Counterparty Reliance Unwind / 相对方信赖撤回机制
Counterparty Reliance Unwind is the mechanism for the moment when a false-clean or overbroad authority has already induced action. A prior row may be narrowed, corrected, quarantined, or callback-bound, but the relying counterparty has already spent or moved something. This mechanism makes that reliance action visible, reversible only with cost, and consumable by future routes.
It composes with 播出合约回读线 and 回叫消费证明线 without duplicating them. Readback asks whether the old contract can be reused by the current reader. Callback consumption asks whether relief still carries an owed callback. This mechanism asks what happens after somebody acted on the false-clean presentation before the correction landed.
Core rule
A reliance action cannot become clean proof of the source authority.
A passing implementation must preserve all three facts at once:
- the source authority row still exists and keeps its own state;
- the counterparty’s reliance action already happened;
- future readers consume the cost, scope, hostility, escrow, or recovery state created by the reliance unwind.
First source-backed runtime producer
The general mechanism is currently instantiated by the Seat Map Annotation false-default chain:
first_runtime_producer:
upstream_default: storyteller.event.false_seat_map_annotation_default.v1
source_state: seat_map_annotation.state.false_clean_default
source_future_effect: seat_map_annotation.future.recovery_only
relying_counterparty: sponsor_recap_desk
reliance_action_taken: scheduled_group_consent_recap
sunk_surface: recap_slot_time
harmed_or_displaced_reader: protected_caption_access_patron
entry_event: storyteller.event.counterparty_reliance_discovered.v1
ledger: storyteller.card.counterparty_reliance_ledger.v1
rite: storyteller.rite.reliance_unwind_conference.v1
default_event: storyteller.event.false_reliance_default.v1
downstream_consumer: storyteller.card.recall_claim_priority_queue.v1The sponsor desk’s schedule is evidence of reliance, never retroactive evidence of group consent. This producer exercises the reusable contract; it does not limit future producers to seat maps, sponsors, or recap slots.
Required state objects
Reliance ledger
相对方信赖账本 stores the row.
Minimum required fields:
counterparty_reliance_row_required:
source_authority_row: <row id or explicit_absence>
source_surface: audience_jury_seat_map_annotation_afteruse | broadcast_contract_readback | callback_consumption | sponsor_afteruse | recovery_indemnity | broadcast_signatory | asset_provenance | settlement_aftershock | equivalent
clean_or_overbroad_claim: <claim>
relying_counterparty: <counterparty>
reliance_action_taken: <action already taken>
sunk_surface: <money slot witness custody public trust worker claimant route asset license or equivalent>
harmed_or_displaced_reader: <reader or explicit_absence>
proof_bridge_or_absence: <proof bridge or explicit_absence>
selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance | false_reliance_default
accepted_cost_surface_or_absence: <cost or explicit_absence>
future_reader_effect: accepted_with_reliance_cost | public_only | lawful_only | sponsor_only | split_required | contradiction_pending | blocked | hostile | recovery_only | false_reliance_hardened | equivalentThe mechanism fails if the state object records reliance as only money, flavor anger, generic liability, or sponsor pressure.
Assignment rite
信赖撤回会 resolves the row through named assignments.
The rite must require:
- source authority row;
- clean or overbroad claim;
- relying counterparty;
- reliance action already taken;
- sunk surface;
- harmed or displaced reader;
- handler or explicit absence;
- proof bridge or explicit absence;
- support or explicit absence;
- selected unwind posture;
- accepted cost surface;
- future route or reader effect.
The current runtime enforces these as twelve exact in-hand slots: ledger, false-clean claim, relying counterparty, scheduled action, sunk recap slot, source floorplan, source seat-map docket, displaced patron row, Jao Min proof bridge, Jao Min handler, one branch posture bundle, and the Chapter Two future reader. The posture bundle itself carries the branch’s accepted cost and future-reader effect, so neither can be supplied by a mismatched generic card.
No famous handler, sponsor clause, archive stamp, lawful wording, edit checksum, public receipt, management urgency, or broadcast fact may replace those slots.
Default event
虚洁净信赖默认 fires or arms when the relying action is used to prove that the source authority was clean, or when the reliance action is hidden while future routes consume its benefit.
The default must name:
- source authority;
- relying counterparty;
- reliance action;
- sunk surface;
- harmed or displaced reader;
- false reliance claim;
- default actor;
- future effect.
State machine
state_machine:
unopened:
meaning: source authority has no reliance action yet or reliance action is not visible
ledgered:
meaning: source authority and relying action are both visible
honored_limited:
meaning: good-faith reliance is accepted only for named reader or surface
reimbursed_unwound:
meaning: reliance is reversed by spending named cost
scoped_license:
meaning: reliance becomes one-reader or one-route authority
escrowed:
meaning: reliance is preserved but cannot be cited as clean proof
clawed_back_with_notice:
meaning: reliance benefit is removed with notice or receipt
debt_published:
meaning: reliance cost is public, lawful, or archive-visible
quarantined:
meaning: reliance is too unsafe for current route use
false_reliance_hardened:
meaning: relying action became false proof of source authority
hostile:
meaning: counterparty or displaced reader contests future route
recovery_only:
meaning: source can be used only through scar-preserving recoveryBranch families
| Branch | Relief | Cost | Future effect |
|---|---|---|---|
| Honor limited reliance | good-faith counterparty does not instantly become enemy | reader scope, public distrust, sponsor heat, archive debt, or route cost rises | accepted with cost, public-only, lawful-only, sponsor-only |
| Reimburse and unwind | false-clean claim is lowered and custody/proof can recover | money, license encumbrance, route delay, handler burden | costlier, accepted with cost, contradiction pending |
| Convert to scoped license | current route can proceed with limited authority | source ambiguity, correction pressure, reader split | public-only, lawful-only, sponsor-only, split-required |
| Escrow reliance | unsafe clean reuse is blocked while trace is preserved | route delay, archive debt, inspection heat | blocked, lawful-only, recovery-only |
| Clawback with notice | overbroad benefit is removed visibly | counterparty hostility, sponsor pressure, public distrust | hostile, contradiction-pending, recovery-only |
| Publish reliance debt | hidden cost becomes public/lawful/archive memory | public confusion, sponsor pressure, inspection heat | accepted with cost, split-required, contradiction-pending |
| Quarantine reliance | fraud, worker exposure, or false route ownership is reduced | current route blocks, recovery cost, counterparty hostility | blocked, recovery-only |
| False reliance default | immediate pressure may drop | false reliance hardens and displaced reader hostility rises | false-reliance-hardened, hostile, blocked, recovery-only |
No branch may produce universal clean authority across public, lawful, sponsor, archive, worker, claimant, route asset, management, and broadcast-reality readers.
