Core documentation

Core, Interop, Edit, Assurance, And Hostile Conformance Requirements

Specification metadata
title: Core, assurance, and hostile conformance requirements
status: draft
normative: true
summary: Stable requirement IDs for private ASP v1.0 Core Profile host, check-provider server, interop, edit/apply host, assurance honesty, and hostile-provider matrix reports.
updated: 2026-06-26

These requirement IDs define the private ASP v1.0 Core Profile report scopes. CORE-* covers the current host/Core smoke report. CORE-SERVER-* covers the black-box Core check-provider server suite. INTEROP-* covers private host/server interoperability evidence through the same ordinary Core provider contract. HOSTILE-* covers the private black-box hostile-provider matrix beyond Core. EDIT-HOST-* covers the private black-box host-mediated edit/apply profile. ASSURANCE-* covers honest assurance-mode and transaction-guarantee reporting for apply paths. No scope creates trust, authority, certification, registry, provider-approval, stable API, public-release, isolated-assurance, mediated-write, staged-snapshot, or workspace-transaction claims.

IDRequirement
CORE-HOST-STATUSBlack-box asp host serve host/status reports ready or explicitly degraded Core state, policy identity, required check coverage, provider state, and receipt coverage.
CORE-HOST-CAPABILITIESBlack-box asp host serve host/capabilities reports check as the required Core capability, keeps inspect and edit non-Core, and exposes required/enrolled/ran/degraded coverage.
CORE-HOST-EVALUATEBlack-box asp host serve host/evaluateChangeset returns host-owned allow, deny, and indeterminate Decision envelopes for Core gate cases.
CORE-CHECK-ASSESSMENTcheck/evaluate provider outputs use the canonical Assessment contract: status, diagnostics/evidence, coverage, validAsOf, provider metadata, timing, and cache metadata.
CORE-CHECK-CONFIGURATIONProviders validate optional request configuration, apply one effective configuration to both views, and report its stable configDigest for every assessment status. Hosts reject a mismatched digest.
CORE-PROVIDER-FORBIDDEN-FIELDSProvider Assessment payloads exclude host-owned decision, verdict, pass, disposition, authority, assurance, transaction, apply, and apply-receipt fields, including nested provider data.
CORE-STALE-VALID-AS-OFA black-box required provider Assessment with stale validAsOf cannot contribute to allow and remains visible as degraded coverage.
CORE-MISSING-REQUIRED-PROVIDERA black-box missing required Core check provider cannot produce allow and remains visible as degraded coverage.
CORE-MISSING-AUTHORITYBlack-box initialized, fresh, complete provider coverage without explicit gate authority cannot produce allow and remains visible as degraded coverage.
CORE-INSUFFICIENT-ASSURANCEBlack-box initialized, authorized, fresh provider coverage below required gate assurance cannot produce allow and reports achieved assurance.
CORE-PROVIDER-QUARANTINEDBlack-box quarantined required Core check provider health cannot produce allow and remains visible as degraded coverage.
CORE-PROVIDER-SKEWEDBlack-box skewed or incompatible required Core check provider enrollment cannot produce allow and remains visible as degraded coverage.
CORE-HOST-INITIALIZE-CONTRACT-REFUSALBlack-box required Core check provider initialize/version contract refusal cannot produce allow, reports skewed degraded coverage, and carries no initialized provider provenance.
CORE-PROVIDER-FAIL-OPENBlack-box fail-open required Core check provider health cannot produce allow and remains visible as degraded coverage.
CORE-MALFORMED-REQUIRED-PROVIDERBlack-box malformed, nested host-owned, or forged provider data cannot produce allow and remains visible as degraded coverage.
CORE-REQUIRED-COVERAGE-VISIBLEBlack-box missing, unavailable, incompatible, malformed, stale, incomplete, unsupported, cancelled, timed-out, crashed, quarantined, missing-authority, insufficient-assurance, direct-write-risk, and policy-self-authorization coverage stays machine-readable in coverage.required, coverage.ran, and coverage.degraded.
CORE-HOST-DECISION-AUTHORITATIVEProviders produce Assessments; black-box host behavior shows only the host produces the final allow, deny, or indeterminate gate Decision and receipt.
CORE-NO-LATTICE-FAST-PATHA direct or privileged Lattice gate, freshness, authority, or apply path is rejected as degraded behavior rather than accepted as Core evidence.
CORE-SERVER-INITIALIZEA Core check provider initialize result reports server identity, fingerprint, provenance, check capability, and read-only permission request.
CORE-SERVER-UNSUPPORTED-PROTOCOLA Core check provider rejects unsupported initialize.protocolVersion with typed contract failure before initialized, host callbacks, or satisfiable Core coverage.
