DEATH_CHOICE_RUNTIME_SPEC.md

music/DEATH_CHOICE_RUNTIME_SPEC.md

THE DEATH CHOICE RUNTIME SPEC (HP-0 state machine, ally revival, defeat economy)

CANON SUBORDINATION — this document is PROPOSAL-TIER: it serves canon and never outranks it.
The canon: the CVD · the T1 foundation docs · the T0 registries (registries/) · the spine
(docs/spine/CH_*.md) · the region pages (_source/02_Tier_2_Region_Pages/). Authority order: docs/DOC_MAP.md § 0.
Canon served (scanned from this document's own citations — widen it by hand where it is thin):
CVD §5 · CVD §17 · T1_Ability_Tree · T1_Combat_System_Spec · T1_Integrity_Paths_Worldstates_Master · (+3 more tier) · T0_Ability_Tree_Registry · T0_Ally_Behavior_Policy · T0_Bonus_Option_Registry · T0_Bonus_Pool_Registry · (+10 more t0)
READ THAT CANON FIRST — open it and derive from it before you build anything from this document.
If this document disagrees with canon, CANON WINS and this document is the defect — fix the
document, never the canon. Nothing here is applied until it is ratified into canon.

Status: PROPOSAL-TIER engineering contract. SPEC-ONLY — no runtime code lands here; the 5090 build

implements against this. Authored 2026-07-29 under the ruled canon of the 2026-07-27 second and

third sittings. REVISED 2026-07-29 against the fresh-context critic round.

Authority order applied throughout: CVD wins, then T1 domain docs, then T0 registries, then T99

operational. Every clause below carries either a RULED citation (Josh's own words, cited to the

DECISIONS record) or a DERIVED marker naming the doc it is derived under. Nothing numerical,

nothing named, and nothing that would change a Josh ruling is decided here — those are §12.

ENGINE REPO ROOT. Every Source/... and Tools/... path in this document is relative to

C:/dev/Humanity/Humanity, the UE game repository — NOT to C:/dev/humanity-forgotten, the canon

repository this document lives in. A reader who follows an engine path from the canon repo finds

nothing. All UE line numbers are pinned to the 2026-07-29 working tree. Canon paths

(docs/..., registries/..., harness/..., _source/...) are relative to the canon repo as usual.

REVISION RECORD. This is the post-critic revision; every finding of the 2026-07-29 fresh-context

critic round is applied. Two of them were director calls rather than author fixes, and both are

recorded in place rather than silently resolved:

director's recommendation (execute ACCELERATES the countdown rather than terminating it) carried

into §2.2 as a PROVISIONAL transition row so the state machine is complete against §10.

of FORKB §3.11 disclosed in full at §2.2 and §12 D-4.

---

0. THE RULED FLOOR — what this spec may not move

These are Josh's rulings, quoted or paraphrased to their citation. Every later section is

execution under them.

progress and the protagonist is resisting it. No two-button prompt, no modal, no wait-versus-return

menu. Doing nothing is doing the thing the fiction describes. [RULED — docs/spine/DECISIONS_PENDING_JOSH.md

L748-753, "RULED 2026-07-27 (second sitting)" J-1; restated at docs/proposals/PRESENTATION_DOCTRINE.md

§0.B.1a]

press; it is never the no-input default; it never becomes unavailable. [RULED — DECISIONS J-1;

PRESENTATION_DOCTRINE §0.B.1a; the never-fails property is the no-dead-end floor at

docs/pipeline_review/FORKB_RESURRECTION_BRIEF_2026-07-27.md §3.11]

protagonist can hold. Josh's words: "maybe after 2 minutes you can't hold on any longer,"

surfaced as "XX seconds until you cannot hold on any longer." The two-minute figure is a SEED;

the magnitude is Phase-5M. [RULED — DECISIONS J-1 L749-752]

J-1, "Timeout = the withdrawal completes to the checkpoint"]

raw combat outcome for a persona'd character, UNLESS an integrity-based departure or story

outcome has a persona'd character die — that lane is explicit and legal. The boundary is the

community-ripple event. [RULED — DECISIONS J-2, with Josh's exception clause]

(Reading A holds). She is the one who brings you back to the revival location, checkpoint and

recharge zone; the let-go and timeout paths are diegetically HERS. [RULED — DECISIONS J-3, Josh's

own third reading; the non-vril lock at _source/03_Tier_3_Characters/T3_Core_Characters [ACTIVE v1.0]

§3.4, "no combat ability, vril, or weapon is gained"]

COUNTDOWN WINDOW. Chain-meter bosses whose win conditions are player-performed still cannot end

without the player. [RULED — DECISIONS J-5]

kill you; the healer's child rescued you. [RULED — DECISIONS J-6]

field. Its provenance is Josh-authored — it was the mother's, passed at the birth, given onward.

[RULED — DECISIONS J-6 plus "RULED 2026-07-27 (third sitting)"; the six ward rows are already on

disk at registries/T0_Ally_Behavior_Policy [DRAFT v0.1]/Sheet1.csv AP_0009 through AP_0014]

Two upstream doctrines this machine must not breach, both already ruled elsewhere:

to the LAST ATTUNED recharge source. [docs/translation/T99_Translation_Combat.md §2.5 L157-164;

CVD §5 Pillar 8; docs/PRE_5090_BUILD_PLAN_VOL2.md SL-1]

may read a loyalty worldstate key, and policy_source is a closed enum with no player-authored

member. Both are already armed in harness/check_ally_build.py B5. The revive policy therefore

may not be loyalty-gated and may not be player-authored.

---

1. VOCABULARY — the six words the whole machine turns on

Naming precision here is load-bearing: three of these words already exist in the corpus with

different meanings, and conflating them is how a future author legalises in-combat player

resurrection by accident.

allies. Writes no community ripple. [DECISIONS J-2]

authored story outcome. Never a raw combat result for a persona'd character. Writes the

community-ripple event, and that write IS the boundary. [DECISIONS J-2 with the exception clause]

unchosen, unpaused.

Requires the encounter to be resolved. Canon rows: A_A_009 Breath of Life, A_C_003 Vril

Revival, A_C_004 Vril Mass Revival in registries/T0_Ability_Tree_Registry [ACTIVE v0.1].

healer's child's act and hers alone. It is the resolution of both the let-go press and the

timeout. It is NOT a revive and must never be schema-expressed as one. [DECISIONS J-3]

The distinction REVIVE-versus-RESCUE is the single most abusable ambiguity in this feature. A

schema that lets one row express both will eventually be read as licensing a non-vril combat

revival, which contradicts T3_Core_Characters §3.4. §7 makes the two unspellable as one another.

---

2. THE HP-0 STATE MACHINE

2.1 States

The machine has six states. The presentation names for them are already ruled at

PRESENTATION_DOCTRINE §0.B (S0 the fall, S1 the low hold, S2 the wait, S3 the rise, S4 the cut,

S5 the dissolve); this spec keeps those names so the two documents do not fork.

not a decision window; LET GO is already accepted here. The camera inherits the fall and settles

on an arena-biased yaw. [PRESENTATION_DOCTRINE §0.B.2 — a build requirement, not a detail]

frame, and an eligible ally may resolve the encounter and then reach the body.

checkpoint anchor. Terminal.

rises with the body. Terminal.

consolation surface fire exactly once. Not player-visible as a state.

2.2 Transition table

FromEventGuardToSide effects
D0health reaches 0player is not already DOWNED (re-entrancy guard, §2.6)D1arm the downed pawn contract (§2.5); snapshot attempt_index; start the world-advance clock read; do NOT arm any respawn timer
D1fall settle elapsesalwaysD2start the hold clock; open the LET GO input; open the ally-resolution loop
D1 or D2LET GO pressednone — always legalD3stop the clock; record outcome=let_go
D2hold clock reaches zeroLET GO not pressed and no revive landedD3record outcome=timeout
D2eligible ally completes revive§4 eligibility resolves TRUE and the clock has not reached zeroD4record outcome=ally_revive; apply reduced vitality; apply ally exhaustion
D2eligibility resolves PERMANENTLY IMPOSSIBLE§4.5 impossibility test, which reads gates 1, 2 and 3 ONLYD2 for the bounded honest-failure window (§9.3), then D3record outcome=timeout with ally_reach=impossible; the hold clock is TRUNCATED to that window rather than run to zero; LET GO stays live for every frame of it [RESOLVED — §12 D-4, director's call 2026-07-29]
D2a hostile carrying downed_target_policy=execute completes its execution on the bodythe hostile is live and in contact, the execute windup completed, and the encounter is unresolvedD2 with the hold clock STEPPED DOWN [PROVISIONAL — PENDING §12 D-8]apply the authored execute step to the hold clock (magnitude Phase-5M, §12 D-3); record execute_pressure_applied on the ledger entry; if the step drives the clock to zero the clock-zero row above fires unchanged and resolves to D3 with outcome=timeout
D3 or D4terminal frameledger not yet appended for this death_event_idD5one idempotent ledger append; one world-advance delta; one consolation resolution

Three properties of this table are load-bearing, and each closes a named defect. The first is

non-negotiable canon. The second and third are this round's director dispositions, recorded as such

rather than asserted as floor — the pre-revision draft declared the second non-negotiable HERE while

listing it as an open fork at §12, and a document cannot hold both.

or luck that produces a dead end does not exist, by construction. [FORKB §3.11; assert in

harness/check_no_dead_end.py, tooth T-6]

honest-failure read is selected by the first failed gate and plays to its authored length, and the

hold then resolves — the clock is not run out behind an image that has already finished.

