Common-Source Corroboration Audit / 同源佐证审计线

An inspector report, an editor checksum, an archive copy, a memorial-voice file, a public clip, and a carrier receipt all support the same clean broadcast claim. Every row may be authentic. The danger is that they are counted as six independent confirmations even though every row descends from slot.last_air_edit: that root directly parents the public clip and editor checksum; the public clip parents the inspector report; the checksum parents the archive copy; and the archive copy parents the memorial-voice file and carrier receipt.

The production desk wants the apparent plurality because a later archive, memorial, sponsor, public, or route-asset reader will accept a claim that looks independently corroborated. If the claim airs before lineage is tested, Broadcast Reality can make the echo look like consensus: the public clip has already produced the inspector report, while the editor checksum has produced the archive copy and its memorial-voice and carrier-receipt derivatives; a new broadcast cites those dependent surfaces, and later desks cite that broadcast.

The playable question is:

When several truthful-looking rows agree, does production commission a distinct-origin capture, disclose that they share one source, split their authority, reopen the root capture, quarantine memorial-voice use, publish a lineage notice, or let one source corroborate itself through six surfaces?

The missing causal conflict

The problem is not that a row is forged, stale, omitted, or contradicted. The rows may all be complete and mutually consistent. The conflict is between:

  1. surface multiplicity — six holders, formats, timestamps, or desks appear to confirm the claim; and
  2. root multiplicity — before broadcast, the audit can establish only one independent capture; a circular citation family exists only if the false-independence claim is aired and cited back into that family.

Authenticity and independence are separate. A valid derivative can remain usable within its own authority scope while contributing zero additional independent corroboration weight.

Bound packet

State-triggered entry

Open this storyline only when all of the following are visible:

entry_state_required:
  trigger_kind: state_pressure
  requested_corroborated_claim_present: true
  apparent_source_rows_min: 2
  apparent_sources_claim_independent_weight: true
  shared_root_or_unknown_lineage_visible: true
  source_family_rows_have_runtime_cards: true
  harmed_future_reader_or_route_visible: true
  future_reader_would_consume_corroboration_weight: true
  player_can_commission_disclose_split_reopen_quarantine_publish_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_card_or_source_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The storyline does not open because seven cards exist. Intake must record the common-source pressure, and 证据谱系冲突 must convert it into a live review state.

Storyline spine

Beat 1 — Six surfaces agree

The inspector report, editor checksum, archive copy, memorial voice, public clip, and carrier receipt all support one claim. The claim may be narrow — for example, that a voice phrase appears in a named broadcast cut — or expansive — that the phrase is independently confirmed, lawfully reusable, and safe for a memorial route.

The first proposition may be true while the second is unsupported.

Beat 2 — Intake records apparent independence

storyteller.rite.common_source_corroboration_intake.v1 uses the exact runtime proof rows and option record_common_source_collision. It records the requested claim, the apparent independent count, the common root, the risk of a later circular link, and the harmed future reader. Intake does not resolve the lineage and does not arm the default.

Beat 3 — Collision exposes the source family

storyteller.event.proof_lineage_collision.v1, option open_common_source_corroboration_review, requires completed intake and all seven exact cards. It makes the lineage dispute, authority scopes, root-count question, memorial-voice exposure, and future reader visible. It does not decide that the rows are false.

Beat 4 — One review fixes evidentiary weight

storyteller.rite.common_source_corroboration_review.v1 is nonrepeatable and exposes exactly seven ordered branches:

BranchState afterFuture effect
commission_distinct_origin_capturedistinct_origin_capture_commissioneddistinct_origin_capture_required_before_clean_corroboration
disclose_common_sourcecommon_source_disclosedcorroboration_weight_capped_at_one
split_by_authorityauthority_scopes_splitreader_specific_proof_required
reopen_root_captureroot_capture_reopenedroot_capture_required_before_route_unlock
quarantine_memorial_voice_usememorial_voice_quarantinedmemorial_voice_use_blocked_pending_lineage
publish_lineage_noticelineage_notice_publishedpublic_lineage_addendum_required
false_independent_corroborationfalse_independent_corroboration_pendingself_corroborating_broadcast_default_pending

The first six branches make the harmful default missable. disclose_common_source records the five units removed from apparent corroboration as corroborationWeightReduction:+5. Only the seventh branch may claim that the six surfaces are six independent roots and air that claim.

Beat 5 — Broadcast repeats its own proof

The harmful branch arms 自证广播默认. The docket’s pre-broadcast source family has circularFamilyCount: 0; airing the false-independence claim creates the return citation and records circularFamilyCountAfterFalseBroadcast: 1 on both the docket and default event. Later reports can then cite the public clip, which cites the broadcast, which relied on the same report. The default must resolve through exactly one terminal:

TerminalDurable stateDurable future effect
record_circular_proof_scarcircular_proof_scar_recordedfuture_routes_require_distinct_lineage_roots
force_root_source_reauditroot_source_reaudit_requiredroot_source_reaudit_required_before_memorial_or_archive_use
freeze_derived_route_assetsderived_route_assets_frozenderived_route_assets_recovery_only_until_lineage_rebuilt

No terminal converts dependent rows into independent proof. Even the least destructive terminal preserves that the false multiplicity was aired.

