music/DEATH_CHOICE_RUNTIME_SPEC.md
CANON SUBORDINATION — this document is PROPOSAL-TIER: it serves canon and never outranks it.
The canon: the CVD · the T1 foundation docs · the T0 registries (registries/) · the spine
(docs/spine/CH_*.md) · the region pages (_source/02_Tier_2_Region_Pages/). Authority order:docs/DOC_MAP.md§ 0.
Canon served (scanned from this document's own citations — widen it by hand where it is thin):
CVD §5·CVD §17·T1_Ability_Tree·T1_Combat_System_Spec·T1_Integrity_Paths_Worldstates_Master· (+3 more tier) ·T0_Ability_Tree_Registry·T0_Ally_Behavior_Policy·T0_Bonus_Option_Registry·T0_Bonus_Pool_Registry· (+10 more t0)
READ THAT CANON FIRST — open it and derive from it before you build anything from this document.
If this document disagrees with canon, CANON WINS and this document is the defect — fix the
document, never the canon. Nothing here is applied until it is ratified into canon.
Status: PROPOSAL-TIER engineering contract. SPEC-ONLY — no runtime code lands here; the 5090 build
implements against this. Authored 2026-07-29 under the ruled canon of the 2026-07-27 second and
third sittings. REVISED 2026-07-29 against the fresh-context critic round.
Authority order applied throughout: CVD wins, then T1 domain docs, then T0 registries, then T99
operational. Every clause below carries either a RULED citation (Josh's own words, cited to the
DECISIONS record) or a DERIVED marker naming the doc it is derived under. Nothing numerical,
nothing named, and nothing that would change a Josh ruling is decided here — those are §12.
ENGINE REPO ROOT. Every Source/... and Tools/... path in this document is relative to
C:/dev/Humanity/Humanity, the UE game repository — NOT to C:/dev/humanity-forgotten, the canon
repository this document lives in. A reader who follows an engine path from the canon repo finds
nothing. All UE line numbers are pinned to the 2026-07-29 working tree. Canon paths
(docs/..., registries/..., harness/..., _source/...) are relative to the canon repo as usual.
REVISION RECORD. This is the post-critic revision; every finding of the 2026-07-29 fresh-context
critic round is applied. Two of them were director calls rather than author fixes, and both are
recorded in place rather than silently resolved:
downed_target_policy=execute collision is now a genuine fork at §12 D-8, with thedirector's recommendation (execute ACCELERATES the countdown rather than terminating it) carried
into §2.2 as a PROVISIONAL transition row so the state machine is complete against §10.
of FORKB §3.11 disclosed in full at §2.2 and §12 D-4.
---
These are Josh's rulings, quoted or paraphrased to their citation. Every later section is
execution under them.
progress and the protagonist is resisting it. No two-button prompt, no modal, no wait-versus-return
menu. Doing nothing is doing the thing the fiction describes. [RULED — docs/spine/DECISIONS_PENDING_JOSH.md
L748-753, "RULED 2026-07-27 (second sitting)" J-1; restated at docs/proposals/PRESENTATION_DOCTRINE.md
§0.B.1a]
press; it is never the no-input default; it never becomes unavailable. [RULED — DECISIONS J-1;
PRESENTATION_DOCTRINE §0.B.1a; the never-fails property is the no-dead-end floor at
docs/pipeline_review/FORKB_RESURRECTION_BRIEF_2026-07-27.md §3.11]
protagonist can hold. Josh's words: "maybe after 2 minutes you can't hold on any longer,"
surfaced as "XX seconds until you cannot hold on any longer." The two-minute figure is a SEED;
the magnitude is Phase-5M. [RULED — DECISIONS J-1 L749-752]
J-1, "Timeout = the withdrawal completes to the checkpoint"]
raw combat outcome for a persona'd character, UNLESS an integrity-based departure or story
outcome has a persona'd character die — that lane is explicit and legal. The boundary is the
community-ripple event. [RULED — DECISIONS J-2, with Josh's exception clause]
(Reading A holds). She is the one who brings you back to the revival location, checkpoint and
recharge zone; the let-go and timeout paths are diegetically HERS. [RULED — DECISIONS J-3, Josh's
own third reading; the non-vril lock at _source/03_Tier_3_Characters/T3_Core_Characters [ACTIVE v1.0]
§3.4, "no combat ability, vril, or weapon is gained"]
COUNTDOWN WINDOW. Chain-meter bosses whose win conditions are player-performed still cannot end
without the player. [RULED — DECISIONS J-5]
kill you; the healer's child rescued you. [RULED — DECISIONS J-6]
field. Its provenance is Josh-authored — it was the mother's, passed at the birth, given onward.
[RULED — DECISIONS J-6 plus "RULED 2026-07-27 (third sitting)"; the six ward rows are already on
disk at registries/T0_Ally_Behavior_Policy [DRAFT v0.1]/Sheet1.csv AP_0009 through AP_0014]
Two upstream doctrines this machine must not breach, both already ruled elsewhere:
to the LAST ATTUNED recharge source. [docs/translation/T99_Translation_Combat.md §2.5 L157-164;
CVD §5 Pillar 8; docs/PRE_5090_BUILD_PLAN_VOL2.md SL-1]
condition_expr may read a loyalty worldstate key, and policy_source is a closed enum with no player-authored
member. Both are already armed in harness/check_ally_build.py B5. The revive policy therefore
may not be loyalty-gated and may not be player-authored.
---
Naming precision here is load-bearing: three of these words already exist in the corpus with
different meanings, and conflating them is how a future author legalises in-combat player
resurrection by accident.
allies. Writes no community ripple. [DECISIONS J-2]
authored story outcome. Never a raw combat result for a persona'd character. Writes the
community-ripple event, and that write IS the boundary. [DECISIONS J-2 with the exception clause]
unchosen, unpaused.
Requires the encounter to be resolved. Canon rows: A_A_009 Breath of Life, A_C_003 Vril
Revival, A_C_004 Vril Mass Revival in registries/T0_Ability_Tree_Registry [ACTIVE v0.1].
healer's child's act and hers alone. It is the resolution of both the let-go press and the
timeout. It is NOT a revive and must never be schema-expressed as one. [DECISIONS J-3]
The distinction REVIVE-versus-RESCUE is the single most abusable ambiguity in this feature. A
schema that lets one row express both will eventually be read as licensing a non-vril combat
revival, which contradicts T3_Core_Characters §3.4. §7 makes the two unspellable as one another.
---
The machine has six states. The presentation names for them are already ruled at
PRESENTATION_DOCTRINE §0.B (S0 the fall, S1 the low hold, S2 the wait, S3 the rise, S4 the cut,
S5 the dissolve); this spec keeps those names so the two documents do not fork.
not a decision window; LET GO is already accepted here. The camera inherits the fall and settles
on an arena-biased yaw. [PRESENTATION_DOCTRINE §0.B.2 — a build requirement, not a detail]
frame, and an eligible ally may resolve the encounter and then reach the body.
checkpoint anchor. Terminal.
rises with the body. Terminal.
consolation surface fire exactly once. Not player-visible as a state.
| From | Event | Guard | To | Side effects |
|---|---|---|---|---|
| D0 | health reaches 0 | player is not already DOWNED (re-entrancy guard, §2.6) | D1 | arm the downed pawn contract (§2.5); snapshot attempt_index; start the world-advance clock read; do NOT arm any respawn timer |
| D1 | fall settle elapses | always | D2 | start the hold clock; open the LET GO input; open the ally-resolution loop |
| D1 or D2 | LET GO pressed | none — always legal | D3 | stop the clock; record outcome=let_go |
| D2 | hold clock reaches zero | LET GO not pressed and no revive landed | D3 | record outcome=timeout |
| D2 | eligible ally completes revive | §4 eligibility resolves TRUE and the clock has not reached zero | D4 | record outcome=ally_revive; apply reduced vitality; apply ally exhaustion |
| D2 | eligibility resolves PERMANENTLY IMPOSSIBLE | §4.5 impossibility test, which reads gates 1, 2 and 3 ONLY | D2 for the bounded honest-failure window (§9.3), then D3 | record outcome=timeout with ally_reach=impossible; the hold clock is TRUNCATED to that window rather than run to zero; LET GO stays live for every frame of it [RESOLVED — §12 D-4, director's call 2026-07-29] |
| D2 | a hostile carrying downed_target_policy=execute completes its execution on the body | the hostile is live and in contact, the execute windup completed, and the encounter is unresolved | D2 with the hold clock STEPPED DOWN [PROVISIONAL — PENDING §12 D-8] | apply the authored execute step to the hold clock (magnitude Phase-5M, §12 D-3); record execute_pressure_applied on the ledger entry; if the step drives the clock to zero the clock-zero row above fires unchanged and resolves to D3 with outcome=timeout |
| D3 or D4 | terminal frame | ledger not yet appended for this death_event_id | D5 | one idempotent ledger append; one world-advance delta; one consolation resolution |
Three properties of this table are load-bearing, and each closes a named defect. The first is
non-negotiable canon. The second and third are this round's director dispositions, recorded as such
rather than asserted as floor — the pre-revision draft declared the second non-negotiable HERE while
listing it as an open fork at §12, and a document cannot hold both.
or luck that produces a dead end does not exist, by construction. [FORKB §3.11; assert in
harness/check_no_dead_end.py, tooth T-6]
honest-failure read is selected by the first failed gate and plays to its authored length, and the
hold then resolves — the clock is not run out behind an image that has already finished.
