Core documentation

Core, Interop, Edit, Assurance, And Hostile Conformance Traceability

Specification metadata
title: Core, assurance, and hostile conformance traceability
status: draft
normative: false
summary: Requirement-to-source-to-test map for private ASP v1.0 Core Profile host, check-provider server, interop, edit/apply host, assurance honesty, and hostile-provider matrix reports.
updated: 2026-06-26

This map binds each Core requirement to current source text, fixtures, and test names. It is private behavior traceability only; public claims, repo dogfood, Lattice parity, and old-tool retirement are outside this scaffold.

RequirementSourceFixturesTest
CORE-HOST-STATUSspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/outer-host.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.json; examples/core/status.ready.jsonCORE-HOST-STATUS exposes ready Core gate status, provider state, policy, and coverage
CORE-HOST-CAPABILITIESspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/outer-host.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.json; examples/core/capabilities.check-only.jsonCORE-HOST-CAPABILITIES exposes check-only Core capability coverage
CORE-HOST-EVALUATEspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.json; examples/core/evaluate.allow.json; examples/core/evaluate.deny.json; examples/core/evaluate.indeterminate.missing-provider.json; examples/core/evaluate.indeterminate.stale-assessment.json; examples/core/evaluate.indeterminate.degraded-required-coverage.jsonCORE-HOST-EVALUATE covers allow, deny, and indeterminate host decision envelopes
CORE-CHECK-ASSESSMENTspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/check-assessment.schema.json; schemas/check-evaluate.schema.jsontests/conformance/fixtures/core/check-assessment.valid.complete.jsonCORE-CHECK-ASSESSMENT accepts the provider Assessment shape used by check/evaluate
CORE-CHECK-CONFIGURATIONspec/05-role-judge.md#request-configuration; schemas/check-evaluate.schema.jsontests/conformance/fixtures/core/check-evaluate.configuration.valid.json; tests/conformance/fixtures/core/check-evaluate.configuration.invalid.null.jsonOpcore provider_configuration_rejects_invalid_values_and_canonicalizes_defaults; fast_configuration_changes_findings_and_binds_every_assessment_status; host_rejects_configuration_digest_mismatch
CORE-PROVIDER-FORBIDDEN-FIELDSspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/check-assessment.schema.jsontests/conformance/fixtures/core/check-assessment.invalid.host-owned-top-level.json; tests/conformance/fixtures/core/check-assessment.invalid.host-owned-nested.jsonCORE-PROVIDER-FORBIDDEN-FIELDS rejects host-owned fields at top level and nested provider data
CORE-STALE-VALID-AS-OFspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/check-assessment.schema.json; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/check-assessment.valid.complete.jsonCORE-STALE-VALID-AS-OF makes a required stale Assessment non-allow with degraded coverage
CORE-MISSING-REQUIRED-PROVIDERspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/core/helpers/core-host-harness.ts; tests/conformance/core/helpers/core-smoke-helpers.tsCORE-MISSING-REQUIRED-PROVIDER makes an absent required provider non-allow with visible coverage
CORE-MISSING-AUTHORITYspec/11-core-profile.md:87-100; spec/08-conformance.md:163-166; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.jsonCORE-MISSING-AUTHORITY rejects fresh complete provider coverage without explicit authority
CORE-INSUFFICIENT-ASSURANCEspec/11-core-profile.md:87-100; spec/08-conformance.md:163-166; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.jsonCORE-INSUFFICIENT-ASSURANCE rejects authorized fresh coverage below required assurance