CORE-SERVER-PREINITIALIZEDcheck/evaluate before initialized fails with a typed provider-not-initialized JSON-RPC error and cannot satisfy Core coverage.
CORE-SERVER-INITIALIZED-GRANTThe provider records the narrowed read-only initialized grant and receives no write or network authority.
CORE-SERVER-CALLBACK-CONTENTThe provider obtains baseline and changeset content through workspace/listTree and workspace/readBlob callbacks.
CORE-SERVER-GRANT-SCOPEFake-host callbacks filter tree entries and blob bytes to the initialized read grant and reject out-of-grant blob reads.
CORE-SERVER-VALID-RESULTSComplete clean, complete diagnostic, incomplete, unsupported, and cancelled results validate as provider Assessments.
CORE-SERVER-TYPED-ERRORProvider inability to evaluate is reported on the JSON-RPC error channel with typed failClass data.
CORE-SERVER-REJECTED-MALFORMED-HOST-FIELDSMalformed provider outputs and top-level or nested host-owned fields are rejected as non-passing server evidence.
CORE-SERVER-REJECTED-FRESHNESSStale validAsOf.baseline, changeset digest, or blob freshness is rejected as non-passing server evidence.
CORE-SERVER-TIMEOUTA hung provider is reported as failed or missing required server evidence, never as pass.
CORE-SERVER-BEHAVIOR-ONLYProvider outputs remain Assessments only and are never accepted as host Decisions, authority grants, assurance, receipts, or verdicts.
INTEROP-REF-HOST-FAKEThe Open Engine reference host interoperates with the fake Core check provider over JSON-RPC stdio using the ordinary provider contract.
INTEROP-REF-HOST-OPCOREThe Open Engine reference host interoperates with Opcore as an ordinary enrolled ASP provider through manager-owned manifest state.
INTEROP-INDEPENDENT-HOST-FAKEA minimal independent host harness interoperates with the fake Core check provider through initialize, initialized grant, host callbacks, and check Assessment validation.
INTEROP-INDEPENDENT-HOST-OPCOREA minimal independent host harness interoperates with the Opcore provider entrypoint through the same provider contract.
INTEROP-UNSUPPORTED-COVERAGE-VISIBLEUnsupported or missing capability coverage remains explicit Assessment/report detail and cannot silently count as passing support.
INTEROP-NO-OPCORE-FAST-PATHInterop tests, fixtures, and runners contain no privileged Opcore, old-tool, or temporary guardrail fast-path calls.
INTEROP-PRIVATE-CLAIMSInterop reports remain private behavior evidence and make no trust, authority, certification, registry, provider-approval, stable API, or public-release claim.
HOSTILE-MALFORMED-INITIALIZEBlack-box host evaluation rejects malformed provider initialize results and records degraded required coverage instead of allowing silently.
HOSTILE-MALFORMED-ASSESSMENTBlack-box host evaluation rejects malformed provider Assessment payloads and records degraded required coverage instead of allowing silently.
HOSTILE-FORGED-HOST-FIELDSProvider-minted host-owned decision, verdict, pass, authority, assurance, transaction, apply, or receipt fields are rejected or degraded.
HOSTILE-STALE-ASSESSMENTStale required provider validAsOf data cannot produce allow and remains visible as degraded coverage.
HOSTILE-MISSING-REQUIRED-PROVIDERA missing required provider cannot produce allow and keeps required, ran, degraded, receipt failure, and provenance gaps visible.
HOSTILE-OPTIONAL-DEGRADED-PROVIDEROptional provider failure remains visible in decision, status, and capability coverage while clean required coverage may still allow the gate.
HOSTILE-UNSUPPORTED-REQUIRED-CAPABILITYA required provider that does not advertise its enrolled required capability is incompatible health with unsupported degraded coverage.
HOSTILE-INCOMPLETE-REQUIRED-COVERAGEIncomplete required provider coverage cannot produce allow and remains machine-readable in degraded coverage and receipt failures.
HOSTILE-PROVIDER-ERRORProvider error during required evaluation cannot produce allow and remains machine-readable in degraded coverage and receipt failures.
HOSTILE-CANCELLED-PROVIDER-REQUESTCancelled provider evaluation cannot produce allow and remains machine-readable in degraded coverage and receipt failures.
HOSTILE-SLOW-PROVIDER-TIMEOUTSlow required provider timeout cannot produce allow and remains machine-readable in degraded coverage and receipt failures.
HOSTILE-PROVIDER-CRASHProvider crash during initialize or active request cannot produce allow and remains machine-readable in degraded coverage and receipt failures.