DISCLOSURE OF THE REVERSAL HISTORY, so no future reader re-derives either position from silence:
docs/pipeline_review/FORKB_RESURRECTION_BRIEF_2026-07-27.md §3.11 L274 reads "W6 IMPOSSIBLE must
fail fast and honestly — never run a timer out on a player who was never going to be revived." The
pre-revision draft of this spec REVERSED that clause, running the full clock and re-scoping "fast"
to mean the READ arriving fast rather than the state ending early. The 2026-07-29 fresh-context
critic round caught the reversal, and the director ruled: adopt FORKB §3.11's reasoning — never run
a timer on a player who cannot be revived. The reversal is WITHDRAWN. What survives from the
draft's argument is its honesty half, in full: waiting still shows the player something, the image
is never replaced by a cut to black, and LET GO is never gated (PRESENTATION_DOCTRINE §0.B.2). The
accepted cost is named at §12 D-4.
execute row is RULED (twenty-first sitting) and implements §12 D-8's (b)(acceleration, not termination) so the machine is complete against §10 case 14 while the fork
stays genuinely open. It is not a settled behaviour and must not be read as one.
withdrawal_timer step and every other combat magnitude is firewalled at
docs/translation/T99_Translation_Combat.md §8.1. [RULED as a seed — DECISIONS J-1, "the 2-minute
figure is a seed; magnitude Phase-5M"]
phase, or a difficulty tier. A clock that stretches when help is near converts a conditional
system into a hidden roll, which is the exact defect FORKB §3.10 exists to prevent. Exactly two
authored SHORTENINGS exist — the impossibility truncation (§2.2, §4.5, §12 D-4) and, pending §12
D-8, the execute step (§10 case 14). Both are deterministic, both are visible on the surface as
the number moving or the state resolving, and neither is a roll. A shortening the player can SEE
is not a hidden roll; an extension the player cannot see is.
moment of encounter resolution, never as a separate timer. [DECISIONS J-5]
dial — ambient vril density (Wellspring, Veiled, Fading, Sundered, The Forgotten One) — through
the ALLY's vril availability, never through the player's hold duration. [FORKB §3.13; the ladder
at docs/COMBAT_ENCOUNTER_SYSTEM.md §9 L238-245]. The composition with the world-advance clock is
stated explicitly at §3.3, because leaving it to the implementer would breach this firewall
through the back door.
including movement, camera, ability, interact and menu-open.
and not a twitch window. It is fully remappable and one-handed reachable.
[docs/proposals/PRESENTATION_DOCTRINE.md §0.B accessibility floor, inheriting the ratified
Attunements options canon]
from the pad, or on assistive input resolves to the rescue at the clock. [RULED-TIER BY PLACEMENT —
docs/proposals/PRESENTATION_DOCTRINE.md §0.B.1a L143-145, inside the THE RULED CLAUSES block. The
provenance is stated precisely because §12 D-8 turns on this clause's authority: it is NOT in
DECISIONS J-1 and is not Josh's own words. Its own SRC at that line is "FORKB brief §3.11, the
let-go path never fails" — it is a doctrine-ELEVATED derivation, ruled-tier by where it sits, not
by who wrote it.]
PRE-SELECTED on a surface that offers one, never availability. Since the ruled surface offers a
single press with no default alternative, this preference has no effect here and must not be
implemented as an auto-press. [DERIVED under FORKB §4]
clock both stop with the game; neither is a real-time clock.
While in D1 through D4 the player pawn:
IsDowned() as a distinct query from the existing bPlayerDead (Humanity/Source/Humanity/Public/Core/HumanityCharacter.h L391 area) so QA and the HUD can tell
the two apart;
hypothetical: AP_0001 in registries/T0_Ally_Behavior_Policy [DRAFT v0.1]/Sheet1.csv reads
ws.integrity_level in [L1_TRULY_GOOD,L2_GOOD_ENOUGH] & flag(local.player_health_at_or_below_50)
and dispatches interpose autonomously. A player at HP 0 satisfies "at or below 50," so on the
day a downed state exists the L1/L2 familiar interposes for a downed player forever. Either the
downed state is excluded from the health-fraction producer, or AP_0001 and AP_0005 are
re-scoped IN THE SAME COMMIT. [FORKB §3.5; tooth T-3 with its must-not-fire twin]
Note that downed_target_policy=execute (§7 touch 12, §10 case 14, §12 D-8) is the one sanctioned
exception to the perception clause above: an execute-policy hostile acts on the BODY, which is a
policy-driven behaviour rather than a perception hit. The two must not be reconciled by making the
downed pawn perceivable, or the interpose defect and the aggro contract both re-open.
The death delegate binds from both PossessedBy and OnRep_PlayerState, guarded only by
bDeathDelegateBound (Humanity/Source/Humanity/Private/Core/HumanityCharacter.cpp L219-225).
Two ledger rows means the world-advance delta applies twice.
death_event_id is minted at the D0-to-D1 edge and is the idempotency key for the ledgerappend, the world delta, the consolation resolution, and the telemetry record.
second death_event_id.
HandlePlayerDeath() starts a 0.55 s fade and arms RespawnTimerHandle for
DeathFadeSeconds + RespawnHoldSeconds (0.55 + 0.9 = 1.45 s) to RespawnAtNearestSite()
(HumanityCharacter.cpp L281-320; constants at HumanityCharacter.h L394-395). The ruled machine
has no state that timer occupies, and the fade is retired.
[PRESENTATION_DOCTRINE §0.B.1b "THE SHIPPED FADE IS RETIRED"]
RespawnAtNearestSite() iterates every AHumanitySiteMarker and picks the minimum
FVector::DistSquared (HumanityCharacter.cpp L322-340). Canon says the LAST ATTUNED recharge
source (docs/translation/T99_Translation_Combat.md §2.5 L161-162). Nearest is not last; a nearer
marker can teleport the player PAST the content they just failed.
recomputed nearest. The recommended anchor class is the vril site itself, because it is already
ruled as save, recharge and loadout sanctum, so one anchor serves three ruled systems and it is
the same place an ally's vril refills. AHumanityVrilRechargeZone already carries VrilSiteId
(Humanity/Source/Humanity/Public/World/HumanityVrilRechargeZone.h L48-50), so the write site
exists today.
docs/DESIGN_GAP_REGISTER.md entry 113]
is corrupted on 30 of 42 rows and sequences this behind register entry 46. That corruption is a
prerequisite, not this spec's work.
---
One append per death_event_id, on ALL outcomes. The choice must not be cosmetic: today nothing is
written to world state on death, so both branches would produce the same empty delta, which is
meta-collapse applied to the defeat axis. [FORKB §3.9]
Proposed new append-only worldstate variable, on the WS_044 idiom, id allocated at the mint pass:
WS_047 defeat_ledger (object, append-only). Per-entry fields: death_event_id, chapter_ref, site_ref (soft-FK T0_Vril_Site_Registry.site_id),
encounter_ref (soft-FK T0_Boss_Encounter_Registry.boss_id, empty for a non-boss death),
attempt_index (integer, per encounter_ref, 1-based),
outcome in {let_go, timeout, ally_revive},
ally_reach in {reached, impossible, empty} (empty for outcomes where the question never arose),
combat_end_provenance in {defeated, leashed, retired, unresolved},
reviver_ref (soft-FK T0_Character_Index.character_id, empty unless outcome is ally_revive),
capability_ref (soft-FK T0_Ability_Tree_Registry.ability_id),
vril_paid_class, hold_elapsed_class, execute_pressure_applied (bool),
world_delta_ref, relationship_delta_ref, consolation_paid (bool).