DISCLOSURE OF THE REVERSAL HISTORY, so no future reader re-derives either position from silence:

docs/pipeline_review/FORKB_RESURRECTION_BRIEF_2026-07-27.md §3.11 L274 reads "W6 IMPOSSIBLE must

fail fast and honestly — never run a timer out on a player who was never going to be revived." The

pre-revision draft of this spec REVERSED that clause, running the full clock and re-scoping "fast"

to mean the READ arriving fast rather than the state ending early. The 2026-07-29 fresh-context

critic round caught the reversal, and the director ruled: adopt FORKB §3.11's reasoning — never run

a timer on a player who cannot be revived. The reversal is WITHDRAWN. What survives from the

draft's argument is its honesty half, in full: waiting still shows the player something, the image

is never replaced by a cut to black, and LET GO is never gated (PRESENTATION_DOCTRINE §0.B.2). The

accepted cost is named at §12 D-4.

(acceleration, not termination) so the machine is complete against §10 case 14 while the fork

stays genuinely open. It is not a settled behaviour and must not be read as one.

2.3 The hold clock

withdrawal_timer step and every other combat magnitude is firewalled at

docs/translation/T99_Translation_Combat.md §8.1. [RULED as a seed — DECISIONS J-1, "the 2-minute

figure is a seed; magnitude Phase-5M"]

phase, or a difficulty tier. A clock that stretches when help is near converts a conditional

system into a hidden roll, which is the exact defect FORKB §3.10 exists to prevent. Exactly two

authored SHORTENINGS exist — the impossibility truncation (§2.2, §4.5, §12 D-4) and, pending §12

D-8, the execute step (§10 case 14). Both are deterministic, both are visible on the surface as

the number moving or the state resolving, and neither is a roll. A shortening the player can SEE

is not a hidden roll; an extension the player cannot see is.

moment of encounter resolution, never as a separate timer. [DECISIONS J-5]

dial — ambient vril density (Wellspring, Veiled, Fading, Sundered, The Forgotten One) — through

the ALLY's vril availability, never through the player's hold duration. [FORKB §3.13; the ladder

at docs/COMBAT_ENCOUNTER_SYSTEM.md §9 L238-245]. The composition with the world-advance clock is

stated explicitly at §3.3, because leaving it to the implementer would breach this firewall

through the back door.

2.4 Input contract during the hold

including movement, camera, ability, interact and menu-open.

and not a twitch window. It is fully remappable and one-handed reachable.

[docs/proposals/PRESENTATION_DOCTRINE.md §0.B accessibility floor, inheriting the ratified

Attunements options canon]

from the pad, or on assistive input resolves to the rescue at the clock. [RULED-TIER BY PLACEMENT —

docs/proposals/PRESENTATION_DOCTRINE.md §0.B.1a L143-145, inside the THE RULED CLAUSES block. The

provenance is stated precisely because §12 D-8 turns on this clause's authority: it is NOT in

DECISIONS J-1 and is not Josh's own words. Its own SRC at that line is "FORKB brief §3.11, the

let-go path never fails" — it is a doctrine-ELEVATED derivation, ruled-tier by where it sits, not

by who wrote it.]

PRE-SELECTED on a surface that offers one, never availability. Since the ruled surface offers a

single press with no default alternative, this preference has no effect here and must not be

implemented as an auto-press. [DERIVED under FORKB §4]

clock both stop with the game; neither is a real-time clock.

2.5 The downed pawn contract

While in D1 through D4 the player pawn:

(Humanity/Source/Humanity/Public/Core/HumanityCharacter.h L391 area) so QA and the HUD can tell

the two apart;

hypothetical: AP_0001 in registries/T0_Ally_Behavior_Policy [DRAFT v0.1]/Sheet1.csv reads

ws.integrity_level in [L1_TRULY_GOOD,L2_GOOD_ENOUGH] & flag(local.player_health_at_or_below_50)

and dispatches interpose autonomously. A player at HP 0 satisfies "at or below 50," so on the

day a downed state exists the L1/L2 familiar interposes for a downed player forever. Either the

downed state is excluded from the health-fraction producer, or AP_0001 and AP_0005 are

re-scoped IN THE SAME COMMIT. [FORKB §3.5; tooth T-3 with its must-not-fire twin]

Note that downed_target_policy=execute (§7 touch 12, §10 case 14, §12 D-8) is the one sanctioned

exception to the perception clause above: an execute-policy hostile acts on the BODY, which is a

policy-driven behaviour rather than a perception hit. The two must not be reconciled by making the

downed pawn perceivable, or the interpose defect and the aggro contract both re-open.

2.6 Re-entrancy, idempotency, and the double-fire landmine

The death delegate binds from both PossessedBy and OnRep_PlayerState, guarded only by

bDeathDelegateBound (Humanity/Source/Humanity/Private/Core/HumanityCharacter.cpp L219-225).

Two ledger rows means the world-advance delta applies twice.

append, the world delta, the consolation resolution, and the telemetry record.

second death_event_id.

HandlePlayerDeath() starts a 0.55 s fade and arms RespawnTimerHandle for

DeathFadeSeconds + RespawnHoldSeconds (0.55 + 0.9 = 1.45 s) to RespawnAtNearestSite()

(HumanityCharacter.cpp L281-320; constants at HumanityCharacter.h L394-395). The ruled machine

has no state that timer occupies, and the fade is retired.

[PRESENTATION_DOCTRINE §0.B.1b "THE SHIPPED FADE IS RETIRED"]

2.7 The checkpoint anchor — the semantic fork the code currently gets wrong

RespawnAtNearestSite() iterates every AHumanitySiteMarker and picks the minimum

FVector::DistSquared (HumanityCharacter.cpp L322-340). Canon says the LAST ATTUNED recharge

source (docs/translation/T99_Translation_Combat.md §2.5 L161-162). Nearest is not last; a nearer

marker can teleport the player PAST the content they just failed.

recomputed nearest. The recommended anchor class is the vril site itself, because it is already

ruled as save, recharge and loadout sanctum, so one anchor serves three ruled systems and it is

the same place an ally's vril refills. AHumanityVrilRechargeZone already carries VrilSiteId

(Humanity/Source/Humanity/Public/World/HumanityVrilRechargeZone.h L48-50), so the write site

exists today.

docs/DESIGN_GAP_REGISTER.md entry 113]

is corrupted on 30 of 42 rows and sequences this behind register entry 46. That corruption is a

prerequisite, not this spec's work.

---

3. WHAT EACH OUTCOME WRITES

3.1 The defeat ledger

One append per death_event_id, on ALL outcomes. The choice must not be cosmetic: today nothing is

written to world state on death, so both branches would produce the same empty delta, which is

meta-collapse applied to the defeat axis. [FORKB §3.9]

Proposed new append-only worldstate variable, on the WS_044 idiom, id allocated at the mint pass:

death_event_id, chapter_ref, site_ref (soft-FK T0_Vril_Site_Registry.site_id),

encounter_ref (soft-FK T0_Boss_Encounter_Registry.boss_id, empty for a non-boss death),

attempt_index (integer, per encounter_ref, 1-based),

outcome in {let_go, timeout, ally_revive},

ally_reach in {reached, impossible, empty} (empty for outcomes where the question never arose),

combat_end_provenance in {defeated, leashed, retired, unresolved},

reviver_ref (soft-FK T0_Character_Index.character_id, empty unless outcome is ally_revive),

capability_ref (soft-FK T0_Ability_Tree_Registry.ability_id),

vril_paid_class, hold_elapsed_class, execute_pressure_applied (bool),

world_delta_ref, relationship_delta_ref, consolation_paid (bool).

