cards in hand, and requires its selected option. It does not set the challenge-opened, current-pad-unproven, or forensic-review-pending flags.
Entry contract
storyteller.event.box_office_stamp_pad_impression_challenge.v1 requires intake_recorded, all four intake pressure flags, and all seven lane cards in hand. Its stable option open_forensic_impression_review sets:
box_office_stamp_pad.impression_challenge_opened: true
box_office_stamp_pad.pressure.current_pad_identity_unproven: true
box_office_stamp_pad.state.forensic_review_pending: trueFixed turns, elapsed days, raw stamp counts, generic queue pressure, card possession without intake, dashboard state, or lens health are forbidden substitutes.
Review contract
storyteller.rite.box_office_stamp_pad_afteruse_review.v1 requires the intake flag; all five pressure flags; impression_challenge_opened; forensic_review_pending; and all seven exact assigned cards.
| Branch | Forensic state | Future effect |
|---|---|---|
certify_source_impression | source_impression_certified | source_impression_may_support_named_refund |
bind_impression_to_ink_batch | ink_batch_bound | matching_ink_batch_required |
split_pre_and_post_reink_claims | pre_post_reink_split | post_reink_receipts_require_new_profile |
reopen_pad_access_log | pad_access_log_reopened | current_access_holder_signoff_required |
publish_pad_changeover_notice | changeover_notice_published | changeover_notice_required_before_recap |
quarantine_unmatched_impression | unmatched_impression_quarantined | impression_quarantined_until_match |
false_current_pad_continuity_default | false_current_pad_continuity_pending | false_stamp_pad_afteruse_default_pending |
Only choice 6 may set box_office_stamp_pad.default_pending, event.false_stamp_pad_afteruse_default.armed, future_route.false_stamp_pad_afteruse_default_pending, and broadcast_reality.false_stamp_pad_continuity_claim_aired.
Default closure contract
storyteller.event.false_stamp_pad_afteruse_default.v1 requires the pending triple, aired claim, false-pending state, and unresolved event. It exposes exactly three stable terminals:
| Choice | Terminal state | Future effect |
|---|---|---|
record_false_pad_continuity | false_current_pad_continuity | future_receipts_require_continuity_challenge |
force_forensic_reimpression | current_pad_retest_required | forensic_reimpression_required_before_recap |
restore_challenged_patron | challenged_patron_restored | patron_refund_restoration_required |
Every option clears the pending triple, aired flag, and false-pending state. It sets box_office_stamp_pad.false_continuity_scar, resolves the event, and leaves exactly one terminal state with one matching future effect.
Negative gates
The mechanism fails if any of the following succeeds:
- resolving intake without all four exact cards, exact slots, cards in hand, or its selected option;
- opening the challenge before
intake_recorded, with any intake pressure flag missing, or without all seven lane cards in hand; - opening review before the challenge event, without intake, or with any pressure flag missing;
- reviewing with a wrong slot, a card absent from hand, or no selected choice;
- arming the default from any constructive branch;
- firing the default without any member of the pending triple, the aired flag, or false-pending state;
- leaving two forensic states or two terminal future effects true at once;
- treating a matching impression as current pad identity, refund validity, patron consent, sponsor immunity, clean recap, or archive ownership.
Replay acceptance
The durable replay contains exactly five actions in order:
- lens-scoped
createwithsource: storyteller; end_turnforstoryteller.rite.box_office_stamp_pad_impression_intake.v1with four exact assignments andrecord_impression_changeover_conflict;event_choiceforstoryteller.event.box_office_stamp_pad_impression_challenge.v1andopen_forensic_impression_review;end_turnforstoryteller.rite.box_office_stamp_pad_afteruse_review.v1with seven exact assignments and choice6;event_choiceforstoryteller.event.false_stamp_pad_afteruse_default.v1selecting one terminal.
The replay is incomplete if it ends at the aired claim, retains any pending flag, omits the false-continuity scar, or differs from its latest session state.
Authority boundary
This mechanism proves only a historical impression profile inside a named forensic comparison window. It grants no current pad identity, refund validity, patron consent, sponsor immunity, clean public recap, archive ownership, voice custody, or universal box-office authority.