lineageOf

The live entitlement path from the root down to group's inbound edge, in root→group order (empty when group is the root), or null if the lineage is quarantined (a divergent record, two live inbound edges, no live path to the root, or a cycle — see holdings/validate). A caller that must charge service against a captured path (design §4.4) reads this at reservation time, while the topology is valid, and later hands the captured list to spendCaptured.