Named landmine, restated to its REPAIRED state. The pre-revision draft carried the brief's

pre-fix framing forward verbatim while updating the count, which produced an internally incoherent

sentence — the exact "trust content, not labels" defect the repo's own discipline warns about, and

the 2026-07-29 critic round caught it. The actual state, read from

harness/check_ws_value_form.py L112-123: APPEND_LEGAL_IDS has been reconcile-and-extended

twice — 6 to 12 under Josh's D-CG25-APPEND-SET ruling (2026-07-24), then 12 to 14 at the ss7-12

schema mint (2026-07-27, the third precedent instance), where WS_044 bonus_respec_ledger and

WS_046 item_instance_ledger landed INSIDE the frozenset in the same commit as their rows. Both

ids are verifiably in the set today; the earlier self-declared deviation is REPAIRED

(MINT_APPLY_CRITIC MAJOR-2 fixed). The precedent is therefore established, not broken. The

ACTIONABLE instruction is unchanged and is the whole point: WS_047 makes it fifteen, and it must

be added to that frozenset in the SAME commit as its registry row, per the co-landing dependency

the comment block above the list already documents. [docs/pipeline_review/MINT_APPLY_CRITIC_2026-07-27.md

§A; FORKB §5.4 item 8; the same landmine named at docs/DESIGN_GAP_REGISTER.md entry 114]

3.2 The checkpoint anchor variable

chapter's entry site). Written on every completed recharge channel; read by D3. Keyed-replace,

NOT append-legal.

3.3 The per-outcome deltas — different currencies, never different magnitudes

The two branches must not be a better-versus-worse pair, or the player solves the surface once and

the choice becomes a tax. They carry DIFFERENT currencies. [FORKB §3.9]

advanced while you were down and it advanced further because you were carried back. Banked

tell-reads and the substrate-lore fragment pay out on this path (§6).

standing for you and that is remembered. It also carries the banked tell-reads, because the

learning economy is the reward-on-death rule and is not a branch prize.

repair relationships and invert the integrity system. Rule it explicitly in the owning doc

(T1_Integrity_Paths §8.11). [FORKB §3.6; RULED as loop-territory at FORKB §2.B]

made visible rather than a new cost: canon's density dial already tightens tells, slows wells and

prunes answers. [DERIVED under docs/COMBAT_ENCOUNTER_SYSTEM.md §9 L238-245 — the five diegetic

tiers and the four world-demand levers, telegraph slack, world generosity, answer-pruning and

withdrawal aggression — plus docs/translation/T99_Translation_Combat.md §8 L742, which defines

the withdrawal_timer step as vril_density -= step on expiry. Derivation source FORKB §3.1(a).

The pre-revision draft cited docs/RUNTIME_GENERATIVE_LAYER.md L133 for this claim; that line

carries only the deterministic-ownership fact — the executor owns vril_density, the arena cycle

clocks and the Withdrawal clock — and the pointer is narrowed to exactly that.]

implementer because it is load-bearing in BOTH directions. T99 §8 L742 makes the

withdrawal_timer the mechanism that moves the one ruled difficulty dial. If lying downed

advanced that timer, the hold WOULD be a difficulty dial and §2.3's firewall would be breached

through the back door. It does not: the hold is bounded at roughly two minutes, it cannot be

farmed, and no vril_density decrement is charged for it. §2.3's firewall is literally true

because of this clause. [DERIVED call under T99 §8; named here so no implementer guesses]

you lie there is the WORLD-ADVANCE delta itself, which rides hold_elapsed_class on the ledger

entry — the ledger and opportunity layer: what moved, what the party lost, what the encounter

remembers. That is what stops waiting from strictly dominating, and it does the job without

touching the density ladder. [FORKB §3.1(a)]

3.4 The bounded-demand invariant — flagged, not applied

docs/DESIGN_GAP_REGISTER.md entry 110 proposes that the per-encounter demand after N failed

attempts be non-increasing and that the graduated delta be authored on the WORLD, never on the

encounter you just failed, with the top two difficulty tiers explicitly untouched. That entry is

recorded CONTESTED-CARRIED, "director call before it enters the gate." This spec DOES NOT apply it;

it names the collision so the runtime is not built in a way that forecloses either answer: the world

delta and the encounter state are written through separate paths (§3.3), which is the shape both

readings need. [Register entry 110; the paired difficulty-ladder gap at entry 111]

---

4. THE ALLY-REVIVAL ELIGIBILITY MODEL

4.1 The three questions, answered by three different systems

Josh's direction reads "may be able to revive." That uncertainty is CONDITIONAL and never

probabilistic. A probabilistic revive would fall under HL_0061 and CVD §17.13 (the sigma bound, the

anti-streak floor, the mandatory success ceiling), which is heavy machinery bought to purchase a

worse feeling on the game's most emotional beat. All five FORKB analysts converged on this.

[FORKB §3.10]

from data, not from a roll.

departed and estranged companions cannot revive by construction because they are not on the

field. Below that, willingness is NOT bond-gated, because a policy condition_expr reading a

loyalty key is structurally illegal under check_ally_build.py B5(i). [FORKB §3, the two

firewalls and the recommended reconciliation]

does she peel the last threat off you first), never access. [Josh's INT-as-AI ruling 2026-07-26,

memory companion-familiar-stat-builds-ai-intelligence; FORKB §3.12]

4.2 The eligibility resolution function — deterministic and ordered

Evaluated per tick in D2, per candidate ally, in this order. First failing gate stops the

evaluation and determines the honest-failure read (§9.3).

1. ON THE FIELD — the ally is instantiated and not departed or estranged (WS_027).

2. NOT DOWNED — the ally is not itself in a downed state.

3. CAPABLE — the ally's taught_capability_refs contains an ability row whose ability_class is

revival or revival_aoe and whose integrity_band_lock is satisfiable by the player's current

ws.integrity_level. Positive-controlled: an unreachable resolver must report as unreachable,

never as a clean zero. [The zero-reporting law, memory a-search-that-cannot-match-reports-zero]

4. ENCOUNTER RESOLVED — the out-of-combat predicate is TRUE (§5). This gates the ACTION, never the

surface. [FORKB §4, "do NOT gate the OPTION on combat state — gate the ACTION"]

5. HAS VRIL — the ally's current vril meets the ability's vril_cost_class. Not refillable in the

field; only at the vril site. This is the depletion-carried-forward tooth. [FORKB §3.1(b)]

6. CAN REACH — a navigable path to the body exists and can be traversed before the hold clock

reaches zero, at the ally's own movement speed. No teleport, no snap.

7. WITHIN THE CLOCK — the cast completes before the clock reaches zero. The revive is instant-cast

in the ability rows (A_C_003, A_C_004 carry instant,instant), so there is no channel to

interrupt and no progress meter belongs on the surface. [PRESENTATION_DOCTRINE §0.B.1b]

Every one of the seven is a property the player's own build and play determined before the death.

That is what makes the uncertainty honest.

4.3 The out-of-combat rule is meaningless until party combat continues

Reported register-honestly, per the standing evidence discipline: until allies exist and a fight can

continue after the player falls, enemies de-aggro or leash from a body within seconds, so the

out-of-combat constraint is CORRECT but nearly FREE. Ship it anyway (retrofitting is expensive) and

never let a play-quality claim ride on it before party combat lands. [FORKB §5.2 B2 and §6 item 2]

4.4 The boss-win countdown bound (J-5)

out-of-combat predicate flips TRUE with combat_end_provenance=defeated, gate 4 opens, and the

revive may land if gates 5 through 7 also hold.

case, because they are properties of the encounter's resolution and the run is the player's. The

ledger records combat_end_provenance=defeated so a later balance pass can separate

party-finished wins from player-finished wins without a second variable.

predicate never flips and the hold resolves to the rescue. The design disarms itself exactly where

an ally-undo would do the most damage. This is not a special case in the machine; it falls out of

gate 4. [DECISIONS J-5; the mechanism at FORKB §2.A J-5 — the pip-meter win conditions, Rangku's

FREE route as an integrity choice only the player can make, Naga Padoha's cosmic subdual]

full clock there, because a fight is live and the player is watching it (§10 case 13, §12 D-4).

allowed, EMPTY MEANS NOT-YET-POPULATED AND NEVER DENIED — the same discipline the pip columns

already carry. This is the toolbox form of FORKB Shape D, for the rare authored arena where an

in-place return would break the encounter economy. [FORKB §3.3 and §1 Shape D disposition]

4.5 The impossibility test

Eligibility is PERMANENTLY IMPOSSIBLE for this death event when no candidate ally can pass gate 3

(nobody is capable) or when every candidate has failed gate 1 or 2 and cannot re-enter. THE TEST

READS GATES 1, 2 AND 3 ONLY. Gate-4 non-resolution — a fight still running, including the

chain-meter boss an ally can never finish — is explicitly NOT impossibility (§4.4, §10 case 13).

