Route Discontinuance Review / 路线停办复核

Route Discontinuance Review is a one-shot assignment rite for the pending route-discontinuance.d17.company_cleanup_open source row. It asks how the producer will stop or narrow the company-cleanup transfer while keeping the claimant, carrier, proof candidate, salvage candidate, and future reader inspectable. Only its notice_pause branch materializes route-discontinuance.d17.public_pause.

Entry contract

The review opens from state pressure only when both exact upstream flags exist:

source_gate:
  complete_storyteller-rite-d17-lost-and-found-night: true
  storyteller_d17_company_cleanup_pending: true
  fixed_source_row: route-discontinuance.d17.company_cleanup_open
  selected_posture: unselected
  state_after: pending_selected_posture

The deterministic replays earn those flags by executing D17 choice index 1, accept_company_lost_property_transfer, then resolving storyteller.event.shen_mansheng_company_custody_window.v1 before starting this review. The review never synthesizes its own prerequisites. Runtime gives the filing an eight-day long-operation window, due before company cleanup or a later memorial reader consumes the route as cleanly gone. Fixed chronology, raw route count, dashboard state, and lens-health state are forbidden triggers.

Exact slot order

The rite has exactly twelve required slots:

slots:
  - register
  - source_row
  - route_or_asset
  - discontinuance_pressure
  - partial_viability
  - claimant
  - harmed_reader
  - carrier_anchor
  - handler
  - proof_bridge
  - salvage_floor
  - future_reader

Each slot accepts only its matching runtime card: storyteller.card.route_discontinuance_register.v1, route_discontinuance_source_row.v1, route_discontinuance_route_or_asset.v1, route_discontinuance_pressure.v1, route_discontinuance_partial_viability.v1, route_discontinuance_claimant.v1, route_discontinuance_harmed_reader.v1, route_discontinuance_carrier_anchor.v1, route_discontinuance_handler.v1, route_discontinuance_proof_bridge.v1, route_discontinuance_salvage_floor.v1, and route_discontinuance_future_reader.v1, all under the storyteller.card namespace. The rite validates that all twelve cards exist in hand, rejects substitutes and off-hand IDs, requires an explicit choice, and cannot resolve twice. Any such failure leaves the default event unarmed.

Ordered choices

0registered_stop

The player records a scoped stop: registeredblocked_with_notice. The source row, claim, carrier/proof, floor, and future reader remain callable; the route cannot be reported as never having existed.

1notice_pause

The player pauses under notice: paused_under_noticepublic_only. This is the only branch that materializes route-discontinuance.d17.public_pause. The row is eligible for floor.public_notice.d17 only when all of route_discontinuance.branch.notice_pause, route_discontinuance.state.paused_under_notice, and future_route.public_only exist. No default flag or counterreceipt is produced.

2transfer_carrier

Production stops carrying the route directly: transferredcarrier_required. A named carrier remains exposed to the claimant and later reader.

3convert_recovery_only

Clean continuation closes while a bounded salvage and recovery path remains visible: recovery_onlyrecovery_only.

4public_abandonment

The stop becomes public: publicly_abandonedpublic_audit_required. This blocks clean private capture but preserves harm and future accountability.

5private_suppression

The route is suppressed under a recorded private posture: privately_suppressedhostile_if_challenged. The branch is costly and scoped, but it is still a registered v1 outcome. It does not arm storyteller.event.unregistered_discontinuance_default.v1.

6reopen_with_bond

The route remains conditionally open under a visible bond, proof bridge, carrier burden, and future-reader restriction: reopened_with_bondbond_required.

7unregistered_default

The player explicitly leaves the stop unregistered: default_pendingunregistered_discontinuance_pending. This is the only choice that sets the shared pending gate and makes storyteller.event.unregistered_discontinuance_default.v1 eligible.

Default gate

default_gate:
  arms_only_on_choice_index: 7
  arms_only_on_branch: unregistered_default
  choices_0_through_6_clear_pending: true
  missing_assignment_arms_default: false
  substituted_assignment_arms_default: false
  off_hand_assignment_arms_default: false
  missing_choice_arms_default: false
  repeated_resolution_arms_default: false

This corrects the old draft envelope: private_suppression does not itself arm default. Only an explicit unregistered disposition does.

The public-pause materialization is equally strict: choices registered_stop, transfer_carrier, convert_recovery_only, public_abandonment, private_suppression, reopen_with_bond, and unregistered_default must never expose route-discontinuance.d17.public_pause.

Expiry

The review is an eight-day long_operation. Its exact expiry consequence is unresolved_review_remains_visible_without_arming_default, and expiryArmsDefault is false. Expiry leaves route-discontinuance.d17.company_cleanup_open pending and inspectable. It does not choose a posture, materialize the public-pause row, set any default flag, trigger the event, or grant the counterreceipt.

Result and authority rules

Every successful branch produces a distinct branch result, discontinuance state, and future-reader result while preserving the fixed source row. The review may record a local management disposition; it may not grant consent, ownership, settlement, waiver, legal truth, archive truth, sponsor truth, inspector truth, proof truth, salvage title, route clearance, or clean universal disappearance.

Replay evidence

  • Both replays first execute D17 choice index 1 and the Shen Mansheng custody event, proving the two upstream gate flags through gameplay.
  • route-discontinuance-register.notice-pause.replay.json then assigns all twelve exact cards and selects target index 1; the event remains unavailable and only this route materializes the public-pause row.
  • route-discontinuance-register.broadcast-erasure.replay.json assigns the same packet and selects target index 7; it proves the public-pause row stays absent before resolving broadcast_reality_erasure.

The replay session IDs prove execution only. The stable in-world input remains the D17 rite/choice pair plus route-discontinuance.d17.company_cleanup_open; route-discontinuance.d17.public_pause is a notice-pause-only output.