pub fn check_staleness_at_use(journal: &Journal) -> CheckResultExpand description
staleness-at-use — the reuse rule (docs/context-reuse.md §4, V2) held
at the point of use: a frame whose exact identity was last verified
stale or gone must never be rendered again.
The identity is the full (provider, frame, digest) triple, so an honest
refresh is invisible here: a re-queried frame carries the source’s new
digest and therefore a different identity. stale means the digest
changed, so a same-identity render afterwards is either the host reusing
the body it was told to drop or the provider contradicting itself — a
defect either way. A later valid verdict for the identity clears it
(verify-after-doubt is exactly how revalidation is supposed to work), and
unknown does not convict: the host may have re-queried and been
re-served the identical bytes, which the journal cannot distinguish.