Widening the test to gate 4 would truncate exactly the wait that the "waiting always shows the

player something" requirement exists to protect, and that widening is the most likely way a future

implementer breaks this feature quietly.

The machine uses the test for two things:

authored length and the withdrawal then completes, rather than the clock running to zero behind an

image that has already finished. LET GO remains live for every frame of that window; T-6 is

unaffected. The window's magnitude is Phase-5M under §12 D-3.

In the Josh Gate slice this test returns IMPOSSIBLE on every death, because Ch 2 through 7 stay solo

as built, the earliest companion window is Ch 13, and the revival ladder sits at T5 of a twelve-tier

climb. The wait branch is present, honest, and resolves truthfully to "no one could reach you." That

is not a stub; it is the same machine with an empty roster — and D-4 is what keeps it from also

being a two-minute tax on every death in the only eleven chapters that exist. [FORKB §6 "THE

STRONGEST OBJECTION" and its answer; FORKB §3.11 restored per §12 D-4]

4.6 The rescuer path — the healer's child

registries/T0_Character_Index [ACTIVE v1.1]) performs the RESCUE on the let-go and timeout paths.

She never appears in the §4.2 eligibility function, because she is not a reviver. [DECISIONS J-3]

through AP_0014 in T0_Ally_Behavior_Policy carry suppress_aggro, suppress_target_selection,

suppress_down_state, traverse_live_field, lapse_concealment and

yield_to_nonperceptual_harm, all on flag(local.ward_borne_and_holding), all

policy_source=canon_seed, all power_source=gear_imprint.

never a durability meter. A visible meter would convert a grief-object into a managed resource

and put a companion's life on a bar. (AP_0009 note)

is a carry, not an act of force, and the spec treats the carry as non-acting; if a future design

makes the carry an act, AP_0013 fires and the whole rescue path needs re-deriving. (AP_0013 note

— flagged here as the seam most likely to be broken silently)

rather than targets. A designer who wants the bearer in danger reaches for non-perceptual harm,

never for a ward-stripping mechanic. (AP_0014 note)

the concealment and the bearer being safe and hidden on the field. This spec consumes them at that

tier and does not promote them.

the player wakes at the anchor — with no carried image. The surface is bare and solitary early,

gains a record at Ch 13 when the journal activates, and gains a witness who can reach you later.

That growth is authored, not accidental. [FORKB §6; the journal timing at WS_009]

---

5. THE OUT-OF-COMBAT PREDICATE

5.1 Why it must be a named primitive with provenance

The predicate does not exist in code or canon today, and whatever gets built becomes gameable:

aggro-based invites kiting past the leash radius and dying outside it; damage-recency invites

breaking line of sight and waiting the timer out. Three concrete engine defects are already

identified: a fleeing enemy counts as aggroed (a timid animal holds combat open forever); a stalking

enemy does not (the standoff is exactly where a revive window is most wrong); and

bPerceivedThisFrame is frame-transient. [FORKB §3.4]

5.2 The contract

individual actor.

the single behaviour most likely to be wrong and least likely to be noticed. [Tooth T-4]

ledger; the boolean is what predicates read.

being defeated, so a naive detector flips to ELIGIBLE because the level unloaded.

AHumanityEncounterVolume::EndPlay already retires what the volume spawned

(Humanity/Source/Humanity/Public/Combat/HumanityEncounterVolume.h L86, carrying the literal

"BUG-0018: retire what this volume spawned" comment). The predicate must read that retirement as

retired, never as defeated, and the existing GuardianTeardownOnEndPlay test is extended to

prove it. [FORKB §3.4; tooth T-5]

5.3 The grammar question — a correction to the brief, positive-controlled

FORKB §5.4 item 7 records the predicate as a GRAMMAR CHANGE and warns that flag(local.*) would

fail a produce-before-consume lint or need a fake producer. Direct inspection says the cost is

lower than that:

EBNF) and L377 (the Read node), and Humanity/Source/Humanity/Private/Quest/ConditionExpr.cpp

L288 and L571 with TSet<FString> Reads at ConditionExpr.h L45. No parser work is required on

either side.

SPINE BEAT files, not to T0_Ally_Behavior_Policy rows. Gate 29 B3 parses policy condition_expr

and does not require a producer. The existing policy rows already consume runtime-produced flags

with no beat producer anywhere: flag(local.enemy_attack_telegraph_visible) (AP_0006) and

flag(local.arena_state_changed) (AP_0008).

following the AP_0006 and AP_0008 precedent exactly, with zero grammar change and zero fake

producer. The competing option is read(...), but the grammar doc defines read(surface) as

"the named surface (an inscription or readable object) has been read"

(docs/CONDITION_EXPRESSION_GRAMMAR.md L63-64), so reusing it for combat state is a semantic

collision in a shared vocabulary. See fork D-1 in §12.

than silently matching nothing — which is precisely the failure this feature cannot afford, since

a silently-never-matching predicate is a revive that silently never fires.

---

6. THE HADES DEATH-REWARD INTEGRATION

6.1 What exists today

distinct values. [docs/DESIGN_GAP_REGISTER.md entry 109]

boss's death_reward line; HandlePlayerDeath() records it as a telemetry quest event and arms a

6-second HUD display window after respawn (HumanityCharacter.cpp L281-320 and L360-372;

ConsolationDisplaySeconds=6.0f at HumanityCharacter.h L400).

(Humanity/Source/Humanity/Private/UI/HumanityDebugHUD.cpp L600).

banked_tell_reads exist in T0_Worldstate_Variables` and have ZERO writers. [Register entry 108]

6.2 The four integrations this spec requires

economy (CVD §5 Pillar 8; T99_Translation_Combat §2.5), not a branch prize. On the revive path the

on-screen consolation line is REPLACED by the companion's own words, and the journal entry still

records the observation — one authored string, two lengths, one write. [FORKB §2.B and §4]

worldstate subsystem at the HandlePlayerDeath call site, keyed boss id to the composure-node ids

already populated on the boss row's composure_nodes column. Zero new schema, zero new registry,

one call site, and the load-bearing half of the defeat economy. [Register entry 108]

resolver has no attempt index. Ride the ledger's attempt_index and let the payout become a small

ordered set per encounter: the first death teaches the tell, a later one names the counter, later

ones stay short. Only the cardinality of one field changes. SEQUENCING IS THE REAL VALUE — do this

BEFORE the natural-voice pass rewrites 281 strings, or the rewrite is paid twice.

[Register entry 109]

repeating within one encounter instance across repeated deaths at the same attempt_index.

[FORKB §5.4 item 15]

6.3 The defeat-protected correction — struck, and why

FORKB §2.C records an analyst contradiction: one analyst specified a PLAYER-side 1-HP clamp in

protected chapters (build item A8, QA test T10), another showed that defeat_protected and the 1-HP

clamp are a BOSS column — the boss withdraws at 1 HP — and are not player-death protection. The

boss-column read is the better-evidenced one, and it is now proven from data rather than argued:

docs/PRE_5090_BUILD_PLAN.md L1425-1426 records "The defeat_protected flagship VERIFIED FROM DATA:

Naga Padoha's TRUE row drives the 1-HP clamp + WITHDRAWN" with the

Humanity.Combat.DefeatProtectedFromData test green, and docs/FUN_REBUILD_PLAN.md L370-372 names

that row as the slice's one 1-HP-clamp defeat_protected boss.

T0_Boss_Encounter_Registry, defeat_protected reads 265 EMPTY, 15 FALSE, 1 TRUE. The single

TRUE row is BE_0005_S3, Naga Padoha, the bound earth-shaker. The pre-revision draft said the

column carried "FALSE on the inspected rows," which read as if no TRUE row existed; one does, it

is the flagship, and it changes nothing about the conclusion — the clamp is on the BOSS, not on

the player.

treats empty as unset has no default at all, and this spec is scrupulous about exactly that

elsewhere. The rule is the same one §4.4 and §10 case 12 apply to ally_revive_policy: an empty

cell is authoring debt, the runtime reads it as FALSE, and only an explicit TRUE clamps. Stated

here so the "only legal source" clause below is complete rather than half a rule.

encounter, and the ruled machine runs there unchanged. A8 and T10 stay struck.

death_reward being empty, which mis-classes any boss carrying a populated death_reward

(BUG-0014). Since death_reward is now populated on 281 of 281 rows, that derivation is dead by

construction and the explicit defeat_protected column is the only legal source — read under the

empty-cell rule above. [docs/FUN_REBUILD_PLAN.md L47-50 and L283-290]

---

7. REGISTRY AND SCHEMA TOUCHES

All new columns land as Vector-C extensions declared in docs/registry_extensions.json under a

named owning system, plus docs/fidelity_baseline.json added_columns, plus

registry_fidelity.py --emit-baseline in the SAME commit. Proposed extension key for every row

below: death-choice.