Named landmine, restated to its REPAIRED state. The pre-revision draft carried the brief's
pre-fix framing forward verbatim while updating the count, which produced an internally incoherent
sentence — the exact "trust content, not labels" defect the repo's own discipline warns about, and
the 2026-07-29 critic round caught it. The actual state, read from
harness/check_ws_value_form.py L112-123: APPEND_LEGAL_IDS has been reconcile-and-extended
twice — 6 to 12 under Josh's D-CG25-APPEND-SET ruling (2026-07-24), then 12 to 14 at the ss7-12
schema mint (2026-07-27, the third precedent instance), where WS_044 bonus_respec_ledger and
WS_046 item_instance_ledger landed INSIDE the frozenset in the same commit as their rows. Both
ids are verifiably in the set today; the earlier self-declared deviation is REPAIRED
(MINT_APPLY_CRITIC MAJOR-2 fixed). The precedent is therefore established, not broken. The
ACTIONABLE instruction is unchanged and is the whole point: WS_047 makes it fifteen, and it must
be added to that frozenset in the SAME commit as its registry row, per the co-landing dependency
the comment block above the list already documents. [docs/pipeline_review/MINT_APPLY_CRITIC_2026-07-27.md
§A; FORKB §5.4 item 8; the same landmine named at docs/DESIGN_GAP_REGISTER.md entry 114]
WS_048 last_attuned_site (enum-or-string, soft-FK T0_Vril_Site_Registry.site_id, default thechapter's entry site). Written on every completed recharge channel; read by D3. Keyed-replace,
NOT append-legal.
The two branches must not be a better-versus-worse pair, or the player solves the surface once and
the choice becomes a tax. They carry DIFFERENT currencies. [FORKB §3.9]
advanced while you were down and it advanced further because you were carried back. Banked
tell-reads and the substrate-lore fragment pay out on this path (§6).
standing for you and that is remembered. It also carries the banked tell-reads, because the
learning economy is the reward-on-death rule and is not a branch prize.
repair relationships and invert the integrity system. Rule it explicitly in the owning doc
(T1_Integrity_Paths §8.11). [FORKB §3.6; RULED as loop-territory at FORKB §2.B]
made visible rather than a new cost: canon's density dial already tightens tells, slows wells and
prunes answers. [DERIVED under docs/COMBAT_ENCOUNTER_SYSTEM.md §9 L238-245 — the five diegetic
tiers and the four world-demand levers, telegraph slack, world generosity, answer-pruning and
withdrawal aggression — plus docs/translation/T99_Translation_Combat.md §8 L742, which defines
the withdrawal_timer step as vril_density -= step on expiry. Derivation source FORKB §3.1(a).
The pre-revision draft cited docs/RUNTIME_GENERATIVE_LAYER.md L133 for this claim; that line
carries only the deterministic-ownership fact — the executor owns vril_density, the arena cycle
clocks and the Withdrawal clock — and the pointer is narrowed to exactly that.]
withdrawal_timer, and this composition is stated rather than left to theimplementer because it is load-bearing in BOTH directions. T99 §8 L742 makes the
withdrawal_timer the mechanism that moves the one ruled difficulty dial. If lying downed
advanced that timer, the hold WOULD be a difficulty dial and §2.3's firewall would be breached
through the back door. It does not: the hold is bounded at roughly two minutes, it cannot be
farmed, and no vril_density decrement is charged for it. §2.3's firewall is literally true
because of this clause. [DERIVED call under T99 §8; named here so no implementer guesses]
you lie there is the WORLD-ADVANCE delta itself, which rides hold_elapsed_class on the ledger
entry — the ledger and opportunity layer: what moved, what the party lost, what the encounter
remembers. That is what stops waiting from strictly dominating, and it does the job without
touching the density ladder. [FORKB §3.1(a)]
docs/DESIGN_GAP_REGISTER.md entry 110 proposes that the per-encounter demand after N failed
attempts be non-increasing and that the graduated delta be authored on the WORLD, never on the
encounter you just failed, with the top two difficulty tiers explicitly untouched. That entry is
recorded CONTESTED-CARRIED, "director call before it enters the gate." This spec DOES NOT apply it;
it names the collision so the runtime is not built in a way that forecloses either answer: the world
delta and the encounter state are written through separate paths (§3.3), which is the shape both
readings need. [Register entry 110; the paired difficulty-ladder gap at entry 111]
---
Josh's direction reads "may be able to revive." That uncertainty is CONDITIONAL and never
probabilistic. A probabilistic revive would fall under HL_0061 and CVD §17.13 (the sigma bound, the
anti-streak floor, the mandatory success ceiling), which is heavy machinery bought to purchase a
worse feeling on the game's most emotional beat. All five FORKB analysts converged on this.
[FORKB §3.10]
from data, not from a roll.
departed and estranged companions cannot revive by construction because they are not on the
field. Below that, willingness is NOT bond-gated, because a policy condition_expr reading a
loyalty key is structurally illegal under check_ally_build.py B5(i). [FORKB §3, the two
firewalls and the recommended reconciliation]
does she peel the last threat off you first), never access. [Josh's INT-as-AI ruling 2026-07-26,
memory companion-familiar-stat-builds-ai-intelligence; FORKB §3.12]
Evaluated per tick in D2, per candidate ally, in this order. First failing gate stops the
evaluation and determines the honest-failure read (§9.3).
1. ON THE FIELD — the ally is instantiated and not departed or estranged (WS_027).
2. NOT DOWNED — the ally is not itself in a downed state.
3. CAPABLE — the ally's taught_capability_refs contains an ability row whose ability_class is
revival or revival_aoe and whose integrity_band_lock is satisfiable by the player's current
ws.integrity_level. Positive-controlled: an unreachable resolver must report as unreachable,
never as a clean zero. [The zero-reporting law, memory a-search-that-cannot-match-reports-zero]
4. ENCOUNTER RESOLVED — the out-of-combat predicate is TRUE (§5). This gates the ACTION, never the
surface. [FORKB §4, "do NOT gate the OPTION on combat state — gate the ACTION"]
5. HAS VRIL — the ally's current vril meets the ability's vril_cost_class. Not refillable in the
field; only at the vril site. This is the depletion-carried-forward tooth. [FORKB §3.1(b)]
6. CAN REACH — a navigable path to the body exists and can be traversed before the hold clock
reaches zero, at the ally's own movement speed. No teleport, no snap.
7. WITHIN THE CLOCK — the cast completes before the clock reaches zero. The revive is instant-cast
in the ability rows (A_C_003, A_C_004 carry instant,instant), so there is no channel to
interrupt and no progress meter belongs on the surface. [PRESENTATION_DOCTRINE §0.B.1b]
Every one of the seven is a property the player's own build and play determined before the death.
That is what makes the uncertainty honest.
Reported register-honestly, per the standing evidence discipline: until allies exist and a fight can
continue after the player falls, enemies de-aggro or leash from a body within seconds, so the
out-of-combat constraint is CORRECT but nearly FREE. Ship it anyway (retrofitting is expensive) and
never let a play-quality claim ride on it before party combat lands. [FORKB §5.2 B2 and §6 item 2]
out-of-combat predicate flips TRUE with combat_end_provenance=defeated, gate 4 opens, and the
revive may land if gates 5 through 7 also hold.
win_reward, mastery credit and tell-reads are attributed to the PLAYER's run in thatcase, because they are properties of the encounter's resolution and the run is the player's. The
ledger records combat_end_provenance=defeated so a later balance pass can separate
party-finished wins from player-finished wins without a second variable.
win_condition is player-performed CANNOT be resolved by an ally, so thepredicate never flips and the hold resolves to the rescue. The design disarms itself exactly where
an ally-undo would do the most damage. This is not a special case in the machine; it falls out of
gate 4. [DECISIONS J-5; the mechanism at FORKB §2.A J-5 — the pip-meter win conditions, Rangku's
FREE route as an integrity choice only the player can make, Naga Padoha's cosmic subdual]
full clock there, because a fight is live and the player is watching it (§10 case 13, §12 D-4).
ally_revive_policy in {allowed, denied} on the boss row, default allowed, EMPTY MEANS NOT-YET-POPULATED AND NEVER DENIED — the same discipline the pip columns
already carry. This is the toolbox form of FORKB Shape D, for the rare authored arena where an
in-place return would break the encounter economy. [FORKB §3.3 and §1 Shape D disposition]
Eligibility is PERMANENTLY IMPOSSIBLE for this death event when no candidate ally can pass gate 3
(nobody is capable) or when every candidate has failed gate 1 or 2 and cannot re-enter. THE TEST
READS GATES 1, 2 AND 3 ONLY. Gate-4 non-resolution — a fight still running, including the
chain-meter boss an ally can never finish — is explicitly NOT impossibility (§4.4, §10 case 13).
Widening the test to gate 4 would truncate exactly the wait that the "waiting always shows the
player something" requirement exists to protect, and that widening is the most likely way a future
implementer breaks this feature quietly.
