Common-Source Corroboration Audit / 同源佐证审计线
An inspector report, an editor checksum, an archive copy, a memorial-voice file, a public clip, and a carrier receipt all support the same clean broadcast claim. Every row may be authentic. The danger is that they are counted as six independent confirmations even though every row descends from slot.last_air_edit: that root directly parents the public clip and editor checksum; the public clip parents the inspector report; the checksum parents the archive copy; and the archive copy parents the memorial-voice file and carrier receipt.
The production desk wants the apparent plurality because a later archive, memorial, sponsor, public, or route-asset reader will accept a claim that looks independently corroborated. If the claim airs before lineage is tested, Broadcast Reality can make the echo look like consensus: the public clip has already produced the inspector report, while the editor checksum has produced the archive copy and its memorial-voice and carrier-receipt derivatives; a new broadcast cites those dependent surfaces, and later desks cite that broadcast.
The playable question is:
When several truthful-looking rows agree, does production commission a distinct-origin capture, disclose that they share one source, split their authority, reopen the root capture, quarantine memorial-voice use, publish a lineage notice, or let one source corroborate itself through six surfaces?
The missing causal conflict
The problem is not that a row is forged, stale, omitted, or contradicted. The rows may all be complete and mutually consistent. The conflict is between:
- surface multiplicity — six holders, formats, timestamps, or desks appear to confirm the claim; and
- root multiplicity — before broadcast, the audit can establish only one independent capture; a circular citation family exists only if the false-independence claim is aired and cited back into that family.
Authenticity and independence are separate. A valid derivative can remain usable within its own authority scope while contributing zero additional independent corroboration weight.
Bound packet
- 同源佐证审计机制 defines lineage families, root counts, authority scope, and false-multiplicity state.
- 同源佐证证据行 binds the seven exact runtime cards.
- 同源佐证复核 binds the intake and one-shot seven-branch review.
- 证据谱系冲突 opens review only after the apparent sources have been recorded.
- 自证广播默认 resolves the harmful aired claim into exactly one of three durable terminals.
- 同源佐证审计 Lens observes reachability, missability, branch divergence, terminal closure, and replay evidence.
State-triggered entry
Open this storyline only when all of the following are visible:
entry_state_required:
trigger_kind: state_pressure
requested_corroborated_claim_present: true
apparent_source_rows_min: 2
apparent_sources_claim_independent_weight: true
shared_root_or_unknown_lineage_visible: true
source_family_rows_have_runtime_cards: true
harmed_future_reader_or_route_visible: true
future_reader_would_consume_corroboration_weight: true
player_can_commission_disclose_split_reopen_quarantine_publish_or_default: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_card_or_source_count_trigger: true
no_dashboard_or_lens_health_trigger: trueThe storyline does not open because seven cards exist. Intake must record the common-source pressure, and 证据谱系冲突 must convert it into a live review state.
Storyline spine
Beat 1 — Six surfaces agree
The inspector report, editor checksum, archive copy, memorial voice, public clip, and carrier receipt all support one claim. The claim may be narrow — for example, that a voice phrase appears in a named broadcast cut — or expansive — that the phrase is independently confirmed, lawfully reusable, and safe for a memorial route.
The first proposition may be true while the second is unsupported.
Beat 2 — Intake records apparent independence
storyteller.rite.common_source_corroboration_intake.v1 uses the exact runtime proof rows and option record_common_source_collision. It records the requested claim, the apparent independent count, the common root, the risk of a later circular link, and the harmed future reader. Intake does not resolve the lineage and does not arm the default.
Beat 3 — Collision exposes the source family
storyteller.event.proof_lineage_collision.v1, option open_common_source_corroboration_review, requires completed intake and all seven exact cards. It makes the lineage dispute, authority scopes, root-count question, memorial-voice exposure, and future reader visible. It does not decide that the rows are false.
Beat 4 — One review fixes evidentiary weight
storyteller.rite.common_source_corroboration_review.v1 is nonrepeatable and exposes exactly seven ordered branches:
| Branch | State after | Future effect |
|---|---|---|
commission_distinct_origin_capture | distinct_origin_capture_commissioned | distinct_origin_capture_required_before_clean_corroboration |
disclose_common_source | common_source_disclosed | corroboration_weight_capped_at_one |
split_by_authority | authority_scopes_split | reader_specific_proof_required |
reopen_root_capture | root_capture_reopened | root_capture_required_before_route_unlock |
quarantine_memorial_voice_use | memorial_voice_quarantined | memorial_voice_use_blocked_pending_lineage |
publish_lineage_notice | lineage_notice_published | public_lineage_addendum_required |
false_independent_corroboration | false_independent_corroboration_pending | self_corroborating_broadcast_default_pending |
The first six branches make the harmful default missable. disclose_common_source records the five units removed from apparent corroboration as corroborationWeightReduction:+5. Only the seventh branch may claim that the six surfaces are six independent roots and air that claim.
Beat 5 — Broadcast repeats its own proof
The harmful branch arms 自证广播默认. The docket’s pre-broadcast source family has circularFamilyCount: 0; airing the false-independence claim creates the return citation and records circularFamilyCountAfterFalseBroadcast: 1 on both the docket and default event. Later reports can then cite the public clip, which cites the broadcast, which relied on the same report. The default must resolve through exactly one terminal:
| Terminal | Durable state | Durable future effect |
|---|---|---|
record_circular_proof_scar | circular_proof_scar_recorded | future_routes_require_distinct_lineage_roots |
force_root_source_reaudit | root_source_reaudit_required | root_source_reaudit_required_before_memorial_or_archive_use |
freeze_derived_route_assets | derived_route_assets_frozen | derived_route_assets_recovery_only_until_lineage_rebuilt |
No terminal converts dependent rows into independent proof. Even the least destructive terminal preserves that the false multiplicity was aired.