#TargetChangeStatusNote
1T0_Worldstate_Variablesnew row WS_047 defeat_ledger (object, append-only)NEW ROW + APPEND_LEGAL_IDS extension in the same commit§3.1; 14 to 15 on an already-repaired precedent
2T0_Worldstate_Variablesnew row WS_048 last_attuned_site (string soft-FK, keyed-replace, NOT append-legal)NEW ROW§2.7, §3.2
3T0_Ability_Tree_Registrynew columns caster_class_scope in {protagonist, ally, both}, revival_direction_scope in {to_ally, to_protagonist, both}, out_of_combat_only (bool)NEW COLUMNSThe asymmetry MUST be schema-expressed or a future author collapses the two directions and silently legalises in-combat player revival [FORKB §5.4 item 3]
4T0_Ability_Tree_Registrypopulate the three new columns on A_A_009, A_C_003, A_C_004 and mint the L3/L4/L5 alternate-route rowsPOPULATE + MINTThe evil-lane hole is a no-dead-end violation waiting to ship; canon already declares the lane exists [T1_Ability_Tree L848; DECISIONS J-4]
5T0_Bonus_Pool_Registry / T0_Bonus_Option_Registrynew rows: pick_class=major, lane=B, unlock_gate_quest_ref populated (this is "taught"), spec_purpose_refs, respec_classEXISTING COLUMNS, NEW ROWSAccess is taught, reliability is trained; a MAJOR pick that competes with other majors, never a character's identity [FORKB §3.12]
6T0_Ally_Behavior_Policynew rows action_ref=revive_protagonist, domain=proactivity, autonomy_band=autonomous, disposition_legal_set=protective, int_tier/unlock_int_min populated, policy_source=canon_seedEXISTING COLUMNS, NEW ROWSStructurally identical to AP_0001; the condition carries the out-of-combat token per §5.3
7T0_Ally_Behavior_Policyre-scope AP_0001 and AP_0005 so a DOWNED player does not satisfy the health-fraction predicateEDIT IN PLACE, SAME COMMIT as the downed state§2.5; FORKB §3.5
8T0_Familiar_Bond_Abilitya revival rungBLOCKEDThese rows are COPY-ONLY from T3_Familiars_Named §1.6. A revival rung cannot be invented in the registry; it needs a living-source T3 edit. Gate 29 B2 polices 22 x 5 coverage. [FORKB §5.4 item 5]
9T0_Spec_Purpose_Registrynew row SPEC_VRIL_REVIVE_ALLY (function_class=heal, scope_class=single, role_axis_ref=ROLE_SINGLE_HEAL)NEW ROWWithout it the build-space sweeps cannot count revival builds as a distinct viable spec, and an uncounted spec is invisible to the balance teeth. Existing ids are token-named (SPEC_VRIL_HEAL_PERSONAL and five others), so the naming pattern holds
10T0_Boss_Encounter_Registrynew column ally_revive_policy in {allowed, denied} on the proven combat-encounter railNEW COLUMNDefault allowed; EMPTY = not-yet-populated, NEVER denied §4.4
11T0_Boss_Encounter_Registrydeath_reward cardinality: one value becomes a small ordered set keyed by attempt_indexCOLUMN SEMANTICS + AUTHORINGDo it BEFORE the natural-voice pass touches 281 strings §6.2
12T0_Creature_Rosternew column downed_target_policy in {disengage, execute, guard, ignore}NEW COLUMN, BLOCKINGRides the missing non-boss aggro block, DESIGN_GAP_REGISTER gap #1, owner W-SPACE. execute is what lets the wait end worse than letting go, with no die roll — but its interaction with the ruled countdown is NOT settled: the column mints regardless, the BEHAVIOUR waits on §12 D-8
13T0_Status_Tablenew rows: the player's reduced-vitality return; the ally's post-revive exhaustionNEW ROWSSuccessive revives return progressively less and leave a lingering impairment on the ALLY, so chaining is self-defeating without a counter to game or a number the UI must show. Existing ids run ST_001 through ST_010
14T0_Role_Composition_Ruleone row asserting a viable glass-damage composition WITHOUT a revive-capable allyNEW ROWThe anti-mandatory-support tooth [FORKB §3.12]; existing ids run RCR_001 through RCR_004
15T0_Voice_Registryregister for the countdown line and the companion's revive lineREFERENCEThe strings themselves live in the sidecars §8
16WS_027 companion_roster_state, WS_012 familiar_bond_statenew sub-field taught_capability_refs; derived revival_readinessNEW SUB-FIELDSWS_012's vril_integration_state (latent, developing, integrated) is already the teaching ladder. CROSS-SPEC, and the ratified line wins: WS_027 is the single canonical home for per-companion state per T1_Integrity_Paths_Worldstates_Master [ACTIVE v2.1] §8.11.6 L581 — persistence rides the per-companion roster object at WS_027, which carries loadout state alongside the loyalty fields once the schema pass authors the columns. This spec AUTHORS ITS COLUMNS THERE and never relocates the object; the loadout-sets spec authors its own columns on the same row in the same pass. One home, one pass, no second mint. The ratified standing bar binds both: until the pass lands, no consumer may read a field that does not yet exist
17docs/DESIGN_GAP_REGISTER.md entry 114 — telemetry enrolmentenrol WS_047 as a TELEMETRY-VISIBLE surface beside the existing six recorders, and assert the entry's two magnitude-free properties: NO ATTEMPT PAID NOTHING, and the world delta applied EXACTLY ONCE per attemptENROLMENT, NOT A NEW REGISTRYEntry 114 is the QA-LOOP OWNER of this artifact's outcome-and-economy axis ("the telemetry family is exactly six recorders and none of them observes an outcome"). Teeth T-9 and T-7 are the executable form of its two properties. Naming 114 here is what keeps the two documents from forking, and the entry's own named landmine is row #1's APPEND_LEGAL_IDS co-landing. Entry 114's boundary is pre-blessed by its adjudication 4: the run-ECONOMY axis, deliberately orthogonal to per-attempt execution-surface latency

Canon edits, each critic-gated before it lands:

(a companion holds no Enhanced Ability Mastery because the infinite-vital-energy devices bond to

the protagonist's vril-seat equipment only, so no Crown-seat channel survives combat pressure).

set, the DOWNED-versus-DEAD line with Josh's story-death exception clause, and the zero-bond-movement

rule. The WS_027 column expansion authors at the same schema pass §8.11.6 already names.

coupling, and the §3.3 clause that the hold does not step withdrawal_timer.

content, alongside the vril-polarity readability floor already earmarked for it. Register entry 112

routes it into the same rank-20 fill as the gameplay-camera, onboarding and HUD-legibility findings:

same doc, same pass, one owner, never a second lane.

---

8. THE STRING SIDECARS

The player strings live in docs/spine/player_strings/CH_NN.csv with the columns

kind,key,player_text (verified on CH_01 through CH_05 and CH_PROLOGUE). The death surface needs a

new kind, because these strings are surface-scoped rather than beat-scoped.

registered per region, which the natural-voice doctrine requires.

line per attempt_index; the companion's revive line.

on any longer" is the READ to be delivered, never the string to bake. It goes through the

natural-voice register and must land in the protagonist's own first-person voice — a person's

failing strength, not a system message. [DECISIONS J-1; PRESENTATION_DOCTRINE §0.B.1a and the

§3.2 defeat row's explicit SEED-NOT-SHIPPABLE-WORDING marker]

"Go back." Two opposites, both what a person actually thinks, neither naming a system, and

critically neither PROMISING rescue, so the honest-failure cases do not read as broken promises.