Source-family contract

Every lineage row must use the same schema or an explicit equivalent:

proof_lineage_row_required:
  rowCardId: storyteller.card.<lineage-row>.v1
  proofId: <stable proof row id>
  apparentSourceId: <stable apparent source id>
  surfaceKind: inspector_report | editor_checksum | archive_copy | memorial_voice | public_clip | carrier_receipt
  sourceFamilyId: family.lyra.last-air-edit.017
  lineageRootId: slot.last_air_edit
  rootSourceIdOrExplicitAbsence: slot.last_air_edit | explicit_absence
  parentCopyIdOrAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
  parentSourceIdOrExplicitAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
  sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
  custodian: <named inspector editor archivist memorial desk fan public or carrier>
  custodianOrExplicitAbsence: <same named custodian or explicit_absence>
  derivationKind: inspector_summary | checksum | archive_copy | memorial_mix | public_clip | carrier_receipt
  originFingerprintOrExplicitAbsence: sha256:lyra-last-air-edit-017 | explicit_absence
  claimFragment: <exact proposition traced through this row>
  authorityScope: inspection | editor_continuity | archive_custody | memorial_voice | public_receipt | carrier_transfer
  captureOrIssueTime: <stable time row>
  versionId: <stable version id>
  futureReaderOrRoute: reader.memorial-archive-route-clearance
  harmedReaderOrClaimantIfOvercounted: lyra_voice_and_memorial_route_claimant
  provesScope: <one exact local proposition>
  doesNotProve: [<explicit denied authorities>]
  independenceState: shared_root
  localAuthorityOnly: true

Different custodians, formats, signatures, or institutional scopes do not create distinct roots. sourceSessionIdOrAbsence and parentCopyIdOrAbsence must remain explicit; absence cannot be presumed independent.

Reachability and missability

All seven review branches must be reachable from the same post-collision seven-card packet. Intake must fail when a required source row is missing, substituted, absent from hand, or assigned to the wrong slot. Collision must fail before intake and when any exact card is absent. Review must fail before collision, with any required collision flag missing, with no choice, or on a second attempt.

The review is nonrepeatable. Resolving any constructive branch closes the other six and makes the default unreachable for that incident. Selecting false_independent_corroboration closes the constructive branches and makes one default terminal mandatory.

Authority boundary

This audit tracks lineage roots and derivative relationships only. It requires distinct roots for independent corroboration and preserves inspection, editor, archive, memorial, public, and carrier scopes. It grants no underlying event truth, independent corroboration without distinct roots, universal inspector all-clear, editor source truth, archive pre-intake origin, memorial-voice consent, voice custody, route-asset content truth, public-clip independent witness status, sponsor immunity, or universal broadcast authority.

An inspector report can remain a valid inspector report. An editor checksum can remain a valid checksum. An archive copy can remain a valid copy. A carrier receipt can remain a valid transfer record. The audit only prevents those derivatives from multiplying one root into several independent witnesses.

Exact non-overlap table

Existing laneIts authorityThis lane remains distinct because
Broadcast Asset Provenance Afterlifedecides which derivative copy owns or serves a later routethe audit counts independent roots; no copy receives ownership merely by passing lineage review
Broadcast Reality Drift Auditreconciles an aired reality that contradicts later proofall apparent rows here may agree; the conflict is false independence before or during broadcast hardening
Custody Oracle Crossreadasks which concrete oracle may read an already-scarred custody statethis audit does not choose a custody oracle; it tests whether several oracle inputs descend from one root
Reader Recusal Recordrecords a reader’s conflict of interest and neutral replacementneutral readers can still receive dependent proof; source dependence exists without reader bias
Recap Syndication Driftprevents a fragment from masquerading as the complete recapa complete derivative may still fail independence; completeness and root multiplicity are separate
Operator Witness Conclavepreserves disagreement among distinct low-rank operator rowsthe rows here agree; the audit asks whether their agreement is inherited from one upstream source
Ruling Reader Collisionhandles one valid source consumed by incompatible readersthis audit handles several apparent sources consumed as independent corroboration of one claim
Proof Board Snapshot Custodypreserves hidden, stale, summarized, ordered, or omitted board rowsa perfectly accurate board can still overcount six derivatives as six independent roots

Replay evidence expectation

The bound replay is lens/replays/common-source-corroboration-audit.false-multiplicity-default.replay.json. It must contain the complete action chain — create, intake, entry, harmful review, and one default terminal — and finish with the pending triple cleared, the aired false-multiplicity scar preserved, exactly one terminal state, and its matching future effect.

Non-goals

  • Not a generic provenance glossary or dashboard.
  • Not a rule that derivative evidence is automatically false.
  • Not an inspector-signoff unanimity story.
  • Not a board-omission, witness-disagreement, reader-recusal, or copy-ownership wrapper.
  • Not a fixed-turn or raw-source-count event.
  • Not valid unless the independent-root count changes a future route, memorial/voice use, archive use, public addendum, correction burden, or recovery state.