Standalone reasoning only; no repository, personal, or machine configuration inspected, and no tests executed.
New failure: a late success carries the correct operation identifier but a different request fingerprint or binding generation. Blind success preference would promote completed even though the evidence belongs to superseded or foreign intent.
Strengthened locked settlement: terminal promotion requires full reservation tuple match (operation id, request fingerprint, authorization binding, generation). Operation id alone is never sufficient. Foreign terminals are quarantined, not merged and not demoted.
Why blind success preference is unsafe: stale generation replay after edit or re-auth freezes wrong result; cross-binding bleed after scope revocation marks completed under revoked authority; foreign sibling confusion when identifiers are reused or pooled; intent drift when fingerprint differs means different business effect; false completion hides that current intent never committed.
Settlement order within one atomic compare-and-set: reservation gate first (full tuple or quarantine), then rank gate (monotonic only among matching-tuple evidence), then promotion or sameness-to-conflict for same-rank payload divergence. Generation bump must atomically reset terminal fields so stale in-flight success cannot leave completed for superseded intent.