Ticket Printer Ribbon Residue Recovery / 票机色带残像恢复机制
The mechanism treats a used thermal ribbon as a finite, privacy-bearing evidence surface. It reveals historical print order and later record conflict; it does not decide seat ownership, comp authority, or consent.
Destructive-read rule
The physical roll has finite residueIntegrity. Named-row extraction, full-sequence publication, and certified redaction must change that surface. A branch cannot preserve the entire roll while also claiming a destructive extraction at zero cost.
Recovery width is explicit: named_row_only, bounded_sequence, whole_roll, or certified_digest_only. Wider recovery exposes more adjacent patrons and protected aliases.
Exact assignment contract
The rite requires eight exact source cards in the current hand: residual docket, spent roll, ordered sequence, canonical conflict, protected subject, recovery method, custodian, and future reader. Arbitrary cards, catalog-only cards, virtual slots, and an omitted choice fail.
Required branch families are seal_residue_for_inspector, extract_named_voided_row, notify_exposed_patrons, publish_displacement_sequence, archive_under_embargo, redact_after_certified_digest, and suppress_residual_sequence. Every branch emits a unique residue state, a unique future route state, relief, cost, and at least three counter deltas.
counter_surfaces:
evidence: [residueIntegrity, erasedRowRecovery, inspectorTrust, publicAccountability]
people: [patronSafety, patronExposureRisk, sourceSafety]
cost: [sponsorPressure, archiveDebt, evidenceLoss, futureRouteCost]suppress_residual_sequence arms ribbon_residue.default_pending. The core-compatible event then offers damaged-segment recovery or admission that the sequence was destroyed. Both outcomes mutate at least three counters or durable states.
authority_boundary:
proves_historical_print_sequence_only: true
grants_current_seat_access: false
grants_sponsor_comp_authority: false
grants_patron_identity_consent: false
grants_archive_ownership: false
grants_memorial_authority: false
grants_universal_broadcast_permission: false