The machine uses the test for two things:
authored length and the withdrawal then completes, rather than the clock running to zero behind an
image that has already finished. LET GO remains live for every frame of that window; T-6 is
unaffected. The window's magnitude is Phase-5M under §12 D-3.
In the Josh Gate slice this test returns IMPOSSIBLE on every death, because Ch 2 through 7 stay solo
as built, the earliest companion window is Ch 13, and the revival ladder sits at T5 of a twelve-tier
climb. The wait branch is present, honest, and resolves truthfully to "no one could reach you." That
is not a stub; it is the same machine with an empty roster — and D-4 is what keeps it from also
being a two-minute tax on every death in the only eleven chapters that exist. [FORKB §6 "THE
STRONGEST OBJECTION" and its answer; FORKB §3.11 restored per §12 D-4]
CHAR_0002, primary human companion, join Ch 13 per registries/T0_Character_Index [ACTIVE v1.1]) performs the RESCUE on the let-go and timeout paths.
She never appears in the §4.2 eligibility function, because she is not a reviver. [DECISIONS J-3]
through AP_0014 in T0_Ally_Behavior_Policy carry suppress_aggro, suppress_target_selection,
suppress_down_state, traverse_live_field, lapse_concealment and
yield_to_nonperceptual_harm, all on flag(local.ward_borne_and_holding), all
policy_source=canon_seed, all power_source=gear_imprint.
never a durability meter. A visible meter would convert a grief-object into a managed resource
and put a companion's life on a bar. (AP_0009 note)
is a carry, not an act of force, and the spec treats the carry as non-acting; if a future design
makes the carry an act, AP_0013 fires and the whole rescue path needs re-deriving. (AP_0013 note
— flagged here as the seam most likely to be broken silently)
rather than targets. A designer who wants the bearer in danger reaches for non-perceptual harm,
never for a ward-stripping mechanic. (AP_0014 note)
the concealment and the bearer being safe and hidden on the field. This spec consumes them at that
tier and does not promote them.
the player wakes at the anchor — with no carried image. The surface is bare and solitary early,
gains a record at Ch 13 when the journal activates, and gains a witness who can reach you later.
That growth is authored, not accidental. [FORKB §6; the journal timing at WS_009]
---
The predicate does not exist in code or canon today, and whatever gets built becomes gameable:
aggro-based invites kiting past the leash radius and dying outside it; damage-recency invites
breaking line of sight and waiting the timer out. Three concrete engine defects are already
identified: a fleeing enemy counts as aggroed (a timid animal holds combat open forever); a stalking
enemy does not (the standoff is exactly where a revive window is most wrong); and
bPerceivedThisFrame is frame-transient. [FORKB §3.4]
individual actor.
the single behaviour most likely to be wrong and least likely to be noticed. [Tooth T-4]
defeated, leashed, retired, unresolved. Provenance is written to theledger; the boolean is what predicates read.
being defeated, so a naive detector flips to ELIGIBLE because the level unloaded.
AHumanityEncounterVolume::EndPlay already retires what the volume spawned
(Humanity/Source/Humanity/Public/Combat/HumanityEncounterVolume.h L86, carrying the literal
"BUG-0018: retire what this volume spawned" comment). The predicate must read that retirement as
retired, never as defeated, and the existing GuardianTeardownOnEndPlay test is extended to
prove it. [FORKB §3.4; tooth T-5]
FORKB §5.4 item 7 records the predicate as a GRAMMAR CHANGE and warns that flag(local.*) would
fail a produce-before-consume lint or need a fake producer. Direct inspection says the cost is
lower than that:
read(surface) is ALREADY first-class on both sides — harness/condition_expr.py L28-41 (the EBNF) and L377 (the Read node), and Humanity/Source/Humanity/Private/Quest/ConditionExpr.cpp
L288 and L571 with TSet<FString> Reads at ConditionExpr.h L45. No parser work is required on
either side.
harness/check_spine_graph.py L328-334 and applies to SPINE BEAT files, not to T0_Ally_Behavior_Policy rows. Gate 29 B3 parses policy condition_expr
and does not require a producer. The existing policy rows already consume runtime-produced flags
with no beat producer anywhere: flag(local.enemy_attack_telegraph_visible) (AP_0006) and
flag(local.arena_state_changed) (AP_0008).
flag(local.encounter_resolved) on the policy row,following the AP_0006 and AP_0008 precedent exactly, with zero grammar change and zero fake
producer. The competing option is read(...), but the grammar doc defines read(surface) as
"the named surface (an inscription or readable object) has been read"
(docs/CONDITION_EXPRESSION_GRAMMAR.md L63-64), so reusing it for combat state is a semantic
collision in a shared vocabulary. See fork D-1 in §12.
than silently matching nothing — which is precisely the failure this feature cannot afford, since
a silently-never-matching predicate is a revive that silently never fires.
---
death_reward is a populated column on T0_Boss_Encounter_Registry — 281 of 281 rows, 264 distinct values. [docs/DESIGN_GAP_REGISTER.md entry 109]
AHumanityCharacter::ResolveActiveFightConsolation() walks live bosses and returns the active boss's death_reward line; HandlePlayerDeath() records it as a telemetry quest event and arms a
6-second HUD display window after respawn (HumanityCharacter.cpp L281-320 and L360-372;
ConsolationDisplaySeconds=6.0f at HumanityCharacter.h L400).
DEFEATED (no fail wall) -- %s (Humanity/Source/Humanity/Private/UI/HumanityDebugHUD.cpp L600).
WS_041 composure_node_mastery and `WS_042 banked_tell_reads exist in T0_Worldstate_Variables` and have ZERO writers. [Register entry 108]
economy (CVD §5 Pillar 8; T99_Translation_Combat §2.5), not a branch prize. On the revive path the
on-screen consolation line is REPLACED by the companion's own words, and the journal entry still
records the observation — one authored string, two lengths, one write. [FORKB §2.B and §4]
WS_041 and WS_042 through the existing worldstate subsystem at the HandlePlayerDeath call site, keyed boss id to the composure-node ids
already populated on the boss row's composure_nodes column. Zero new schema, zero new registry,
one call site, and the load-bearing half of the defeat economy. [Register entry 108]
death_reward currently resolves to one sentence forever because the resolver has no attempt index. Ride the ledger's attempt_index and let the payout become a small
ordered set per encounter: the first death teaches the tell, a later one names the counter, later
ones stay short. Only the cardinality of one field changes. SEQUENCING IS THE REAL VALUE — do this
BEFORE the natural-voice pass rewrites 281 strings, or the rewrite is paid twice.
[Register entry 109]
consolation_paid on the ledger entry prevents the same line repeating within one encounter instance across repeated deaths at the same attempt_index.
[FORKB §5.4 item 15]
FORKB §2.C records an analyst contradiction: one analyst specified a PLAYER-side 1-HP clamp in
protected chapters (build item A8, QA test T10), another showed that defeat_protected and the 1-HP
clamp are a BOSS column — the boss withdraws at 1 HP — and are not player-death protection. The
boss-column read is the better-evidenced one, and it is now proven from data rather than argued:
docs/PRE_5090_BUILD_PLAN.md L1425-1426 records "The defeat_protected flagship VERIFIED FROM DATA:
Naga Padoha's TRUE row drives the 1-HP clamp + WITHDRAWN" with the
Humanity.Combat.DefeatProtectedFromData test green, and docs/FUN_REBUILD_PLAN.md L370-372 names
that row as the slice's one 1-HP-clamp defeat_protected boss.
