IRON LITANY

Covenant of the Independent Witness

This original game mechanism turns shrine observance into embodied work. The priest meters incense air, closes an inscribed challenge contact, watches an independent sealed relay answer, and binds only the connection that physically answered. The tank continues moving and fighting throughout. Sound reinforces visible evidence; sound is never the only way to finish the rite. The mechanism is a game design extrapolation, not a claim that this exact rite exists in published lore.

Work and evidence

1. Meter the smoke. A shutter controls air through an incense cup. The tank's current casing heat determines how much draft it draws. Too little air folds smoke into the cup; too much tears it against the casing. A steady plume permits the witness to charge. The relationship is constant and readable: target = clamp(.76 - .005 * heat, .28, .70), with a tolerance of .085 on either side. A single memorized setting does not cover the ordinary heat range.

2. Challenge a real circuit. The three inscribed contacts—Iron Remembers, Ash Bears Witness, Bone Keeps the Vow—connect different physical branches. Hold one contact for four seconds with a steady plume. Its five sealed pins rise in order at 1.2, 1.8, 2.4, 3.0 and 3.6 seconds. Early release discards unfinished charge. An unstable plume also resets charge. The circuit does not accept isolated click events as work.

3. Judge the witness. Foreign answers can reach contacts at .3, .6 and .9 seconds without moving the sealed pins. Captions describe that contradiction: an answer reached a location while its sealed pin lay still. They never name the hidden cause. Actual pin impressions persist in wax after proof is earned and the priest releases the contact. Only already-observed physical impressions appear in presentation data.

4. Bind the witnessed connection. Begin at its first wax impression. Draw the stylus through each observed groove and let the next contact take the wax before turning. The simulation moves the actual stylus at .8 normalized board units per second and requires .22 seconds inside a pin radius of .047. Pointer coordinates supply a target; they cannot move the tool or award progress without elapsed simulation time. The stylus and its pointer target should be visibly distinct.

5. Seat the seal. The player must explicitly lift the completed stroke. The seal then settles for .9 seconds. The module reports completion once; the host applies the circuit-specific benefit.

A stroke that physically leaves the witnessed groove makes a visible misconnection. It costs three spirit and two trust, leaves a scar, clears the witness and requires the same circuit to be challenged again. It does not consume another preparation or reroll the route. One physical failure produces one cost; stale commands cannot repeat that cost. Lifting a merely incomplete stroke breaks its ink and retains its earned witness, without a punishment beyond lost time.

Host integration

dist/game/src/covenant-rite.js has no DOM, audio, clock or random dependencies. The host owns station proximity, reagent payment, need predicates, cooldown and rewards. The intended preparation spends one incense and one seal. The station must remain within reach on every tool command. The host supplies the priest's real position, never a requested success flag.

The host calls:

s.action = createCovenantAction(s, 'shrine', 'vessel');
covenantCommand(s, 'covenant-draft', {opening: .55});
covenantCommand(s, 'covenant-contact', {contact: 'iron', held: true});
// Advance through the normal live simulation; dt is capped at .25 seconds.
const completed = advanceCovenantAction(s, dt);
covenantCommand(s, 'covenant-contact', {contact: 'iron', held: false});
covenantCommand(s, 'covenant-trace', {x: .18, y: .18, held: true});
// Further targets must follow the witnessed route; progress comes from advance.
covenantCommand(s, 'covenant-trace', {x: .50, y: .18, held: true});
// An explicit release seats only a completed trace.
covenantCommand(s, 'covenant-trace', {x: .50, y: .50, held: false});

The example coordinates illustrate the command protocol, not a universal solution. Route templates are adjacent paths derived deterministically from campaign seed, leg, station, intent and the chosen contact. They never consume campaign RNG. Cancelling and restarting cannot reroll that profile. createCovenantAction returns null for invalid station/intent/state. The supported pairs are shrine/vessel, shrine/self and vox/vessel.

