I agree. You would need an oracle in order to put physical things on the blockchain, and that is subject to incorrect data or tampering. It's non-trivial, but not technically impossible.
Yes, but if you have a mechanism (either technical or institutional) that you trust to attach real-world goods to your blockchain in a sufficiently correct and tamper-resistant manner, why not just let that mechanism manage your ledger directly and skip the blockchain entirely?
Those seem like two separate problems to me. The oracle reliably reports to the blockchain while the blockchain ensures that the historical record is tamper-proof.
But why can you trust the oracle to report correctly but not to maintain the record?