Off-Station Receiving Gate Counterreceipt / 站外接收闸反签回执机制
This mechanism turns one protected branch-0 transfer into a finite receiving-gate decision. It separates the parent witness result, source schedule, terminal trace, receiving receipt, named-subject response, gate identity, person/property label boundary, and later reader.
Activation invariant
activation:
parent_rite: storyteller.rite.lan_qiao_offstation_transfer_review.v1
parent_choice_index: 0
parent_choice_id: recruit_protected_transfer_list_witness
parent_completion_flag: complete_storyteller.rite.lan_qiao_offstation_transfer_review.v1
parent_state_flag: lan_qiao.state.recruited_protected_transfer_list_witness
parent_future_flag: lan_qiao.future.named_origin_gate_receiver_required
readiness_flag: offstation_receiving_gate.parent.protected_named_transfer_ready
accepts_other_parent_outcomes: false
child_repeatable: false
Choice 0 alone gains the counterreceipt, named-subject acknowledgement, D-17 receiving-gate, and person/property label-boundary cards. The transfer schedule, terminal access log, receiving-custody receipt, and named future reader are reused from the protected parent packet.
Exact assignment invariant
child_slots_in_order:
- counterreceipt: storyteller.card.offstation_receiving_gate_counterreceipt.v1
- transfer_schedule: storyteller.card.lan_qiao_offstation_transfer_schedule.v1
- terminal_access_log: storyteller.card.lan_qiao_terminal_access_log.v1
- receiving_custody: storyteller.card.lan_qiao_receiving_custody_receipt.v1
- named_subject: storyteller.card.offstation_named_subject_acknowledgement.v1
- receiving_gate: storyteller.card.offstation_receiving_gate_d17.v1
- label_boundary: storyteller.card.offstation_person_property_label_boundary.v1
- future_reader: storyteller.card.lan_qiao_future_reader.v1
exact_slots_required: true
assigned_cards_must_be_in_hand: true
selected_option_required: true
selected_option_requirements_enforced: true
selected_posture_source: rite_choice
selected_posture_card_exists: false
State transition
option_ids_in_order:
- countersign_named_receiver
- return_for_subject_acknowledgement
- seal_person_first_exception
- publish_receiving_gate_addendum
- freeze_company_receiver_claim
- refuse_unlawful_handoff
- quarantine_receiving_chain
- hidden_receiver_acceptance_default
Each option must close the one-shot review, set one exclusive receiving state, apply effect-backed relief and cost counters, and write one future-reader effect. The first seven options leave all misacceptance-pending flags false. Hidden receiver acceptance alone sets the pending triple and historical scar.
Recovery invariant
storyteller.event.offstation_receiving_gate_misacceptance.v1 is the only default event for this mechanism. It exposes exactly:
publish_subject_acknowledgement_addendum;return_transfer_to_origin_gate;quarantine_receiving_terminal.
All three outcomes clear offstation_receiving_gate.default_pending, event.offstation_receiving_gate_misacceptance.armed, and future_route.offstation_receiving_gate_recovery_pending. All preserve offstation_receiving_gate.history.hidden_acceptance_recorded and leave distinct state, counter, and future-route mutations.
Authority invariant
localAuthorityOnly: true
authorityBoundary:
preservesParentProtectedTransferResult: true
preservesSourceTransferSchedule: true
preservesOriginAndReceivingGates: true
preservesTerminalAccessLog: true
preservesReceivingCustodyReceipt: true
preservesNamedSubjectResponse: true
preservesPersonPropertyLabelBoundary: true
grantsPersonhoodJudgment: false
grantsSubjectConsent: false
grantsLawfulCustody: false
grantsStationAccess: false
grantsVoiceprintOrAvatarConsent: false
grantsRouteAssetTransfer: false
grantsCompanyCustody: false
grantsPublicTestimony: false
grantsCleanProof: false
grantsUniversalTransferAuthority: false
A countersigned receipt proves only that one named receiving gate accepted one scoped row. It does not recruit Lan Qiao, rule on the subject, or replace the parent transfer-custody decision.