CORE-PROVIDER-QUARANTINEDspec/11-core-profile.md:87-103; spec/08-conformance.md:158-175; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.jsonCORE-PROVIDER-QUARANTINED keeps quarantined required provider non-allow and visibly degraded
CORE-PROVIDER-SKEWEDspec/11-core-profile.md:87-103; spec/08-conformance.md:158-175; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.jsonCORE-PROVIDER-SKEWED keeps skewed required provider non-allow and visibly degraded
CORE-HOST-INITIALIZE-CONTRACT-REFUSALspec/11-core-profile.md:87-103; spec/08-conformance.md:158-175; spec/08-conformance.md:209; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.json; packages/asp/src/core-host.ts; packages/asp/src/core-host-support.ts; packages/asp/src/fake-check-provider.tsCORE-HOST-INITIALIZE-CONTRACT-REFUSAL keeps initialize version refusal non-allow and visibly degraded
CORE-PROVIDER-FAIL-OPENspec/11-core-profile.md:87-103; spec/08-conformance.md:158-175; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.jsonCORE-PROVIDER-FAIL-OPEN keeps fail-open required provider non-allow and visibly degraded
CORE-MALFORMED-REQUIRED-PROVIDERspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/check-assessment.schema.json; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/check-assessment.invalid.host-owned-nested.jsonCORE-MALFORMED-REQUIRED-PROVIDER makes malformed required-provider data non-allow
CORE-REQUIRED-COVERAGE-VISIBLEspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; examples/core/evaluate.indeterminate.degraded-required-coverage.jsonCORE-REQUIRED-COVERAGE-VISIBLE keeps every degraded required coverage reason machine-readable
CORE-HOST-DECISION-AUTHORITATIVEspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/check-assessment.schema.json; schemas/verdict.schema.jsontests/conformance/core/core-host-black-box.test.ts; tests/conformance/fixtures/core/core-host-adoption-receipt.valid.json; tests/conformance/fixtures/core/check-assessment.valid.complete.json; tests/conformance/fixtures/core/check-assessment.invalid.host-owned-top-level.jsonCORE-HOST-DECISION-AUTHORITATIVE treats provider Assessments as inputs, never final gate output
CORE-NO-LATTICE-FAST-PATHspec/11-core-profile.md:103; spec/08-conformance.md:106; schemas/verdict.schema.jsonexamples/outer/evaluate.lattice-fast-path.response.jsonCORE-NO-LATTICE-FAST-PATH rejects direct privileged Lattice gate paths as degraded
CORE-SERVER-INITIALIZEspec/11-core-profile.md:28; spec/08-conformance.md:54; schemas/initialize.schema.jsonpackages/asp/bin/fake-check-provider; packages/asp/src/fake-check-provider.tsCORE-SERVER-INITIALIZE returns check identity, provenance, capability, and read-only permission request
CORE-SERVER-UNSUPPORTED-PROTOCOLspec/08-conformance.md:209; schemas/error.schema.jsonpackages/asp/src/fake-check-provider.ts; tests/conformance/server/core-check-provider.test.ts; tests/conformance/server/helpers/core-server-harness.ts; schemas/error.schema.jsonCORE-SERVER-UNSUPPORTED-PROTOCOL rejects unsupported initialize before initialized coverage
CORE-SERVER-PREINITIALIZEDspec/11-core-profile.md:55; spec/08-conformance.md:59; schemas/error.schema.jsontests/conformance/server/core-check-provider.test.tsCORE-SERVER-PREINITIALIZED rejects check/evaluate before initialized with typed provider-not-initialized error
CORE-SERVER-INITIALIZED-GRANTspec/11-core-profile.md:55; spec/08-conformance.md:59; schemas/initialize.schema.jsontests/conformance/server/core-check-provider.test.tsCORE-SERVER-INITIALIZED-GRANT records narrowed read-only initialized grant without write or network authority
CORE-SERVER-CALLBACK-CONTENTspec/11-core-profile.md:56; spec/08-conformance.md:61; schemas/host-callbacks.schema.jsontests/conformance/server/helpers/core-server-harness.ts; tests/conformance/fixtures/server/core/workspace/src/core.ts; tests/conformance/fixtures/server/core/workspace/README.mdCORE-SERVER-CALLBACK-CONTENT reads baseline and changeset blobs only through host callbacks