Source-family contract
Every lineage row must use the same schema or an explicit equivalent:
proof_lineage_row_required:
rowCardId: storyteller.card.<lineage-row>.v1
proofId: <stable proof row id>
apparentSourceId: <stable apparent source id>
surfaceKind: inspector_report | editor_checksum | archive_copy | memorial_voice | public_clip | carrier_receipt
sourceFamilyId: family.lyra.last-air-edit.017
lineageRootId: slot.last_air_edit
rootSourceIdOrExplicitAbsence: slot.last_air_edit | explicit_absence
parentCopyIdOrAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
parentSourceIdOrExplicitAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
custodian: <named inspector editor archivist memorial desk fan public or carrier>
custodianOrExplicitAbsence: <same named custodian or explicit_absence>
derivationKind: inspector_summary | checksum | archive_copy | memorial_mix | public_clip | carrier_receipt
originFingerprintOrExplicitAbsence: sha256:lyra-last-air-edit-017 | explicit_absence
claimFragment: <exact proposition traced through this row>
authorityScope: inspection | editor_continuity | archive_custody | memorial_voice | public_receipt | carrier_transfer
captureOrIssueTime: <stable time row>
versionId: <stable version id>
futureReaderOrRoute: reader.memorial-archive-route-clearance
harmedReaderOrClaimantIfOvercounted: lyra_voice_and_memorial_route_claimant
provesScope: <one exact local proposition>
doesNotProve: [<explicit denied authorities>]
independenceState: shared_root
localAuthorityOnly: trueDifferent custodians, formats, signatures, or institutional scopes do not create distinct roots. sourceSessionIdOrAbsence and parentCopyIdOrAbsence must remain explicit; absence cannot be presumed independent.
Reachability and missability
All seven review branches must be reachable from the same post-collision seven-card packet. Intake must fail when a required source row is missing, substituted, absent from hand, or assigned to the wrong slot. Collision must fail before intake and when any exact card is absent. Review must fail before collision, with any required collision flag missing, with no choice, or on a second attempt.
The review is nonrepeatable. Resolving any constructive branch closes the other six and makes the default unreachable for that incident. Selecting false_independent_corroboration closes the constructive branches and makes one default terminal mandatory.
Authority boundary
This audit tracks lineage roots and derivative relationships only. It requires distinct roots for independent corroboration and preserves inspection, editor, archive, memorial, public, and carrier scopes. It grants no underlying event truth, independent corroboration without distinct roots, universal inspector all-clear, editor source truth, archive pre-intake origin, memorial-voice consent, voice custody, route-asset content truth, public-clip independent witness status, sponsor immunity, or universal broadcast authority.
An inspector report can remain a valid inspector report. An editor checksum can remain a valid checksum. An archive copy can remain a valid copy. A carrier receipt can remain a valid transfer record. The audit only prevents those derivatives from multiplying one root into several independent witnesses.
Exact non-overlap table
| Existing lane | Its authority | This lane remains distinct because |
|---|---|---|
| Broadcast Asset Provenance Afterlife | decides which derivative copy owns or serves a later route | the audit counts independent roots; no copy receives ownership merely by passing lineage review |
| Broadcast Reality Drift Audit | reconciles an aired reality that contradicts later proof | all apparent rows here may agree; the conflict is false independence before or during broadcast hardening |
| Custody Oracle Crossread | asks which concrete oracle may read an already-scarred custody state | this audit does not choose a custody oracle; it tests whether several oracle inputs descend from one root |
| Reader Recusal Record | records a reader’s conflict of interest and neutral replacement | neutral readers can still receive dependent proof; source dependence exists without reader bias |
| Recap Syndication Drift | prevents a fragment from masquerading as the complete recap | a complete derivative may still fail independence; completeness and root multiplicity are separate |
| Operator Witness Conclave | preserves disagreement among distinct low-rank operator rows | the rows here agree; the audit asks whether their agreement is inherited from one upstream source |
| Ruling Reader Collision | handles one valid source consumed by incompatible readers | this audit handles several apparent sources consumed as independent corroboration of one claim |
| Proof Board Snapshot Custody | preserves hidden, stale, summarized, ordered, or omitted board rows | a perfectly accurate board can still overcount six derivatives as six independent roots |
Replay evidence expectation
The bound replay is lens/replays/common-source-corroboration-audit.false-multiplicity-default.replay.json. It must contain the complete action chain — create, intake, entry, harmful review, and one default terminal — and finish with the pending triple cleared, the aired false-multiplicity scar preserved, exactly one terminal state, and its matching future effect.
Non-goals
- Not a generic provenance glossary or dashboard.
- Not a rule that derivative evidence is automatically false.
- Not an inspector-signoff unanimity story.
- Not a board-omission, witness-disagreement, reader-recusal, or copy-ownership wrapper.
- Not a fixed-turn or raw-source-count event.
- Not valid unless the independent-root count changes a future route, memorial/voice use, archive use, public addendum, correction burden, or recovery state.