Evidence Carryover Fork / 导出证据回流分岔机制

Evidence Carryover Fork is the mechanism for proof that survives one crisis resolution and returns later as an active route asset pressure. It turns an exported custody receipt, archive copy, fan oxygen witness packet, black-box checksum, memorial air copy, or sponsor counterclaim from passive provenance into a playable object that can protect, accuse, capture, or poison a route.

This is not a meta save-file rule. In-world, the export is the version of reality that escaped the room: a receipt copied before seizure, a lawful seal carried across an audit boundary, a fan queue ledger mirrored outside the sponsor channel, a black-box checksum replayed by an editor, or a memorial voice proof that returns after a later broadcast contradicts it.

Mechanic promise

When a prior resolved proof returns, the game must ask what the returning evidence does to current custody rather than treating it as historical color.

The player must be able to accept the returning proof, quarantine it, overwrite it, trade it, expose it publicly, or deny it. Each branch must mutate at least one route asset or proxy posture state. A carryover proof is invalid if it only unlocks a text recap.

Inputs

Accept rows from:

State model

Every active carryover row should be represented as a docket-like card with this minimal state:

evidence_carryover:
  carryover_id: <stable id>
  evidence_object: archive_copy | fan_oxygen_receipt | black_box_checksum | memorial_air_copy | sponsor_counterclaim | consent_receipt | proxy_statement | equivalent
  source_session_id: <prior durable session id or explicit in-world source id>
  source_seed: <prior seed if generated by replay evidence>
  source_outcome: protected | route_asset | missed | hostile | captured | sacrificed | false_owner | split_canon | recovery_only | equivalent
  current_claimant: player | archive | inspector | sponsor | fan_public | editor | artist | pirate | proxy | split | none
  rival_claimant: archive | inspector | sponsor | fan_public | editor | artist | pirate | proxy | split | none
  contradiction_kind: owner_mismatch | consent_mismatch | checksum_mismatch | voice_mismatch | archive_signature_mismatch | memorial_right_mismatch | witness_sequence_mismatch | none
  route_asset_before: unseen | offered | recruited | protected | route_asset | missed | hostile | captured | sacrificed | false_owner | recovery_only | blocked
  proposed_use: accept | quarantine | overwrite | trade | expose | deny
  route_asset_after: protected | route_asset | costlier | hostile | captured | lawful_only | public_only | split_canon | contradiction_pending | recovery_only | blocked

Resolution rules

Rule 1 — Carryover cannot be invisible

A returning proof must name its prior outcome, current claimant, rival claimant, contradiction kind, and affected route asset before resolution. If the object cannot identify what it carries forward, it is not a carryover proof.

Rule 2 — Acceptance creates debt

Accepting the proof can improve lawful custody, route access, public legitimacy, voice integrity, or archive signature. It must also increase or spend another surface: inspection heat, sponsor stop-loss pressure, edit debt, fan resentment, handler burden, proxy exposure, or broadcast reality drift.

Rule 3 — Quarantine preserves proof but raises pressure

Quarantine is valid when the returned proof would create false ownership, voice violation, or public fraud. It must preserve a future recovery path while worsening schedule, audience, sponsor, fan, inspection, or route pressure.

Rule 4 — Overwrite is never clean

Overwriting the old proof with a newer aired reality may lower contradiction now, but it must create source ambiguity, public distrust, archive debt, consent debt, or hostile witness pressure.

Rule 5 — Trade transfers custody, not guilt

Trading the proof to sponsor, archive, inspector, editor, fan public, pirate relay, artist, or proxy can lower an immediate pressure only if it gates or captures a future route.

Rule 6 — Exposure makes at least one claimant hostile

Public exposure can improve public receipt or fan legitimacy, but it must arm retaliation, inspection heat, sponsor default pressure, proxy risk, or route asset capture.

Rule 7 — Denial leaves a shadow

Denying a returned proof is allowed, but the denied object must become hostile, captured, recovery-only, false-owner, contradiction-pending, or blocked. Denial cannot erase the proof for free.

Branch outputs

A resolved carryover row must change at least three surfaces, including at least one relief and one cost:

  • route_asset_pressure
  • archive_debt
  • archive_signature_legitimacy
  • inspection_heat
  • sponsor_stop_loss_pressure
  • public_receipt_legitimacy
  • fan_oxygen_resentment
  • voice_integrity
  • source_ambiguity
  • edit_debt
  • consent_debt
  • handler_burden
  • proxy_exposure
  • broadcast_reality_drift
  • false_custody_owner
  • recovery_route_cost

Integration notes

  • A protected route asset can be upgraded by a returning proof only if a new claimant cost is paid.
  • A hostile or missed asset can become recovery-only through quarantine or public exposure, but not cleanly recruited.
  • A captured proof can return as leverage only through a trade, rescue, public receipt, or lawful seal; otherwise it remains faction-gated.
  • A false owner becomes harder to undo when the returning proof is denied or overwritten.
  • A proxy who carries the returning proof inherits exposure or hostility if the player uses the proof without protection.

Non-goals

  • Not a turn trigger.
  • Not a save-system tutorial.
  • Not a generic replay log.
  • Not a free persistent bonus.
  • Not a raw content-count expansion.
  • Not valid if the returned evidence lacks prior outcome, claimant conflict, branch choice, route-state mutation, and counter deltas.