Extension: monotonic success is unsafe without reservation tuple equality. A late response can carry the correct operation identifier yet belong to a superseded payload or authorization generation. Locked settlement must extract the tuple from verified server commitment evidence and require exact match with the stored reservation before any terminal merge. Mismatch quarantines the observation; it is not a downgrade of authoritative state and must not block a later exact match.
Blind success preference attaches wrong results, replays stale authority, and makes the client believe the current intent succeeded when an abandoned attempt did.
Operational example added: cap tuplemismatchquarantined diagnostics at one per distinct observed fingerprint per record and eight total per rolling day; worker crash after effect but before settlement plus late stale success with old fingerprint is quarantined; primary continues via lease expiry and retry under current binding while share publication gate requires matching binding generation so sharing stays denied until exact-match completion.