T0_Boss_Encounter_Registry, defeat_protected reads 265 EMPTY, 15 FALSE, 1 TRUE. The single
TRUE row is BE_0005_S3, Naga Padoha, the bound earth-shaker. The pre-revision draft said the
column carried "FALSE on the inspected rows," which read as if no TRUE row existed; one does, it
is the flagship, and it changes nothing about the conclusion — the clamp is on the BOSS, not on
the player.
treats empty as unset has no default at all, and this spec is scrupulous about exactly that
elsewhere. The rule is the same one §4.4 and §10 case 12 apply to ally_revive_policy: an empty
cell is authoring debt, the runtime reads it as FALSE, and only an explicit TRUE clamps. Stated
here so the "only legal source" clause below is complete rather than half a rule.
encounter, and the ruled machine runs there unchanged. A8 and T10 stay struck.
bDefeatProtected was derived from death_reward being empty, which mis-classes any boss carrying a populated death_reward
(BUG-0014). Since death_reward is now populated on 281 of 281 rows, that derivation is dead by
construction and the explicit defeat_protected column is the only legal source — read under the
empty-cell rule above. [docs/FUN_REBUILD_PLAN.md L47-50 and L283-290]
---
All new columns land as Vector-C extensions declared in docs/registry_extensions.json under a
named owning system, plus docs/fidelity_baseline.json added_columns, plus
registry_fidelity.py --emit-baseline in the SAME commit. Proposed extension key for every row
below: death-choice.
| # | Target | Change | Status | Note |
|---|---|---|---|---|
| 1 | T0_Worldstate_Variables | new row WS_047 defeat_ledger (object, append-only) | NEW ROW + APPEND_LEGAL_IDS extension in the same commit | §3.1; 14 to 15 on an already-repaired precedent |
| 2 | T0_Worldstate_Variables | new row WS_048 last_attuned_site (string soft-FK, keyed-replace, NOT append-legal) | NEW ROW | §2.7, §3.2 |
| 3 | T0_Ability_Tree_Registry | new columns caster_class_scope in {protagonist, ally, both}, revival_direction_scope in {to_ally, to_protagonist, both}, out_of_combat_only (bool) | NEW COLUMNS | The asymmetry MUST be schema-expressed or a future author collapses the two directions and silently legalises in-combat player revival [FORKB §5.4 item 3] |
| 4 | T0_Ability_Tree_Registry | populate the three new columns on A_A_009, A_C_003, A_C_004 and mint the L3/L4/L5 alternate-route rows | POPULATE + MINT | The evil-lane hole is a no-dead-end violation waiting to ship; canon already declares the lane exists [T1_Ability_Tree L848; DECISIONS J-4] |
| 5 | T0_Bonus_Pool_Registry / T0_Bonus_Option_Registry | new rows: pick_class=major, lane=B, unlock_gate_quest_ref populated (this is "taught"), spec_purpose_refs, respec_class | EXISTING COLUMNS, NEW ROWS | Access is taught, reliability is trained; a MAJOR pick that competes with other majors, never a character's identity [FORKB §3.12] |
| 6 | T0_Ally_Behavior_Policy | new rows action_ref=revive_protagonist, domain=proactivity, autonomy_band=autonomous, disposition_legal_set=protective, int_tier/unlock_int_min populated, policy_source=canon_seed | EXISTING COLUMNS, NEW ROWS | Structurally identical to AP_0001; the condition carries the out-of-combat token per §5.3 |
| 7 | T0_Ally_Behavior_Policy | re-scope AP_0001 and AP_0005 so a DOWNED player does not satisfy the health-fraction predicate | EDIT IN PLACE, SAME COMMIT as the downed state | §2.5; FORKB §3.5 |
| 8 | T0_Familiar_Bond_Ability | a revival rung | BLOCKED | These rows are COPY-ONLY from T3_Familiars_Named §1.6. A revival rung cannot be invented in the registry; it needs a living-source T3 edit. Gate 29 B2 polices 22 x 5 coverage. [FORKB §5.4 item 5] |
| 9 | T0_Spec_Purpose_Registry | new row SPEC_VRIL_REVIVE_ALLY (function_class=heal, scope_class=single, role_axis_ref=ROLE_SINGLE_HEAL) | NEW ROW | Without it the build-space sweeps cannot count revival builds as a distinct viable spec, and an uncounted spec is invisible to the balance teeth. Existing ids are token-named (SPEC_VRIL_HEAL_PERSONAL and five others), so the naming pattern holds |
| 10 | T0_Boss_Encounter_Registry | new column ally_revive_policy in {allowed, denied} on the proven combat-encounter rail | NEW COLUMN | Default allowed; EMPTY = not-yet-populated, NEVER denied §4.4 |
| 11 | T0_Boss_Encounter_Registry | death_reward cardinality: one value becomes a small ordered set keyed by attempt_index | COLUMN SEMANTICS + AUTHORING | Do it BEFORE the natural-voice pass touches 281 strings §6.2 |
| 12 | T0_Creature_Roster | new column downed_target_policy in {disengage, execute, guard, ignore} | NEW COLUMN, BLOCKING | Rides the missing non-boss aggro block, DESIGN_GAP_REGISTER gap #1, owner W-SPACE. execute is what lets the wait end worse than letting go, with no die roll — but its interaction with the ruled countdown is NOT settled: the column mints regardless, the BEHAVIOUR waits on §12 D-8 |
| 13 | T0_Status_Table | new rows: the player's reduced-vitality return; the ally's post-revive exhaustion | NEW ROWS | Successive revives return progressively less and leave a lingering impairment on the ALLY, so chaining is self-defeating without a counter to game or a number the UI must show. Existing ids run ST_001 through ST_010 |
| 14 | T0_Role_Composition_Rule | one row asserting a viable glass-damage composition WITHOUT a revive-capable ally | NEW ROW | The anti-mandatory-support tooth [FORKB §3.12]; existing ids run RCR_001 through RCR_004 |
| 15 | T0_Voice_Registry | register for the countdown line and the companion's revive line | REFERENCE | The strings themselves live in the sidecars §8 |
| 16 | WS_027 companion_roster_state, WS_012 familiar_bond_state | new sub-field taught_capability_refs; derived revival_readiness | NEW SUB-FIELDS | WS_012's vril_integration_state (latent, developing, integrated) is already the teaching ladder. CROSS-SPEC, and the ratified line wins: WS_027 is the single canonical home for per-companion state per T1_Integrity_Paths_Worldstates_Master [ACTIVE v2.1] §8.11.6 L581 — persistence rides the per-companion roster object at WS_027, which carries loadout state alongside the loyalty fields once the schema pass authors the columns. This spec AUTHORS ITS COLUMNS THERE and never relocates the object; the loadout-sets spec authors its own columns on the same row in the same pass. One home, one pass, no second mint. The ratified standing bar binds both: until the pass lands, no consumer may read a field that does not yet exist |
| 17 | docs/DESIGN_GAP_REGISTER.md entry 114 — telemetry enrolment | enrol WS_047 as a TELEMETRY-VISIBLE surface beside the existing six recorders, and assert the entry's two magnitude-free properties: NO ATTEMPT PAID NOTHING, and the world delta applied EXACTLY ONCE per attempt | ENROLMENT, NOT A NEW REGISTRY | Entry 114 is the QA-LOOP OWNER of this artifact's outcome-and-economy axis ("the telemetry family is exactly six recorders and none of them observes an outcome"). Teeth T-9 and T-7 are the executable form of its two properties. Naming 114 here is what keeps the two documents from forking, and the entry's own named landmine is row #1's APPEND_LEGAL_IDS co-landing. Entry 114's boundary is pre-blessed by its adjudication 4: the run-ECONOMY axis, deliberately orthogonal to per-attempt execution-surface latency |
Canon edits, each critic-gated before it lands:
T1_Ability_Tree §11.7 — the ally-cast, out-of-combat, protagonist-target case and the reason(a companion holds no Enhanced Ability Mastery because the infinite-vital-energy devices bond to
the protagonist's vril-seat equipment only, so no Crown-seat channel survives combat pressure).
T1_Ability_Tree §5I.2 — the spec purpose.T1_Integrity_Paths §8.11 — THE OWNING HOME: the CAN/WILL/HOW-WELL split, the loyalty-state legalset, the DOWNED-versus-DEAD line with Josh's story-death exception clause, and the zero-bond-movement
rule. The WS_027 column expansion authors at the same schema pass §8.11.6 already names.
T1_Combat_System_Spec failure states — the hold state, the out-of-combat condition, the density coupling, and the §3.3 clause that the hold does not step withdrawal_timer.
T1_UI_UX_Spec — currently a two-line empty stub, and this surface is its natural first realcontent, alongside the vril-polarity readability floor already earmarked for it. Register entry 112
routes it into the same rank-20 fill as the gameplay-camera, onboarding and HUD-legibility findings:
same doc, same pass, one owner, never a second lane.
docs/DOC_MAP.md — a row plus a named consumer for every new artifact.---
The player strings live in docs/spine/player_strings/CH_NN.csv with the columns
kind,key,player_text (verified on CH_01 through CH_05 and CH_PROLOGUE). The death surface needs a
new kind, because these strings are surface-scoped rather than beat-scoped.
kind=defeat, keys prefixed DEATH_. Chapter-scoped so the voice can be culturallyregistered per region, which the natural-voice doctrine requires.
line per attempt_index; the companion's revive line.
on any longer" is the READ to be delivered, never the string to bake. It goes through the
natural-voice register and must land in the protagonist's own first-person voice — a person's
failing strength, not a system message. [DECISIONS J-1; PRESENTATION_DOCTRINE §0.B.1a and the
§3.2 defeat row's explicit SEED-NOT-SHIPPABLE-WORDING marker]
"Go back." Two opposites, both what a person actually thinks, neither naming a system, and
critically neither PROMISING rescue, so the honest-failure cases do not read as broken promises.
