CS-09 Initial-Collision Double-Fire / CS-09 同缩写重复执行
Premise
During a smoke stop, source bundle CS-09 survives intact. Nobody overwrites fly cue F-27.
The collision comes from two genuine callers. Rowan Neri initials the white master RN when F-27 is prepared at 21:14:07. After the desk handoff, relief caller Rhea Noll initials the yellow rail carbon RN when F-27 is executed at 21:17:42. Motor current, brake release, and rail travel prove one physical movement at 21:17:43.
Recovery cycle R6 scans the stack into a blue copy. Its importer drops paper colour, column position, pressure depth, caller identity, and mark semantics. It joins only on cue plus displayed initials, producing two identical EXECUTE:F-27:RN tokens. One has already been consumed; the other is queued for the physical bus.
The playable problem is not who may authorize the cue. It is whether one physical cue instance executes at most once when a lossy document reader mistakes PREPARED and EXECUTED for two executions.
Distinct seam boundary
This storyline remains narrower than adjacent lanes:
- Cue-Sheet Overwrite Afteruse Receipt begins with altered cue text and governs later use of that overwrite. CS-09 is unaltered; the fault is a consumed execution replayed through a lossy key.
- Prompt-Book Errata Afteruse Receipt asks whether a correction cleans earlier history. Here both marks are correct in their own phase.
- Stale Dispatch Recall starts from an old instruction that remains actionable after its boundary changes. Here the instruction already executed, and recovery lost its execution receipt.
- Stage Light Cue Custody asks what an executed light cue can prove downstream. This line asks whether a physical fly cue happens twice.
- Fly-rail lock-pin and counterweight-load-sheet lanes govern configuration and clearance. This line does not grant rigging clearance; it enforces execution uniqueness after clearance has already been handled elsewhere.
- Signatory, consent, sponsor, archive, and authorship systems cannot decide whether the motor moved once or twice.
If the line collapses into certify initials, restrict a reader, reopen a generic claimant, split consent from custody, or quarantine an old mark, it has lost its identity.
State-triggered entry
entry_state:
trigger_kind: state_pressure
cue_bundle: CS-09
cue_instance: F-27 / recovery cycle R6
cue_text_changed: false
white_prepared_mark_visible: true
yellow_executed_mark_visible: true
distinct_callers_share_RN: true
physical_execution_receipt_count: 1
flattened_execute_token_count: 2
second_physical_pulse_queued: true
exact_eight_source_cards_in_hand: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_initial_count_trigger: trueThe story does not open merely because two initials look alike. It opens when the same cue instance has one physical execution receipt and a recovery importer is about to replay a second machine token.
Bound content pack
- Cue Execution Idempotency Ledger defines the state transition, stable key, exact source tuple, and destructive evidence rule.
- CS-09 Initial-Collision Docket binds the paper layers, callers, timecodes, automation trace, physical receipt, and future route.
- CS-09 Cue Execution Idempotency Review resolves eight operational responses from eight exact cards.
- CS-09 Duplicate Cue Hardening records partial or complete second movement if the duplicate reaches the rail.
- CS-09 Execution Idempotency Lens observes exact reachability, branch divergence, one-shot closure, default execution, and authority denial.
Story spine
Beat 1 — One cue, two honest marks
Rowan’s RN means standby. Rhea’s RN means executed. The shared initials are a display collision, not evidence that one person acted twice. The white and yellow sheets preserve different semantic states.
Beat 2 — A physical receipt closes the first epoch
Headset audio says “go F-27” once. Cue light changes once. Motor current and brake telemetry show one movement. The execution epoch is consumed even though the paper stack contains two RN glyphs.
Beat 3 — Recovery flattens the tuple
The blue recovery scan erases colour, columns, pressure depth, caller key, and semantic phase. The importer treats both marks as execution tokens. Because its key omits the physical receipt, it cannot tell that one token is already spent.
Beat 4 — The player chooses an operational repair
Run CS-09 Cue Execution Idempotency Review. The player may bind chronology, cancel the pulse, rekey callers, split state registers, consume the carbon stack for pressure forensics, divert the duplicate into a dry-run sink, require manual rail recall, or accept a second execution.
Beat 5 — A double movement becomes real
If both tokens are admitted as executions, the rail receives a second F-27 pulse. The interlock may trip after partial travel, leaving an aired set discontinuity, or the scenery may complete a second movement. In Storyteller’s world, the recovery cut can harden this false second call into the version future reruns inherit.
Branch map
| Branch | Relief | Cost / scar | Execution state after | Future effect |
|---|---|---|---|---|
| bind_single_execution_chronology | one mark becomes PREPARED, one becomes EXECUTED, one rail receipt closes F-27 | every reader carries the full instance checksum | single_execution_chronology_bound | cue_instance_checksum_required |
| cancel_queued_duplicate_pulse | imminent second movement is stopped | execution truth remains uncertain; manual readback repeats | duplicate_pulse_cancelled_execution_unproven | manual_execution_readback_required |
| rekey_callers_and_reissue_bundle | RN-A and RN-B stop colliding in new bundles | migration load; old stack remains disputed | unique_caller_keys_reissued | unique_operator_key_required |
| split_prepared_and_executed_registers | standby can no longer enter the execution stream | legacy schema conversion | prepared_executed_registers_split | state_transition_schema_required |
| lift_and_separate_carbon_layers | pressure order becomes legible | original carbon stack is consumed | carbon_layers_lifted_trace_consumed | new_source_stack_required |
| divert_duplicate_pulse_to_dry_run_sink | automation fault is replayed without rail movement | every route distinguishes simulation from physical execution | duplicate_pulse_diverted_to_sink | dry_run_sink_attestation_required |
| manual_rail_recall_before_restart | physical position becomes the restart gate | operator burden and show delay | manual_rail_recall_completed | operator_witness_before_restart_required |
| accept_duplicate_execution_default | recovery remains on schedule | second movement and broadcast-reality scar become pending | duplicate_execution_pending | duplicate_execution_default_pending |
Every constructive branch preserves physical execution count at one. The default is the only branch that permits a second actuation in the same execution epoch.
Authority boundary
The ledger can prove the operational chronology and actuation count of F-27 / R6. It cannot establish caller identity from initials alone, caller authority, authorship, performer consent, rigging clearance, edit permission, sponsor clearance, archive ownership, blame, or universal broadcast permission.
Missability and recovery
The seam becomes missable if the carbon stack is separated before pressure order is photographed, the blue ingest loses its source bundle link, motor telemetry rolls over, or R6 emits the second pulse before the review opens. A new caller key cannot retroactively clean the old execution. A new hardware latch protects future epochs but cannot erase an aired second movement.
This is not a recruitment storyline. Rowan Neri and Rhea Noll are evidence-bearing caller roles; resolving the line neither recruits them nor manufactures authority or consent.
Replay expectation
The durable replay must put all eight exact cards in the current hand, assign them to their exact slots, select bind_single_execution_chronology, and emit single_execution_chronology_bound plus cue_instance_checksum_required. Focused runtime evidence must also execute all eight branches, reject wrong, duplicate, missing, catalog-only, out-of-hand, and omitted-choice attempts, close the one-shot rite, and execute both default outcomes.