HOSTILE-QUARANTINED-PROVIDERQuarantined required provider health cannot produce allow and remains visible as degraded coverage.
HOSTILE-MISSING-AUTHORITYFresh complete provider coverage without explicit required authority cannot produce allow and records host-owned authority evidence.
HOSTILE-INSUFFICIENT-ASSURANCEAuthorized provider coverage below required gate assurance cannot produce allow and reports achieved assurance honestly.
HOSTILE-POLICY-SELF-AUTHORIZATIONCandidate policy/config changes cannot authorize, select, or weaken the gate evaluating the same changeset.
HOSTILE-DIRECT-WRITE-RISKDeclared direct-write risk or untrusted edit launch cannot be treated as mediated host authority or a passing gate.
HOSTILE-COMMAND-LIKE-EDIT-OUTPUTCommand-like edit output is rejected before apply and leaves the workspace unchanged.
HOSTILE-NO-OPCORE-FAST-PATHHostile tests, fixtures, and runners contain no privileged reference-provider, old-tool, or temporary guardrail fast-path calls.
EDIT-HOST-REQUEST-PLAN-NO-WRITEhost/requestEditPlan returns provider EditPlan data and a host receipt without mutating the workspace or accepting provider-owned decisions, commands, or apply receipts.
EDIT-HOST-POSITIVE-APPLYhost/applyProposal validates and applies a canonical provider EditPlan through the host, reports actual assurance mode and transaction guarantee, and writes the expected content.
EDIT-HOST-STALE-PLANStale provider EditPlan baseline or validAsOf data is rejected before apply and leaves the workspace unchanged.
EDIT-HOST-CAS-CONFLICTApply validates expected before digests and refuses a changed file without overwriting current content.
EDIT-HOST-PATH-POLICYApply validates touched-resource preconditions, expected absence for creates, and requested path scope before writing.
EDIT-HOST-UNKNOWN-PROPOSALApply refuses unknown or uncached proposal identity before validation or mutation.
EDIT-HOST-DENIED-VALIDATIONHost deny validation over the hypothetical after-state prevents apply and reports blocking diagnostic coverage.
EDIT-HOST-INDETERMINATE-VALIDATIONIndeterminate host validation over the hypothetical after-state prevents apply and reports incomplete coverage.
EDIT-HOST-COMMAND-LIKE-OUTPUTCommand-like provider edit output is rejected as provider data, not executed or converted into host apply behavior.
EDIT-HOST-DIRECT-WRITE-RISKDirect-write provider output and untrusted writable edit launch are rejected before apply.
EDIT-HOST-MALFORMED-OUTPUTMalformed provider edit output is rejected before apply and cannot satisfy edit coverage.
EDIT-HOST-HOST-FIELD-SMUGGLINGProvider-owned decisions, apply receipts, authority, assurance, transaction, or receipt fields in edit output are rejected.
EDIT-HOST-MISSING-AUTHORITYMissing explicit edit authority prevents required apply paths and reports host-owned authority evidence.
EDIT-HOST-INSUFFICIENT-ASSURANCEAdvisory edit isolation cannot satisfy required apply assurance and reports achieved assurance honestly.
EDIT-HOST-CONCURRENT-APPLYConcurrent apply attempts are serialized or refused so only one write can succeed.
EDIT-HOST-NO-OPCORE-FAST-PATHEdit/apply tests, fixtures, and runners contain no privileged reference-provider, old-tool, or temporary guardrail fast-path calls.
ASSURANCE-ADVISORY-REPORTINGAdvisory edit authority reports advisory/none, refuses apply requiring stronger assurance, and leaves the workspace unchanged.
ASSURANCE-GATED-BOUNDARYGated edit apply reports gated/none and identifies the gate validation and interactive apply boundary being controlled.
ASSURANCE-MEDIATED-WRITE-DOWNGRADERequested mediated-write evidence without enforced host-mediated writes is refused or downgraded to weaker assurance.
ASSURANCE-ISOLATED-DOWNGRADERequested isolated evidence without enforced provider write isolation is refused or downgraded to weaker assurance.
ASSURANCE-DIRECT-WRITE-REFUSALDirect-write provider output and untrusted editable launch cannot pass as mediated-write, isolated, or successful apply evidence.
ASSURANCE-TRANSACTION-GUARANTEE-BOUNDEvery observed transaction guarantee is schema-accepted and no stronger than the current none guarantee.
ASSURANCE-FAILED-APPLY-NO-SUCCESSFUL-RECEIPTProvider crash, command-like edit output, denied validation, and indeterminate validation cannot produce misleading successful apply receipts.