[FORKB §4]
string that EXPLAINS what death is hands the player Layer-3 metaphysics on a surface they will
see fifty times. The return is SHOWN, never explained. Canon models this exactly: the four
revival ability rows describe what happens and never what it means.
internal tokens and never appear on the surface.
harness/check_reveal_discipline.py WHO_SOFT.
DEFEATED (no fail wall) -- %s. Three defects in one greybox line: "no fail wall"is internal design vocabulary on a player-facing frame (naming the mercy destroys it),
"DEFEATED" is system voice, and the consolation payload is system voice too.
bringing someone back is one adjective away from theology. Relief, reproach and exhaustion —
never cosmology. It takes the natural-voice pass with string_status tracked AND the reveal gate.
the state, and not the boss. BE_0002 carries boss_name "Rangku Wera, the Quiet Step" and
display_name "the one who tracks me" — the surface draws the diegetic name or no name, never the
registry name. [DECISIONS J-7; the registry values verified in T0_Boss_Encounter_Registry row
BE_0002]
---
The presentation is already RULED at docs/proposals/PRESENTATION_DOCTRINE.md §0.B and is not
re-authored here. What follows is only the runtime contract the UI layer must satisfy.
Exactly two authored elements and no third: THE VOICE (the countdown read, at the EDGE of frame,
never a centre-of-screen meter) and THE CHOICE (LET GO). No mode taxonomy, no ability name, no
state name, no nameplate, no greyed second option. [DECISIONS J-7; the no-mode-taxonomy rule at
memory no-mode-taxonomy-on-player-surfaces]
that keeps the last look stares at a wall for half of all deaths and the wait reads as broken.
This is a build requirement, not a polish item.
point of the state is that the player can SEE whether anyone is coming.
you see them. If nobody is out there, you see empty ground.
A wait that resolves into nothing is indistinguishable from a bug, and not being able to tell IS the
failure. The read is selected by which §4.2 gate failed first:
| First failed gate | The image |
|---|---|
| 4 (encounter unresolved) | the ally still fighting; you watch them try and fail to disengage |
| 6 (cannot reach) | the near-miss |
| 5 (no vril) | they arrive, kneel, and cannot |
| 3 (never learned it) | they arrive, kneel, hold on, and stay with you while the draw takes |
| 1 or 2 (dead or departed) | empty ground where they would have been; say nothing; the absence is the memory |
Per §12 D-4, the selected image PLAYS TO ITS AUTHORED LENGTH, and in the permanently-impossible case
(gates 1, 2 or 3) the hold then RESOLVES rather than running the clock out behind an image that has
already finished. The image is the load-bearing part; the silence after it was not. The gate-4 read
is the exception and it runs the full clock, because that fight is still happening in front of the
player (§4.4, §4.5, §10 case 13).
If these images are cut for budget, the "it is a slot machine" objection becomes correct and the
feature should not ship. [PRESENTATION_DOCTRINE §0.B.2; FORKB §4]
The death surface is the highest-frequency player-facing text in the game and it fires from Ch 2.
Five named risks, in severity order, carried forward as build constraints:
pulse, a light, a sense of being held, the collective reaching for you — is exactly HL_0046's
Grand Sage communication vocabulary (visions, intuition pulses, vibrational imprints), deployed on
a surface visited dozens of times before Ch 76. HL_0044's protection assumes hints are rare enough
to police individually; a death screen played 200 times is a drip.
harness/check_reveal_discipline.py reads canon artifacts, not runtime presentation, so this is a
MAJOR-class hazard the existing gates would NOT catch. The surface takes its own named entry in
the reveal-discipline baseline. [FORKB §4 R1b]
Duat Ch 69, the Realm Road Ch 70-74). Keep the revive VITAL AND MEDICAL, never mythic: someone
catching you, not someone raising you. The resonance is allowed to exist and a player who read the
Osiris material will feel it — that feeling is the payload, and naming it destroys it.
familiar reveal. The death-and-wake loop rhymes with the Ch-2 opening ("Get up. Climb toward the
light." — verified live in docs/spine/player_strings/CH_02.csv beat CH02_B01), which is a free
presentation asset with a hard constraint: it must never re-stage the familiar's death image or
gesture at it.
(Astral Projection) and leaks a Crown-seat capability the player does not have. Pre-Ch-15 the read
is body-and-senses: the world greys, sound muffles, edges go soft. Not a soul leaving — a vessel
emptying.
Options are TEXT plus a distinct input, never colour-coded or icon-only. The companion's approach
needs TWO INDEPENDENT CHANNELS (silhouette and motion in frame, which is what the arena-biased yaw
buys, AND audio). The diegetic vignette timer needs an explicit duration-indicator backstop for low
vision. The dark hold into a bright vril close-up is a PHOTOSENSITIVITY RISK BY CONSTRUCTION and
needs a reduced-intensity variant — a hard floor item on the most-repeated surface in the game.
Motion sliders inherit. No hold-to-confirm-only, no twitch window, full remap, one-handed reachable.
BUG-0017's single-framed-overlay invariant has an unruled collision: dying during a held scene, or
dying with a fork pending. Recommended precedence, applied here as reversible: THE DEFEAT SURFACE
OUTRANKS BOTH. Also, CP-6 needs one clarifying clause, because the hold can outlast the arc-reveal
hold: the hold is a player-paced live-world state OUTSIDE the hold-class ordinal ladder (closer to
CC-9 dwell), or a future author will read a contradiction into a ruled doc. [FORKB §4 doctrine deltas]
---
Each one names the behaviour and its reason. These are the cases a runtime gets wrong silently.
1. Death by environmental hazard or fall damage with no encounter active — the machine runs
normally; encounter_ref is empty, combat_end_provenance=unresolved, and no boss consolation
resolves. The world delta still applies; reward-on-death is not boss-only.
2. Death during a cutscene or a held scene — §9.6 precedence; the scene yields to the defeat surface.
3. Death while a dialogue fork is pending — the fork is preserved and re-offered after the terminal
frame. It is never auto-resolved by the death.
4. The encounter resolves in the same frame the clock reaches zero — THE CLOCK WINS. Ties resolve to
the rescue. This is stated so it is not left to float ordering, and it is the merciful-and-honest
ordering: the player did not survive on a frame technicality they cannot perceive.
5. Two allies both eligible in the same frame — the highest-priority policy row wins
(T0_Ally_Behavior_Policy.priority), then the lowest ally index. Deterministic, never random.
6. The reviving ally is downed mid-approach — eligibility re-evaluates; the read falls back to the
next candidate or to the honest-failure image. No state is rolled back. If that re-evaluation
makes the case permanently impossible, §4.5's bounded window applies from that moment.
7. Mass Revival (A_C_004, revival_aoe) fires while the player is downed alongside allies — the
player is a legal target of the AOE under the same seven gates. The direction scope columns
(touch #3) are what keep this from also legalising an in-combat player revival.
8. The player dies while already at reduced vitality from a previous revive — the status stacks per
the T0_Status_Table row's stack_op and stack_cap; successive revives return progressively
less. This is the chain-limiter and it must not surface as a number.
9. Level streaming or volume teardown during the hold — §5.2 teardown trap; provenance is retired
and the predicate does NOT flip to eligible.
10. Save and quit during the hold — the hold is not a persistable state. Loading resolves to the
anchor as if the timeout had run. The ledger append fires on the resolution, not on the load.
11. The anchor site is unreachable or was never touched (a chapter entered without a recharge
channel) — fall back to the chapter's entry site, and record the fallback in the ledger. Never
fall back to nearest-by-distance, which is the exact bug §2.7 retires.
12. The ally_revive_policy cell is EMPTY on the encounter row — treated as allowed. Empty means
not-yet-populated and never denied. The same empty-cell rule governs defeat_protected (§6.3).
13. A chain-meter boss's field is cleared by the party — the encounter does NOT resolve, so the
surface stays exactly as it is and the FULL clock runs. This is the case the "waiting always
shows you something" requirement exists to keep readable, and it is why §4.5's impossibility
test deliberately excludes gate 4.
14. downed_target_policy=execute fires during the hold — PROVISIONAL, and this case is the visible
surface of a genuine fork rather than a settled behaviour. Per §12 D-8's recommendation the
execution STEPS THE HOLD CLOCK DOWN by its authored magnitude instead of terminating the hold;
if the step drives the clock to zero the ordinary clock-zero row fires and the ordinary rescue
resolves with outcome=timeout, and execute_pressure_applied is recorded on the ledger entry.