Source snapshots match intent exactly. Shrine/vessel witnesses shrine incidents and shrine taint. Shrine/self witnesses self incidents and personal corruption. Vox/vessel witnesses vox incidents and vox taint. A foreign reply remains stable during that paid attempt even if a different action subsequently resolves its source. Host completion must use the snapshot target and actual incident identity; it must not purge unrelated or unobserved intrusions.

covenantCommand returns {ok, message}. Unknown or malformed tools, paused/out-of-mission tools, invalid coordinates and obsolete contact releases return failure without advancing the work. covenant-cancel removes the action without granting a benefit or refund. The ordinary root cancellation path may also remove the action after releasing its tools.

advanceCovenantAction(s, dt) returns true exactly once when the seating phase completes. It changes no resources, health, corruption, incident resolution or spirit acknowledgment. The only direct world cost is the explicit physical misconnection described above. The host should remove the completed action after applying its own final reward.

Workplate and accessible input

The nine node centres are a 3 by 3 grid at x/y .18, .50, .82; IDs 0–8 run left to right, top to bottom. Iron's challenge contact is node 0, Ash's is node 2, Bone's is node 6. COVENANT_NODES and COVENANT_CONTACTS expose immutable physical geometry and inscriptions.

Use pointer capture for deliberate contact/stylus holds. A pointer release sends the corresponding held:false command; it never infers success from UI animation. A keyboard stylus targets the same board coordinates with arrow directions and a deliberate held/released binding state. Its movement still passes through the same authoritative weighted tool and dwell checks. Focus on this control must suppress global movement keys. A shutter slider supplies the same opening regardless of mouse, touch or keyboard input. A rejected starting stroke should explain where the resting tool or first impression is.

Render the actual lifted pins, smoke condition, witnessed wax path, actual stylus, pointer target, contact seating and miswire scar as physical brass, soot, iron and wax. Keep the compact existing low-resolution gothic treatment. Use a stable workplate through all phases so pointer capture and keyboard focus cannot disappear. Avoid numbered choice menus, pulse rings, decorative success counters or bright game-show prompts. Visible instructions and physical evidence must remain available without audio.

Presentation, cues and persistence

covenantPresentation(s) returns a cloned view:

{
  kind, station, intent, phase, phaseLabel, feedback,
  contact, held, charge, proof,
  nodes: [{id, x, y, label, mark, challenge}],
  draft: {opening, target, min, max, state, caption},
  witness: {impressions, raised, echo, echoCaption},
  stylus: {point, target, down, path, pinDwell},
  scar: {from, to} | null,
  cue: {serial, kind, node, at},
  remaining
}

charge and pinDwell are normalized visible progress. impressions contains only already-lifted real pins, and stylus.path only bound contacts. Future route nodes, hidden source flags and deterministic profile are omitted. raised is a currently moving physical pin; echo is a current independent uncorroborated reply. They are separate visual and audio sources.

The finite cue serial increases when a pin rises, a reply sounds, a wrong branch scratches or a completed trace seats. Cue kinds are none, pin, echo, scratch and seal. A view read never changes the serial. Audio should initialize its consumed serial to the restored action's current serial when restoring or enabling late, so old events do not replay. Genuine pin spacing and early reply spacing exceed the maximum simulation step, avoiding competing event sources in the same update.

Call releaseCovenantTools(s) on pause, blur and restoration before the watch resumes. It disables held inputs while retaining the shutter, partial charge, earned proof or partial stylus position. Unfinished work cannot advance unattended. The player must explicitly regrip the same challenge or resting stylus to continue. Fully earned contact proof safely becomes the trace phase. This differs intentionally from voluntary early release, which abandons unfinished charge or ink.

validateCovenantAction(s, action) is an additive save-v1 validator. It checks exact fields, legal intent, deterministic profile, target-specific source snapshot, canonical geometry, timings, held/released consistency and phase ledger. A finished trace must contain the minimum plausible travel plus pin seating; a saved endpoint alone cannot qualify a seal. Arrival dwell is prorated to the part of the update after entering the pin radius, so every legitimate .05 and .25 second simulation update remains a valid saved state. Other existing action kinds are not changed.

Verification and acceptance

Focused tests cover deterministic paths, heat-dependent draft, independently witnessed answers, rapid clicking, short holds, one-frame coordinate submissions, valid timed tracing at .05/.25 second updates, required explicit release, wrong-branch costs, pause/regrip, save validation, source-intent isolation, selector cloning and finite cues. Campaign integration and actual pointer/keyboard playthroughs remain the host's responsibility. Automated proof of causal progression is not visual, audio or player approval.