[FORKB §4]

string that EXPLAINS what death is hands the player Layer-3 metaphysics on a surface they will

see fifty times. The return is SHOWN, never explained. Canon models this exactly: the four

revival ability rows describe what happens and never what it means.

internal tokens and never appear on the surface.

harness/check_reveal_discipline.py WHO_SOFT.

is internal design vocabulary on a player-facing frame (naming the mercy destroys it),

"DEFEATED" is system voice, and the consolation payload is system voice too.

bringing someone back is one adjective away from theology. Relief, reproach and exhaustion —

never cosmology. It takes the natural-voice pass with string_status tracked AND the reveal gate.

the state, and not the boss. BE_0002 carries boss_name "Rangku Wera, the Quiet Step" and

display_name "the one who tracks me" — the surface draws the diegetic name or no name, never the

registry name. [DECISIONS J-7; the registry values verified in T0_Boss_Encounter_Registry row

BE_0002]

---

9. UI SURFACES

The presentation is already RULED at docs/proposals/PRESENTATION_DOCTRINE.md §0.B and is not

re-authored here. What follows is only the runtime contract the UI layer must satisfy.

9.1 What is on the surface

Exactly two authored elements and no third: THE VOICE (the countdown read, at the EDGE of frame,

never a centre-of-screen meter) and THE CHOICE (LET GO). No mode taxonomy, no ability name, no

state name, no nameplate, no greyed second option. [DECISIONS J-7; the no-mode-taxonomy rule at

memory no-mode-taxonomy-on-player-surfaces]

9.2 What the camera must do

that keeps the last look stares at a wall for half of all deaths and the wait reads as broken.

This is a build requirement, not a polish item.

point of the state is that the player can SEE whether anyone is coming.

you see them. If nobody is out there, you see empty ground.

9.3 The honest-failure reads — load-bearing, not polish

A wait that resolves into nothing is indistinguishable from a bug, and not being able to tell IS the

failure. The read is selected by which §4.2 gate failed first:

First failed gateThe image
4 (encounter unresolved)the ally still fighting; you watch them try and fail to disengage
6 (cannot reach)the near-miss
5 (no vril)they arrive, kneel, and cannot
3 (never learned it)they arrive, kneel, hold on, and stay with you while the draw takes
1 or 2 (dead or departed)empty ground where they would have been; say nothing; the absence is the memory

Per §12 D-4, the selected image PLAYS TO ITS AUTHORED LENGTH, and in the permanently-impossible case

(gates 1, 2 or 3) the hold then RESOLVES rather than running the clock out behind an image that has

already finished. The image is the load-bearing part; the silence after it was not. The gate-4 read

is the exception and it runs the full clock, because that fight is still happening in front of the

player (§4.4, §4.5, §10 case 13).

If these images are cut for budget, the "it is a slot machine" objection becomes correct and the

feature should not ship. [PRESENTATION_DOCTRINE §0.B.2; FORKB §4]

9.4 Reveal discipline — this surface needs its own baseline entry

The death surface is the highest-frequency player-facing text in the game and it fires from Ch 2.

Five named risks, in severity order, carried forward as build constraints:

pulse, a light, a sense of being held, the collective reaching for you — is exactly HL_0046's

Grand Sage communication vocabulary (visions, intuition pulses, vibrational imprints), deployed on

a surface visited dozens of times before Ch 76. HL_0044's protection assumes hints are rare enough

to police individually; a death screen played 200 times is a drip.

harness/check_reveal_discipline.py reads canon artifacts, not runtime presentation, so this is a

MAJOR-class hazard the existing gates would NOT catch. The surface takes its own named entry in

the reveal-discipline baseline. [FORKB §4 R1b]

Duat Ch 69, the Realm Road Ch 70-74). Keep the revive VITAL AND MEDICAL, never mythic: someone

catching you, not someone raising you. The resonance is allowed to exist and a player who read the

Osiris material will feel it — that feeling is the payload, and naming it destroys it.

familiar reveal. The death-and-wake loop rhymes with the Ch-2 opening ("Get up. Climb toward the

light." — verified live in docs/spine/player_strings/CH_02.csv beat CH02_B01), which is a free

presentation asset with a hard constraint: it must never re-stage the familiar's death image or

gesture at it.

(Astral Projection) and leaks a Crown-seat capability the player does not have. Pre-Ch-15 the read

is body-and-senses: the world greys, sound muffles, edges go soft. Not a soul leaving — a vessel

emptying.

9.5 Accessibility floor

Options are TEXT plus a distinct input, never colour-coded or icon-only. The companion's approach

needs TWO INDEPENDENT CHANNELS (silhouette and motion in frame, which is what the arena-biased yaw

buys, AND audio). The diegetic vignette timer needs an explicit duration-indicator backstop for low

vision. The dark hold into a bright vril close-up is a PHOTOSENSITIVITY RISK BY CONSTRUCTION and

needs a reduced-intensity variant — a hard floor item on the most-repeated surface in the game.

Motion sliders inherit. No hold-to-confirm-only, no twitch window, full remap, one-handed reachable.

9.6 The overlay precedence collision

BUG-0017's single-framed-overlay invariant has an unruled collision: dying during a held scene, or

dying with a fork pending. Recommended precedence, applied here as reversible: THE DEFEAT SURFACE

OUTRANKS BOTH. Also, CP-6 needs one clarifying clause, because the hold can outlast the arc-reveal

hold: the hold is a player-paced live-world state OUTSIDE the hold-class ordinal ladder (closer to

CC-9 dwell), or a future author will read a contradiction into a ruled doc. [FORKB §4 doctrine deltas]

---

10. EDGE CASES

Each one names the behaviour and its reason. These are the cases a runtime gets wrong silently.

1. Death by environmental hazard or fall damage with no encounter active — the machine runs

normally; encounter_ref is empty, combat_end_provenance=unresolved, and no boss consolation

resolves. The world delta still applies; reward-on-death is not boss-only.

2. Death during a cutscene or a held scene — §9.6 precedence; the scene yields to the defeat surface.

3. Death while a dialogue fork is pending — the fork is preserved and re-offered after the terminal

frame. It is never auto-resolved by the death.

4. The encounter resolves in the same frame the clock reaches zero — THE CLOCK WINS. Ties resolve to

the rescue. This is stated so it is not left to float ordering, and it is the merciful-and-honest

ordering: the player did not survive on a frame technicality they cannot perceive.

5. Two allies both eligible in the same frame — the highest-priority policy row wins

(T0_Ally_Behavior_Policy.priority), then the lowest ally index. Deterministic, never random.

6. The reviving ally is downed mid-approach — eligibility re-evaluates; the read falls back to the

next candidate or to the honest-failure image. No state is rolled back. If that re-evaluation

makes the case permanently impossible, §4.5's bounded window applies from that moment.

7. Mass Revival (A_C_004, revival_aoe) fires while the player is downed alongside allies — the

player is a legal target of the AOE under the same seven gates. The direction scope columns

(touch #3) are what keep this from also legalising an in-combat player revival.

8. The player dies while already at reduced vitality from a previous revive — the status stacks per

the T0_Status_Table row's stack_op and stack_cap; successive revives return progressively

less. This is the chain-limiter and it must not surface as a number.

9. Level streaming or volume teardown during the hold — §5.2 teardown trap; provenance is retired

and the predicate does NOT flip to eligible.

10. Save and quit during the hold — the hold is not a persistable state. Loading resolves to the

anchor as if the timeout had run. The ledger append fires on the resolution, not on the load.

11. The anchor site is unreachable or was never touched (a chapter entered without a recharge

channel) — fall back to the chapter's entry site, and record the fallback in the ledger. Never

fall back to nearest-by-distance, which is the exact bug §2.7 retires.

12. The ally_revive_policy cell is EMPTY on the encounter row — treated as allowed. Empty means

not-yet-populated and never denied. The same empty-cell rule governs defeat_protected (§6.3).

13. A chain-meter boss's field is cleared by the party — the encounter does NOT resolve, so the

surface stays exactly as it is and the FULL clock runs. This is the case the "waiting always

shows you something" requirement exists to keep readable, and it is why §4.5's impossibility

test deliberately excludes gate 4.

14. downed_target_policy=execute fires during the hold — PROVISIONAL, and this case is the visible

surface of a genuine fork rather than a settled behaviour. Per §12 D-8's recommendation the

execution STEPS THE HOLD CLOCK DOWN by its authored magnitude instead of terminating the hold;

if the step drives the clock to zero the ordinary clock-zero row fires and the ordinary rescue

resolves with outcome=timeout, and execute_pressure_applied is recorded on the ledger entry.

The wait genuinely got worse, with no die roll. Do NOT implement the TERMINATING form without

D-8's resolution: it collides with a ruled clause (§2.4 bullet 3), and execute is blocked on

the non-boss aggro spec in any case (§13.2).