The wait genuinely got worse, with no die roll. Do NOT implement the TERMINATING form without
D-8's resolution: it collides with a ruled clause (§2.4 bullet 3), and execute is blocked on
the non-boss aggro spec in any case (§13.2).
15. downed_target_policy=guard — the enemy holds over the body and refuses to leash, so combat
never ends and the wait cannot resolve to a revive. Legal and authored, not a bug. Note this is
a gate-4 case, so the full clock runs (case 13's rule, not §4.5's).
16. Allies must NOT initiate new engagements while the player is downed — they finish what is on
them and come. One rule; it closes the AFK-farm-from-the-floor exploit and improves the fiction.
17. The player is downed with zero allies ever recruited (the whole Josh Gate slice) — §4.5 returns
IMPOSSIBLE, the empty-ground read plays, and the hold resolves at the end of it per §12 D-4. The
machine is identical and the roster is empty.
18. Repeated deaths at the same encounter — attempt_index increments and the payout advances
through its ordered set (§6.2); consolation_paid prevents a same-index repeat.
19. A persona'd ally would die in combat — it does not. Allies go DOWNED, never dead, in combat.
This also protects the gear-return contract from a loot-loss edge case. Story death remains
legal through the integrity or story lane only. [DECISIONS J-2 exception clause]
20. The rescuer is not yet in the party (before Ch 13) — the rescue resolves with no carried image
§4.6.
21. The bearer acts while carrying — AP_0013 lapses the concealment. The spec treats the carry as
NON-acting; any design that makes it an act re-opens the whole rescue path §4.6.
22. Non-perceptual harm reaches the bearer — the ward yields (AP_0014). Legal, authored, and the
only sanctioned way to put the rescuer in danger.
23. Death inside a COMMITTED rift-run pocket — DELEGATED, not answered here. The rift-dungeon spec
owns pocket interiors, and its ruled rule is that a committed run's pocket inherits NO sanctum,
under the no-lockout law. This machine therefore resolves the rescue to the run's own entry
anchor rather than to WS_048, and records the substitution in the ledger's world_delta_ref.
One owner, never two mints: if the rift spec's pocket rule moves, this clause follows it rather
than forking from it. The no-lockout law is what guarantees the resolution has a destination, so
T-6 holds inside pockets too. [Cross-spec director ruling, 2026-07-29]
---
Nine teeth. Every one carries a MUST-NOT-FIRE twin, because a tooth that can only pass is a tooth
that reports zero when it cannot match. Fixtures are named so the tooth is runnable, not aspirational.
RespawnTimerHandle is NOT armed.
DeathFadeSeconds=0.55 and RespawnHoldSeconds=0.9 must have no live reader.
VS_CH02_001 and then dying beside a second, NEARER site marker, the rescue resolves at VS_CH02_001.
to the near marker and prove the assertion flips, so a tooth that always passes is impossible.
AHumanitySiteMarker actors plus one AHumanityVrilRechargeZone carrying VrilSiteId=VS_CH02_001; WS_048 read after the terminal frame.
ws.integrity_level=L1_TRULY_GOOD and the player at health 0, AP_0001 does NOT evaluate TRUE and no interpose dispatches.
still satisfy AP_0001. A fix that kills the predicate outright passes the first assertion and
breaks the feature.
harness/condition_expr.py evaluation over the live T0_Ally_Behavior_Policy row plus the UE-side FHumanityConditionExpr49Test idiom for the runtime half.
predicate stays FALSE for the entire break and no revive gate opens.
window, with combat_end_provenance=defeated.
least likely to be noticed, and a frame-transient bPerceivedThisFrame read passes a naive test.
AHumanityEncounterVolume::EndPlay) yields provenance retired and the predicate does NOT flip
to eligible.
defeated.
GuardianTeardownOnEndPlay test rather than writing a parallel one.harness/check_no_dead_end.py: no configuration ofencounter, ally roster, arena, integrity band or policy data can produce a state in which LET GO
is unavailable or its resolution has no destination. The impossibility window (§4.5) and the
execute step (§10 case 14) are both inside the invariant's scope — neither may gate the press.
site_id) must FAIL the gate rather than silently pass, proving the invariant is armed and not
a scaffold.
WS_047 entry and one world-advance delta, under re-possession and under both delegate bind paths (PossessedBy and OnRep_PlayerState).
death_event_id values and attempt_index incrementing.
Tools/run_soak.py death-loop lane — N scripted deaths per map across both branches, asserting no leaked RespawnTimerHandle, no duplicate ledger rows, no actor leak, and
stable peak memory. Player death has ZERO test coverage today while 55 UE automation tests assert
boss defeat, so this lane is new surface, not an extension.
DESIGN_GAP_REGISTER entry 114's SECOND magnitude-freeproperty (the world delta applied exactly once per attempt). T-9 carries the first.
T0_Ability_Tree_Registry row may carry revival_direction_scope=to_protagonist without out_of_combat_only=true. Josh's constraint made
impossible to violate in data rather than policed in prose.
revival_direction_scope=to_ally and out_of_combat_only=falseis LEGAL and must pass, or the tooth is really just banning a column value.
check_ally_build.py self-test idiom.
covered): every WS_047 entry carries a non-empty payout — consolation_paid=true, OR a
non-empty banked tell-read delta (WS_041 or WS_042 moved on this death_event_id). The tooth
asserts NON-EMPTINESS, never a number, so it survives every Phase-5M retune untouched. This is the
executable form of §6.2's BOTH PATHS PAY, which is the load-bearing economy claim of the whole
defeat axis — an unasserted version of it is exactly the defect class that ships silently.
consolation and no banked read — must FAIL the tooth. A tooth that cannot fail on the constructed
violation is reporting zero because it cannot match.
Tools/run_soak.py death-loop lane (shared with T-7) for the runtime half, plus aharness-side scan over the ledger fixture so the property also runs at zero token cost on commit.
DESIGN_GAP_REGISTER entry 114 is the QA-loop owner of both properties; T-9 and T-7 are named there as its executable form so the two documents do not fork, and WS_047 is enrolled
as a telemetry-visible surface per §7 touch 17.
Two further teeth already specified elsewhere and enrolled by reference rather than re-authored:
the revive-capability PROVENANCE tooth (every taught_capability_refs entry resolves to a row with
ability_class in {revival, revival_aoe} and a satisfiable band lock, positive-controlled so an
unreachable resolver reports as unreachable and never as a clean zero), and the EVIL-LANE HOLE tooth
(if the L1/L2 lane is a live affordance and L3/L4/L5 is empty, fail or warn with a named worklist —
the executable form of the no-dead-end floor). Both are FORKB §5.5 items and both belong on Gate 29.
Gate ritual for any commit touching this feature: run_gates.py UNPIPED, plus
registry_fidelity.py --emit-baseline in the SAME commit as any registry edit, plus
check_registry_extensions.py, check_ws_value_form.py, check_reveal_discipline.py and
check_grand_sage_silence.py scoped to the new strings.
---
Per the standing decision protocol, each carries alternatives, a recommendation, and the strongest
objection. D-4 is RESOLVED by the director in this round and is recorded as resolved; every other
entry here is unapplied.
flag(local.encounter_resolved) — zero grammar change, exact precedent in AP_0006 andAP_0008, no fake producer needed (§5.3 positive control).
read(rt.combat_resolved) — reuses the existing read() node, but the grammar doc defines read(surface) as an inscription or readable object having been read, so it overloads a shared
vocabulary.
state(...) predicate — cleanest semantics, costs a parser change on both sidesplus a grammar-doc amendment.
shared vocabulary. STRONGEST OBJECTION: local.* reads as beat-scoped to anyone who learned the
grammar from the spine files, so (a) buys cheapness with a readability cost that (c) does not have.
WS_047 defeat_ledger (this spec's assumption).WS_034 nemesis_memory_per_boss, which already exists and is append-legal.WS_034 is per-boss bydefinition. STRONGEST OBJECTION: a new append-only variable is a THIRD touch of a ruled constant.
APPEND_LEGAL_IDS has already been reconcile-and-extended twice (6 to 12, then 12 to 14), each
time by deliberate ruling and each time correctly — but every touch opens a window in which a
ruled enumeration and its data can drift apart, and the co-landing requirement is the only thing
that closes it. (b) needs no such window.
execute step magnitude, the revived vitality fraction, the ally vril cost, the two branches'
currency weights, the INT threshold at which an ally notices, and the reduced-vitality stack curve.
