Box Office Stamp Pad Impression Provenance / 票房印台印迹溯源机制

This mechanism compares a historical ink impression with a reusable physical pad across a documented re-ink or pad-changeover window. It asks which impression profile can be attributed to which pad state at which time. It does not decide whether the underlying refund, comp, claimant notice, or admission was authorized.

Evidence separation

box_office_evidence_boundaries:
  comp_stamp: seat_relief_authorization
  claimant_stamp: notice_or_representation_scope
  refund_name_correction: corrected_identity_and_acceptance
  ticket_stub: named_admission
  stamp_pad_impression: historical_impression_profile_within_named_changeover_window

A matching ink profile does not validate a refund; a valid refund does not identify the pad that made its impression.

Forensic provenance tuple

stamp_pad_impression_provenance:
  source_impression_id: required
  source_impression_timestamp: required
  source_receipt_or_absence: required
  original_pad_id_or_absence: required
  original_ink_batch_or_absence: required
  original_ink_profile:
    colour: required
    density: required
    edge_wear: required
    fibre_bleed: required
  original_access_holder_or_absence: required
  reink_or_pad_changeover_window: required
  changeover_actor_or_absence: required
  current_pad_id_or_absence: required
  current_ink_batch_or_absence: required
  current_impression_profile_or_absence: required
  requested_afteruse: required
  future_receipt_verifier: required
  challenged_patron: required

An absent value is evidence of a gap, not permission to infer continuity. Desk location, stamp design, or matching text cannot replace pad identity, ink profile, access custody, or changeover time.

State machine

four exact intake cards
  -> impression intake end_turn + record_impression_changeover_conflict
  -> intake_recorded + four intake pressure flags
  -> impression challenge event_choice
  -> impression_challenge_opened + current_pad_identity_unproven + forensic_review_pending
  -> exact seven-card nonrepeatable review end_turn
  -> one constructive state/future pair
     OR false_current_pad_continuity_pending + pending triple + aired claim
  -> if false: exact default event_choice
  -> pending and aired flags cleared + false_continuity_scar preserved
  -> exactly one durable terminal state + exactly one matching future effect

Intake contract

storyteller.rite.box_office_stamp_pad_impression_intake.v1 is the required upstream gameplay rite:

slots:
  source_impression: storyteller.card.box_office_stamp_pad_source_impression.v1
  original_ink_profile: storyteller.card.box_office_stamp_pad_original_ink_profile.v1
  changeover_trace: storyteller.card.box_office_stamp_pad_changeover_trace.v1
  challenged_patron: storyteller.card.box_office_stamp_pad_challenged_patron.v1
option: record_impression_changeover_conflict
sets:
  box_office_stamp_pad.intake_recorded: true
  box_office_stamp_pad.pressure.source_impression_visible: true
  box_office_stamp_pad.pressure.original_ink_profile_visible: true
  box_office_stamp_pad.pressure.reink_or_changeover_visible: true
  box_office_stamp_pad.pressure.challenged_patron_visible: true

The intake resolves through end_turn, requires all four assigned cards in hand, and requires its selected option. It does not set the challenge-opened, current-pad-unproven, or forensic-review-pending flags.

Entry contract

storyteller.event.box_office_stamp_pad_impression_challenge.v1 requires intake_recorded, all four intake pressure flags, and all seven lane cards in hand. Its stable option open_forensic_impression_review sets:

box_office_stamp_pad.impression_challenge_opened: true
box_office_stamp_pad.pressure.current_pad_identity_unproven: true
box_office_stamp_pad.state.forensic_review_pending: true

Fixed turns, elapsed days, raw stamp counts, generic queue pressure, card possession without intake, dashboard state, or lens health are forbidden substitutes.

Review contract

storyteller.rite.box_office_stamp_pad_afteruse_review.v1 requires the intake flag; all five pressure flags; impression_challenge_opened; forensic_review_pending; and all seven exact assigned cards.

BranchForensic stateFuture effect
certify_source_impressionsource_impression_certifiedsource_impression_may_support_named_refund
bind_impression_to_ink_batchink_batch_boundmatching_ink_batch_required
split_pre_and_post_reink_claimspre_post_reink_splitpost_reink_receipts_require_new_profile
reopen_pad_access_logpad_access_log_reopenedcurrent_access_holder_signoff_required
publish_pad_changeover_noticechangeover_notice_publishedchangeover_notice_required_before_recap
quarantine_unmatched_impressionunmatched_impression_quarantinedimpression_quarantined_until_match
false_current_pad_continuity_defaultfalse_current_pad_continuity_pendingfalse_stamp_pad_afteruse_default_pending

Only choice 6 may set box_office_stamp_pad.default_pending, event.false_stamp_pad_afteruse_default.armed, future_route.false_stamp_pad_afteruse_default_pending, and broadcast_reality.false_stamp_pad_continuity_claim_aired.

Default closure contract

storyteller.event.false_stamp_pad_afteruse_default.v1 requires the pending triple, aired claim, false-pending state, and unresolved event. It exposes exactly three stable terminals:

ChoiceTerminal stateFuture effect
record_false_pad_continuityfalse_current_pad_continuityfuture_receipts_require_continuity_challenge
force_forensic_reimpressioncurrent_pad_retest_requiredforensic_reimpression_required_before_recap
restore_challenged_patronchallenged_patron_restoredpatron_refund_restoration_required

Every option clears the pending triple, aired flag, and false-pending state. It sets box_office_stamp_pad.false_continuity_scar, resolves the event, and leaves exactly one terminal state with one matching future effect.

Negative gates

The mechanism fails if any of the following succeeds:

  • resolving intake without all four exact cards, exact slots, cards in hand, or its selected option;
  • opening the challenge before intake_recorded, with any intake pressure flag missing, or without all seven lane cards in hand;
  • opening review before the challenge event, without intake, or with any pressure flag missing;
  • reviewing with a wrong slot, a card absent from hand, or no selected choice;
  • arming the default from any constructive branch;
  • firing the default without any member of the pending triple, the aired flag, or false-pending state;
  • leaving two forensic states or two terminal future effects true at once;
  • treating a matching impression as current pad identity, refund validity, patron consent, sponsor immunity, clean recap, or archive ownership.

Replay acceptance

The durable replay contains exactly five actions in order:

  1. lens-scoped create with source: storyteller;
  2. end_turn for storyteller.rite.box_office_stamp_pad_impression_intake.v1 with four exact assignments and record_impression_changeover_conflict;
  3. event_choice for storyteller.event.box_office_stamp_pad_impression_challenge.v1 and open_forensic_impression_review;
  4. end_turn for storyteller.rite.box_office_stamp_pad_afteruse_review.v1 with seven exact assignments and choice 6;
  5. event_choice for storyteller.event.false_stamp_pad_afteruse_default.v1 selecting one terminal.

The replay is incomplete if it ends at the aired claim, retains any pending flag, omits the false-continuity scar, or differs from its latest session state.

Authority boundary

This mechanism proves only a historical impression profile inside a named forensic comparison window. It grants no current pad identity, refund validity, patron consent, sponsor immunity, clean public recap, archive ownership, voice custody, or universal box-office authority.