fix(outbound): a later decision may not cancel a delivery the peer already has (17d) master
17b holds a delivery whose settlement failed AFTER a confirmed POST: pending, re-claimable, resuming at the settlement rather than the wire. 17d then added a consent-shaped reason to cancel an actor's pending work — and a held delivery is pending by construction, so the opt-out cancelled it. Cancelled is terminal, so the worker never returned and the ledger row was stranded. Both harms are permanent and cross sub-run boundaries. 17b's reseed subtracts only 'delivered' rows, so a stranded row over-counts the served score forever. 17d's own purge enumerates live votes from that same column, so the Undo the erasure owes the peer is never enqueued — the destructive tier silently failing at the one thing it exists to do. The guard was written for the resume path and held there; this arrived through the store instead. It is now one constant fragment concatenated into every cancellation — the opt-out's, the ban's, the community's, and CancelClaimed, which cannot strand a row today only because the worker returns before the consent recheck can reach it. That safety lives in a different file from the statement, so carrying the term there closes the class rather than the instance. `ledger_unsettled` now has one spelling, owned by the store: two would let a cancellation and a resume disagree about which rows are held, silently, and fatally in the direction where the cancel wins. The rule, stated at the predicate: a decision that arrives later may not rewrite the record of something that has already happened. 17c-3 applied it to terminal rows; the held state is that rule one state over, and the only pending state where it applies. A held delivery's POST already succeeded — leaving it to settle finishes bookkeeping for something the peer HAS, while cancelling it abandons bookkeeping for something the peer has anyway. Also lands 17d's remaining coverage: the four decision-19 confirm cases (confirmed-deleted runs; confirmed-live does nothing destructive and still advances the seq so a stale deletion cannot wedge the DID; confirm-failure is genuinely retryable — the same frame redelivered after the confirmer heals terminates and advances; and a confirmed deletion with no destructive seam records the preference without degrading to a pause), plus the two controls — an opt-out from a DID with no actor is a no-op success, because minting one to disable it would create the identity the record asks us not to create. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>