15. downed_target_policy=guard — the enemy holds over the body and refuses to leash, so combat

never ends and the wait cannot resolve to a revive. Legal and authored, not a bug. Note this is

a gate-4 case, so the full clock runs (case 13's rule, not §4.5's).

16. Allies must NOT initiate new engagements while the player is downed — they finish what is on

them and come. One rule; it closes the AFK-farm-from-the-floor exploit and improves the fiction.

17. The player is downed with zero allies ever recruited (the whole Josh Gate slice) — §4.5 returns

IMPOSSIBLE, the empty-ground read plays, and the hold resolves at the end of it per §12 D-4. The

machine is identical and the roster is empty.

18. Repeated deaths at the same encounter — attempt_index increments and the payout advances

through its ordered set (§6.2); consolation_paid prevents a same-index repeat.

19. A persona'd ally would die in combat — it does not. Allies go DOWNED, never dead, in combat.

This also protects the gear-return contract from a loot-loss edge case. Story death remains

legal through the integrity or story lane only. [DECISIONS J-2 exception clause]

20. The rescuer is not yet in the party (before Ch 13) — the rescue resolves with no carried image

§4.6.

21. The bearer acts while carrying — AP_0013 lapses the concealment. The spec treats the carry as

NON-acting; any design that makes it an act re-opens the whole rescue path §4.6.

22. Non-perceptual harm reaches the bearer — the ward yields (AP_0014). Legal, authored, and the

only sanctioned way to put the rescuer in danger.

23. Death inside a COMMITTED rift-run pocket — DELEGATED, not answered here. The rift-dungeon spec

owns pocket interiors, and its ruled rule is that a committed run's pocket inherits NO sanctum,

under the no-lockout law. This machine therefore resolves the rescue to the run's own entry

anchor rather than to WS_048, and records the substitution in the ledger's world_delta_ref.

One owner, never two mints: if the rift spec's pocket rule moves, this clause follows it rather

than forking from it. The no-lockout law is what guarantees the resolution has a destination, so

T-6 holds inside pockets too. [Cross-spec director ruling, 2026-07-29]

---

11. VERIFICATION TEETH

Nine teeth. Every one carries a MUST-NOT-FIRE twin, because a tooth that can only pass is a tooth

that reports zero when it cannot match. Fixtures are named so the tooth is runnable, not aspirational.

T-1 THE CHOICE IS OFFERED AND THE OLD TIMER IS NOT ARMED

RespawnTimerHandle is NOT armed.

DeathFadeSeconds=0.55 and RespawnHoldSeconds=0.9 must have no live reader.

T-2 THE ANCHOR IS THE LAST-TOUCHED SITE, NOT THE NEAREST

rescue resolves at VS_CH02_001.

to the near marker and prove the assertion flips, so a tooth that always passes is impossible.

VrilSiteId=VS_CH02_001; WS_048 read after the terminal frame.

T-3 THE DOWNED PLAYER DOES NOT SATISFY HEALTH-FRACTION PREDICATES

evaluate TRUE and no interpose dispatches.

still satisfy AP_0001. A fix that kills the predicate outright passes the first assertion and

breaks the feature.

the UE-side FHumanityConditionExpr49Test idiom for the runtime half.

T-4 THE OUT-OF-COMBAT PREDICATE HOLDS THROUGH A MOMENTARY LINE-OF-SIGHT BREAK

predicate stays FALSE for the entire break and no revive gate opens.

window, with combat_end_provenance=defeated.

least likely to be noticed, and a frame-transient bPerceivedThisFrame read passes a naive test.

T-5 TEARDOWN DOES NOT FAKE OUT-OF-COMBAT

AHumanityEncounterVolume::EndPlay) yields provenance retired and the predicate does NOT flip

to eligible.

defeated.

T-6 THE LET-GO PATH NEVER FAILS

encounter, ally roster, arena, integrity band or policy data can produce a state in which LET GO

is unavailable or its resolution has no destination. The impossibility window (§4.5) and the

execute step (§10 case 14) are both inside the invariant's scope — neither may gate the press.

site_id) must FAIL the gate rather than silently pass, proving the invariant is armed and not

a scaffold.

T-7 THE LEDGER APPENDS EXACTLY ONCE AND THE WORLD DELTA APPLIES EXACTLY ONCE

and under both delegate bind paths (PossessedBy and OnRep_PlayerState).

death_event_id values and attempt_index incrementing.

branches, asserting no leaked RespawnTimerHandle, no duplicate ledger rows, no actor leak, and

stable peak memory. Player death has ZERO test coverage today while 55 UE automation tests assert

boss defeat, so this lane is new surface, not an extension.

property (the world delta applied exactly once per attempt). T-9 carries the first.

T-8 THE ASYMMETRY IS UNSPELLABLE-TO-VIOLATE IN DATA

revival_direction_scope=to_protagonist without out_of_combat_only=true. Josh's constraint made

impossible to violate in data rather than policed in prose.

is LEGAL and must pass, or the tooth is really just banning a column value.

check_ally_build.py self-test idiom.

T-9 NO ATTEMPT PAID NOTHING

covered): every WS_047 entry carries a non-empty payout — consolation_paid=true, OR a

non-empty banked tell-read delta (WS_041 or WS_042 moved on this death_event_id). The tooth

asserts NON-EMPTINESS, never a number, so it survives every Phase-5M retune untouched. This is the

executable form of §6.2's BOTH PATHS PAY, which is the load-bearing economy claim of the whole

defeat axis — an unasserted version of it is exactly the defect class that ships silently.

consolation and no banked read — must FAIL the tooth. A tooth that cannot fail on the constructed

violation is reporting zero because it cannot match.

harness-side scan over the ledger fixture so the property also runs at zero token cost on commit.

are named there as its executable form so the two documents do not fork, and WS_047 is enrolled

as a telemetry-visible surface per §7 touch 17.

Two further teeth already specified elsewhere and enrolled by reference rather than re-authored:

the revive-capability PROVENANCE tooth (every taught_capability_refs entry resolves to a row with

ability_class in {revival, revival_aoe} and a satisfiable band lock, positive-controlled so an

unreachable resolver reports as unreachable and never as a clean zero), and the EVIL-LANE HOLE tooth

(if the L1/L2 lane is a live affordance and L3/L4/L5 is empty, fail or warn with a named worklist —

the executable form of the no-dead-end floor). Both are FORKB §5.5 items and both belong on Gate 29.

Gate ritual for any commit touching this feature: run_gates.py UNPIPED, plus

registry_fidelity.py --emit-baseline in the SAME commit as any registry edit, plus

check_registry_extensions.py, check_ws_value_form.py, check_reveal_discipline.py and

check_grand_sage_silence.py scoped to the new strings.

---

12. THE GENUINE FORKS — options with recommendations

Per the standing decision protocol, each carries alternatives, a recommendation, and the strongest

objection. D-4 is RESOLVED by the director in this round and is recorded as resolved; every other

entry here is unapplied.

D-1 THE OUT-OF-COMBAT TOKEN

AP_0008, no fake producer needed (§5.3 positive control).

read(surface) as an inscription or readable object having been read, so it overloads a shared

vocabulary.

plus a grammar-doc amendment.

shared vocabulary. STRONGEST OBJECTION: local.* reads as beat-scoped to anyone who learned the

grammar from the spine files, so (a) buys cheapness with a readability cost that (c) does not have.

D-2 THE LEDGER'S HOME

definition. STRONGEST OBJECTION: a new append-only variable is a THIRD touch of a ruled constant.

APPEND_LEGAL_IDS has already been reconcile-and-extended twice (6 to 12, then 12 to 14), each

time by deliberate ruling and each time correctly — but every touch opens a window in which a

ruled enumeration and its data can drift apart, and the co-landing requirement is the only thing

that closes it. (b) needs no such window.

D-3 REDUCED VITALITY MAGNITUDE AND THE CHAIN CURVE

execute step magnitude, the revived vitality fraction, the ally vril cost, the two branches'

currency weights, the INT threshold at which an ally notices, and the reduced-vitality stack curve.

This is not a fork so much as a firewall reminder — nothing here may be picked by an engine agent.