This is not a fork so much as a firewall reminder — nothing here may be picked by an engine agent.
behind a finished image — FORKB §3.11's literal reading, "fail fast and honestly."
revived. The decisive evidence is this feature's own §4.5 — in the Josh Gate slice the
impossibility test returns IMPOSSIBLE on EVERY death, so under (a) every death for eleven chapters
costs a full two-minute wait on a branch that was never going to open. That is not a hypothetical
objection; it is the entire playable slice and the only player the QA loop has.
gate and PLAYS to its authored length — the resolution is never a cut to black, and
PRESENTATION_DOCTRINE §0.B.2's "waiting always shows the player SOMETHING" is satisfied by the
image, not by the silence after it. LET GO stays live for every frame (T-6 unaffected). The
window's magnitude is Phase-5M under D-3.
That cost is accepted and mitigated by carrying the knowledge as an IMAGE rather than a system
message — empty ground, or someone who arrives and cannot. The player learns a fact about the
world, not a fact about the machine.
ally cannot disengage from — including the chain-meter boss whose win condition only the player
can perform (§4.4, §10 cases 13 and 15) — runs the FULL clock, because something is happening and
the player is watching it. §4.5's test reads gates 1, 2 and 3 only. Widening it to gate 4 is the
most likely way a future implementer breaks this quietly.
§3.11 L274 reads "W6 IMPOSSIBLE must fail fast and honestly — never run a timer out on a player
who was never going to be revived." The pre-revision draft REVERSED that clause and re-scoped
"fast" to the read rather than the state, while simultaneously declaring the behaviour
non-negotiable at §2.2 and open at §12 — a contradiction a document cannot hold. The 2026-07-29
fresh-context critic round caught it and named the reversal; the director resolved it to (b) under
the delegated design authority, and the reversal is WITHDRAWN. Both §2.2 and this entry carry the
record.
a separate L4/L5 route, HL_0076 magnitude banding (which routes cleanly around the §8.11.8
firewall because no condition_expr reads loyalty and the magnitude rides the band exactly as all
healing does), or both.
orthogonal. STRONGEST OBJECTION: it touches the equally-weighted-endings architecture, which is
Josh's, and doing both is the largest authoring surface of the three.
Truly Good guild"), but every revival row carries integrity_band_lock of L1 or L1,L2. Under
current data an L5 guild cannot field a rezzer at all — a direct contradiction of a ratified
Tier-C rule.
T1_Ability_Tree §12 says catalog access is FOR — path identity and replayability), and Tier-C
fields the L4/L5 alternate route so the role space stays equal. This promotes the evil-lane
revival from a no-dead-end nicety to a Tier-C BLOCKER.
T0_Familiar_Bond_Ability rows are COPY-ONLY from T3_Familiars_Named §1.6. A revival rungcannot be invented in the registry.
permits this); (b) leave familiars out of the revival lane entirely and keep it companion-only.
A_C_004's relay through Collective Surge already presupposeslinked allies holding revival-class casts. STRONGEST OBJECTION: familiars are the ally class the
player has EARLIEST, so granting them the revive is the fastest way to make support-familiars
mandatory — the banned meta-collapse mode.
execute COLLISION — ✅ RULED (Josh, twenty-first sitting 2026-07-29): OPTION (b) ACCELERATEJosh, verbatim: "1 b yeah agreed with recommendation" — an execute ACCELERATES the countdown;
the acceleration magnitude is a Phase-5M tuning value, never canon. The options record below is
preserved as the decision history.
Raised to a fork on the director's instruction in the 2026-07-29 critic round, and deliberately NOT
resolved inside §10, because what collides here is two ruled things rather than a design taste, and
§10 is a section readers treat as clarification rather than policy.
downed_target_policy=execute is legitimately grounded — FORKB §3.1(c) grounds the mechanic, FORKB §5.4 item 13 grounds the column, and Shape B was the adopted shape — so execute
is not this spec's invention. But PRESENTATION_DOCTRINE §0.B.1a L143-145, inside THE RULED CLAUSES
block, states that no input is a legal, UNPUNISHED way to play the beat, and §2.4 restates it as
ruled floor. An execute that TERMINATES the hold punishes the no-input path in kind: the wait
ends worse than the press, which is precisely what that clause forbids. Two ruled things, one
runtime. The mechanic's VALUE is not what makes this a fork; the clause conflict is.
countdown read "XX seconds until you cannot hold on any longer" becomes a promise the surface
cannot keep — which §8's own refuse-list bans as a PROMISING string.
execute TERMINATES the hold. The pre-revision draft's silent choice, shipped in §10 case 14as "the highest-value single value in the enum."
execute ACCELERATES the countdown rather than terminating it: the execution steps the holdclock down by an authored magnitude, and if the step drives it to zero the ordinary clock-zero row
fires and the ordinary rescue resolves.
execute is BARRED while the ruled countdown surface is up, and applies only to downed ALLIES.provisional. Originally carried as a PROVISIONAL row so the
state machine is complete against §10 while the fork stays genuinely open. It is the only reading
that satisfies BOTH ruled clauses at once. The countdown stays TRUTHFUL because it reads live
remaining hold and the player watches the number drop; a shortening you can see is not a broken
promise, and an enemy standing over your body is the most legible possible reason for one. And the
no-input path stays unpunished IN KIND: its outcome class is unchanged — still the rescue, still
outcome=timeout, still the ruled resolution — it simply arrives sooner. The defeat axis keeps its
teeth: the wait genuinely got worse, with no die roll, which is what (a) was bought for.
execute in FORKB§3.1(c) was that the wait can end WORSE than letting go. Under (b) it ends SOONER but in the same
place, so a player who reads the ledger learns the two branches converge and concludes the pressure
was cosmetic — the exact meta-collapse-on-the-defeat-axis defect §3.1 exists to prevent. (a) keeps
the sharpest defeat axis at the cost of a ruled clause; (c) keeps both ruled clauses cleanly but
spends the enum's best value on a case the player never sees.
execute itself is blocked on the non-boss aggro spec (DESIGN_GAP_REGISTER gap #1, owner W-SPACE, §13.2). This fork
therefore gates nothing in the slice and can be resolved on real feel strips rather than argued —
which is the right way to settle it.
---
Per the standing engine-reuse rule, every item declares whether it is reusable ENGINE or
game-specific CANON, so game two is a harvest.
sites). Hard prerequisite: there is no checkpoint to revive at today.
hold state SURFACE-AGNOSTIC so blocking-ness is a property of the surface and not of the machine.
This is a build-now architectural requirement, not a Tier-C afterthought, because 100 players
cannot hold on one player's prompt and the MMO form is a non-blocking timed release-or-wait.
pays FOUR existing debts on landing: rage decays out of combat, stamina regenerates out of combat,
loadout switching is never mid-encounter, and every T0_Ally_Behavior_Policy predicate that needs
to know a fight is running. Schedule it regardless of this feature.
Without it the choice is cosmetic.
Four of those seven are slice requirements on their own merits. That is the strongest scheduling
argument in the whole feature: they get built either way, and this spec is the reason they get
scheduled.
The ally pawn and AI subsystem (the largest single item, greenfield, with a head start because the
predicate evaluator already exists on BOTH sides); party combat that continues after the player
falls (which is what makes the out-of-combat rule MEAN anything); downed_target_policy plus the
execute windup (blocked on the non-boss aggro spec, DESIGN_GAP_REGISTER gap #1 — and its
hold-clock interaction is §12 D-8, unresolved, so the behaviour lands with the fork, not before it);
the revive cast and presentation hookup; the teaching loop.
The death presentation itself is explicitly deferred as an art placeholder. Name this surface as a
FLAGSHIP CASE in the tiered-asset request: the revive is the ONE ability the player watches from the
receiving end, in close-up, held still, so a low-tier revive should look effortful and a mastered
one should look like nothing at all. It is a held close-up, not a combat-speed flourish.
[Josh's presentation-ladder nod, 2026-07-26; FORKB §5.3 C2]
---
This feature has ZERO surface in the Josh Gate slice. Ch 2 through 7 stay solo as built, the
earliest companion window is Ch 13, and the revival ladder sits at T5 of a twelve-tier climb. The
machine ships present and honest, with the wait resolving truthfully to "no one could reach you" —
and, per §12 D-4, resolving PROMPTLY there, because a two-minute clock on a branch that cannot open
is a tax levied on every death in the only eleven chapters that exist.
That is a design gift rather than a defect, and it must be BUILT that way rather than DISCOVERED
that way: the death surface is bare and solitary early, gains a record at Ch 13 when the journal
activates, and gains a witness who can reach you later. Built deliberately it is a true story about
the arc — the world starts empty and fills. Discovered as a bug report it is a disaster. And the
one thing this spec must never produce is a greyed second option teasing a capability the game
cannot deliver for eleven chapters: a taught-then-broken affordance is worse than an absent one.