Source integration
Seat Map Annotation false default
座位图批注后用回执线 is the first runtime producer. Its false default preserves the real jury floorplan and protected patron row while arming a later discovery: the sponsor recap desk has already scheduled a group-consent recap on the false-clean seat map. The recap slot is sunk; the caption-access patron reader is displaced; the seat-map error remains false.
Recall claim priority
召回认领优先级线 is the first named downstream consumer. Its queue already accepts storyteller.card.counterparty_reliance_ledger.v1 as a callable source. That handoff makes the unwind result determine which sponsor, protected-patron, public, or lawful claim can consume the constrained recap surface first.
Broadcast contract readback
When 播出合约回读线 narrows or blocks a prior contract row after a later party already scheduled, paid, aired, released, or accepted custody, this mechanism creates a reliance ledger. The source readback remains true; the reliance action becomes the new pressure.
Callback consumption proof
When 回叫消费证明线 reveals that a relief row still owed a callback after a future counterparty consumed it, this mechanism records the spend or custody move caused by the clean relief presentation. The owed callback is not erased by reimbursement or license conversion.
Recovery indemnity shelf
When 复原追偿搁架线 assigns or refuses a future recourse holder after a counterparty relied on clean shelter, this mechanism decides whether the reliance is honored, unwound, scoped, escrowed, clawed back, published, quarantined, or defaulted.
Ruling reader collision
When 裁定读者冲突线 proves that readers are incompatible, this mechanism handles the party that already acted before the incompatibility was recognized. Reader collision decides recognition; reliance unwind decides sunk reliance.
False-service claimant escalation
When 误服裁定认领升级线 creates a concrete claimant row, this mechanism can make sponsor, management, archive, or public reliance on the false service into a debt that the claimant consumes.
Counter contract
Every resolution or default must mutate at least three surfaces:
counter_deltas_required:
relief: at_least_one
cost: at_least_one
future_reader_or_route_effect: at_least_onePrimary surfaces:
counterparty_reliance_pressurefalse_reliance_hardenedreliance_legibilitycounterparty_hostilitysunk_reliance_costdisplaced_reader_hostilityreader_scope_narrowingsource_ambiguitypublic_receipt_distrustsponsor_stop_loss_pressurearchive_debtinspection_heatproducer_license_encumbranceroute_delayroute_asset_false_ownerworker_exposureclaimant_burdenbroadcast_reality_driftfuture_route_acceptance
Replay evidence shape
The first runtime pair is expected at:
lens/replays/counterparty-reliance-unwind.reimburse.replay.json;lens/replays/counterparty-reliance-unwind.false-default.replay.json.
mechanic: storyteller.mechanic.counterparty_reliance_unwind.v1
session_id: lens-counterparty-reliance-unwind-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
trigger_kind: state_pressure
source_authority_row_present: true
clean_or_overbroad_claim_present: true
relying_counterparty_present: true
reliance_action_already_taken: true
sunk_surface_visible: true
no_fixed_turn_trigger: true
offered:
card: storyteller.card.counterparty_reliance_ledger.v1
rite: storyteller.rite.reliance_unwind_conference.v1
branch_runs:
constructive_branch:
selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance
ledger_state_after: <state>
relying_counterparty_state_after: <state>
displaced_reader_state_after: <state>
future_reader_effect: <effect>
counter_deltas: {}
default_branch:
selected_unwind: false_reliance_default
event_seen_or_armed: storyteller.event.false_reliance_default.v1
false_reliance_claim: <claim>
future_reader_effect: <effect>
counter_deltas: {}
downstream_read:
reader: public | lawful_reader | sponsor | archive | claimant | worker | route_asset | management | broadcast_reality | equivalent
consumed_state: <ledger state>
route_effect_after_read: <effect>
assertions:
- entry_is_state_triggered
- source_authority_preserved
- reliance_action_already_taken_visible
- sunk_surface_visible
- displaced_reader_visible_or_explicit_absence
- branches_diverge
- every_success_has_cost
- false_reliance_default_names_actor_and_claim
- downstream_reader_consumes_reliance_state
- no_universal_clean_authority
- no_fixed_turn_triggerNon-goals
- Not a new verdict.
- Not a generic indemnity or settlement system.
- Not a substitute for readback, callback, reader collision, or claimant intake.
- Not a timer.
- Not valid if the reliance action has not already changed state.
- Not valid if the future route does not read the resulting reliance state.