D-4 THE IMPOSSIBILITY CASE — RESOLVED 2026-07-29 (DIRECTOR'S CALL)

behind a finished image — FORKB §3.11's literal reading, "fail fast and honestly."

revived. The decisive evidence is this feature's own §4.5 — in the Josh Gate slice the

impossibility test returns IMPOSSIBLE on EVERY death, so under (a) every death for eleven chapters

costs a full two-minute wait on a branch that was never going to open. That is not a hypothetical

objection; it is the entire playable slice and the only player the QA loop has.

gate and PLAYS to its authored length — the resolution is never a cut to black, and

PRESENTATION_DOCTRINE §0.B.2's "waiting always shows the player SOMETHING" is satisfied by the

image, not by the silence after it. LET GO stays live for every frame (T-6 unaffected). The

window's magnitude is Phase-5M under D-3.

That cost is accepted and mitigated by carrying the knowledge as an IMAGE rather than a system

message — empty ground, or someone who arrives and cannot. The player learns a fact about the

world, not a fact about the machine.

ally cannot disengage from — including the chain-meter boss whose win condition only the player

can perform (§4.4, §10 cases 13 and 15) — runs the FULL clock, because something is happening and

the player is watching it. §4.5's test reads gates 1, 2 and 3 only. Widening it to gate 4 is the

most likely way a future implementer breaks this quietly.

§3.11 L274 reads "W6 IMPOSSIBLE must fail fast and honestly — never run a timer out on a player

who was never going to be revived." The pre-revision draft REVERSED that clause and re-scoped

"fast" to the read rather than the state, while simultaneously declaring the behaviour

non-negotiable at §2.2 and open at §12 — a contradiction a document cannot hold. The 2026-07-29

fresh-context critic round caught it and named the reversal; the director resolved it to (b) under

the delegated design authority, and the reversal is WITHDRAWN. Both §2.2 and this entry carry the

record.

D-5 THE PATH-PARITY MECHANISM (already routed to Josh, unresolved at J-4's grain)

a separate L4/L5 route, HL_0076 magnitude banding (which routes cleanly around the §8.11.8

firewall because no condition_expr reads loyalty and the magnitude rides the band exactly as all

healing does), or both.

orthogonal. STRONGEST OBJECTION: it touches the equally-weighted-endings architecture, which is

Josh's, and doing both is the largest authoring surface of the three.

D-6 THE TIER-C BAND-LOCK COLLISION — name it now, do not solve it here

Truly Good guild"), but every revival row carries integrity_band_lock of L1 or L1,L2. Under

current data an L5 guild cannot field a rezzer at all — a direct contradiction of a ratified

Tier-C rule.

T1_Ability_Tree §12 says catalog access is FOR — path identity and replayability), and Tier-C

fields the L4/L5 alternate route so the role space stays equal. This promotes the evil-lane

revival from a no-dead-end nicety to a Tier-C BLOCKER.

D-7 THE FAMILIAR REVIVAL RUNG

cannot be invented in the registry.

permits this); (b) leave familiars out of the revival lane entirely and keep it companion-only.

linked allies holding revival-class casts. STRONGEST OBJECTION: familiars are the ally class the

player has EARLIEST, so granting them the revive is the fastest way to make support-familiars

mandatory — the banned meta-collapse mode.

D-8 THE execute COLLISION — ✅ RULED (Josh, twenty-first sitting 2026-07-29): OPTION (b) ACCELERATE

Josh, verbatim: "1 b yeah agreed with recommendation" — an execute ACCELERATES the countdown;

the acceleration magnitude is a Phase-5M tuning value, never canon. The options record below is

preserved as the decision history.

Raised to a fork on the director's instruction in the 2026-07-29 critic round, and deliberately NOT

resolved inside §10, because what collides here is two ruled things rather than a design taste, and

§10 is a section readers treat as clarification rather than policy.

mechanic, FORKB §5.4 item 13 grounds the column, and Shape B was the adopted shape — so execute

is not this spec's invention. But PRESENTATION_DOCTRINE §0.B.1a L143-145, inside THE RULED CLAUSES

block, states that no input is a legal, UNPUNISHED way to play the beat, and §2.4 restates it as

ruled floor. An execute that TERMINATES the hold punishes the no-input path in kind: the wait

ends worse than the press, which is precisely what that clause forbids. Two ruled things, one

runtime. The mechanic's VALUE is not what makes this a fork; the clause conflict is.

countdown read "XX seconds until you cannot hold on any longer" becomes a promise the surface

cannot keep — which §8's own refuse-list bans as a PROMISING string.

as "the highest-value single value in the enum."

clock down by an authored magnitude, and if the step drives it to zero the ordinary clock-zero row

fires and the ordinary rescue resolves.

provisional. Originally carried as a PROVISIONAL row so the

state machine is complete against §10 while the fork stays genuinely open. It is the only reading

that satisfies BOTH ruled clauses at once. The countdown stays TRUTHFUL because it reads live

remaining hold and the player watches the number drop; a shortening you can see is not a broken

promise, and an enemy standing over your body is the most legible possible reason for one. And the

no-input path stays unpunished IN KIND: its outcome class is unchanged — still the rescue, still

outcome=timeout, still the ruled resolution — it simply arrives sooner. The defeat axis keeps its

teeth: the wait genuinely got worse, with no die roll, which is what (a) was bought for.

§3.1(c) was that the wait can end WORSE than letting go. Under (b) it ends SOONER but in the same

place, so a player who reads the ledger learns the two branches converge and concludes the pressure

was cosmetic — the exact meta-collapse-on-the-defeat-axis defect §3.1 exists to prevent. (a) keeps

the sharpest defeat axis at the cost of a ruled clause; (c) keeps both ruled clauses cleanly but

spends the enum's best value on a case the player never sees.

blocked on the non-boss aggro spec (DESIGN_GAP_REGISTER gap #1, owner W-SPACE, §13.2). This fork

therefore gates nothing in the slice and can be resolved on real feel strips rather than argued —

which is the right way to settle it.

---

13. BUILD SEQUENCING AND THE ENGINE-VERSUS-CANON DECLARATION

Per the standing engine-reuse rule, every item declares whether it is reusable ENGINE or

game-specific CANON, so game two is a harvest.

13.1 Build-now, no ally runtime required

sites). Hard prerequisite: there is no checkpoint to revive at today.

hold state SURFACE-AGNOSTIC so blocking-ness is a property of the surface and not of the machine.

This is a build-now architectural requirement, not a Tier-C afterthought, because 100 players

cannot hold on one player's prompt and the MMO form is a non-blocking timed release-or-wait.

pays FOUR existing debts on landing: rage decays out of combat, stamina regenerates out of combat,

loadout switching is never mid-encounter, and every T0_Ally_Behavior_Policy predicate that needs

to know a fight is running. Schedule it regardless of this feature.

Without it the choice is cosmetic.

Four of those seven are slice requirements on their own merits. That is the strongest scheduling

argument in the whole feature: they get built either way, and this spec is the reason they get

scheduled.

13.2 Post-slice

The ally pawn and AI subsystem (the largest single item, greenfield, with a head start because the

predicate evaluator already exists on BOTH sides); party combat that continues after the player

falls (which is what makes the out-of-combat rule MEAN anything); downed_target_policy plus the

execute windup (blocked on the non-boss aggro spec, DESIGN_GAP_REGISTER gap #1 — and its

hold-clock interaction is §12 D-8, unresolved, so the behaviour lands with the fork, not before it);

the revive cast and presentation hookup; the teaching loop.

13.3 5090-era

The death presentation itself is explicitly deferred as an art placeholder. Name this surface as a

FLAGSHIP CASE in the tiered-asset request: the revive is the ONE ability the player watches from the

receiving end, in close-up, held still, so a low-tier revive should look effortful and a mastered

one should look like nothing at all. It is a held close-up, not a combat-speed flourish.

[Josh's presentation-ladder nod, 2026-07-26; FORKB §5.3 C2]

---

14. THE HONEST SCOPE STATEMENT

This feature has ZERO surface in the Josh Gate slice. Ch 2 through 7 stay solo as built, the

earliest companion window is Ch 13, and the revival ladder sits at T5 of a twelve-tier climb. The

machine ships present and honest, with the wait resolving truthfully to "no one could reach you" —

and, per §12 D-4, resolving PROMPTLY there, because a two-minute clock on a branch that cannot open

is a tax levied on every death in the only eleven chapters that exist.

That is a design gift rather than a defect, and it must be BUILT that way rather than DISCOVERED

that way: the death surface is bare and solitary early, gains a record at Ch 13 when the journal

activates, and gains a witness who can reach you later. Built deliberately it is a true story about

the arc — the world starts empty and fills. Discovered as a bug report it is a disaster. And the

one thing this spec must never produce is a greyed second option teasing a capability the game

cannot deliver for eleven chapters: a taught-then-broken affordance is worse than an absent one.

Generated by harness/site/structure_site.py — the URL path is the repo path. review root