The source’s c = ⟨κ, cid, op⟩: who asked, which request of theirs it is, and what it says.
Both identifying halves are load-bearing. from is what the port’s
LogInd::Ordered reports, and the page carries it for the same reason — the reply goes back
to κ. cid is what keeps two appends of the same value from collapsing into one: perform
skips a command it has already applied, and without cid a client appending 7 twice would see
one entry.
cid’s scope is this incarnation. It is a counter in volatile state, exactly as the Synod
ballot’s round is, and a restarted process re-mints values it has already used. A request
carrying a reused ⟨from, cid⟩ can be taken for one already applied and dropped, which is the
identity rule’s worked example: an identifier that crosses the wire outlives the handler that
minted it, so its generator is state with a scope, and this one survives nothing. Making it
durable is part of the fail-recovery change, not this one.