CORE-SERVER-GRANT-SCOPEspec/03-data-model.md:82; spec/11-core-profile.md:116; schemas/host-callbacks.schema.jsonpackages/asp/src/workspace-store.ts; tests/conformance/server/helpers/core-server-harness.ts; tests/conformance/fixtures/server/core/workspace/secrets/out-of-grant.txtCORE-SERVER-GRANT-SCOPE filters callback tree and blob access to the initialized read grant
CORE-SERVER-VALID-RESULTSspec/11-core-profile.md:57; spec/08-conformance.md:74; schemas/check-assessment.schema.json; schemas/check-evaluate.schema.jsontests/conformance/server/core-check-provider.test.tsCORE-SERVER-VALID-RESULTS returns valid complete, diagnostic, incomplete, unsupported, and cancelled Assessments
CORE-SERVER-TYPED-ERRORspec/08-conformance.md:79; schemas/error.schema.jsonpackages/asp/src/fake-check-provider.ts; tests/conformance/server/core-check-provider.test.tsCORE-SERVER-TYPED-ERROR reports inability to evaluate on the JSON-RPC error channel with failClass
CORE-SERVER-REJECTED-MALFORMED-HOST-FIELDSspec/11-core-profile.md:69; spec/08-conformance.md:81; schemas/check-assessment.schema.jsonpackages/asp/src/assessment-validator.ts; packages/asp/src/fake-check-provider.tsCORE-SERVER-REJECTED-MALFORMED-HOST-FIELDS rejects malformed and host-owned provider result fields
CORE-SERVER-REJECTED-FRESHNESSspec/11-core-profile.md:66; spec/08-conformance.md:122; schemas/check-assessment.schema.jsonpackages/asp/src/assessment-validator.ts; tests/conformance/server/core-check-provider.test.tsCORE-SERVER-REJECTED-FRESHNESS rejects stale baseline or changeset freshness
CORE-SERVER-TIMEOUTspec/11-core-profile.md:86; spec/08-conformance.md:140; packages/asp/src/json-rpc-peer.tspackages/asp/src/fake-check-provider.ts; tests/conformance/server/core-check-provider.test.tsCORE-SERVER-TIMEOUT reports a hung provider as failed server evidence, not pass
CORE-SERVER-BEHAVIOR-ONLYspec/11-core-profile.md:72; spec/08-conformance.md:17; schemas/check-assessment.schema.jsontests/conformance/server/core-check-provider.test.tsCORE-SERVER-BEHAVIOR-ONLY accepts provider outputs only as Assessments, never host Decisions or authority grants
INTEROP-REF-HOST-FAKEspec/08-conformance.md:106; spec/09-outer-seam.md:35; spec/11-core-profile.md:103tests/conformance/interop/interop-matrix.test.ts; tests/conformance/interop/helpers/interop-harness.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-REF-HOST-FAKE reference host and fake provider use the Core check contract
INTEROP-REF-HOST-OPCOREspec/08-conformance.md:106; spec/10-installation-and-discovery.md:88; spec/11-core-profile.md:103tests/conformance/interop/interop-matrix.test.ts; tests/conformance/interop/helpers/interop-harness.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-REF-HOST-OPCORE reference host and ordinary provider enrollment use the Core check contract
INTEROP-INDEPENDENT-HOST-FAKEspec/08-conformance.md:54; spec/09-outer-seam.md:35; spec/11-core-profile.md:55tests/conformance/interop/interop-matrix.test.ts; tests/conformance/interop/helpers/interop-harness.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-INDEPENDENT-HOST-FAKE independent host and fake provider use the Core check contract
INTEROP-INDEPENDENT-HOST-OPCOREspec/08-conformance.md:54; spec/09-outer-seam.md:35; spec/10-installation-and-discovery.md:88tests/conformance/interop/interop-matrix.test.ts; tests/conformance/interop/helpers/interop-harness.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-INDEPENDENT-HOST-OPCORE independent host and ordinary provider entrypoint use the Core check contract
INTEROP-UNSUPPORTED-COVERAGE-VISIBLEspec/08-conformance.md:74; spec/08-conformance.md:158; spec/11-core-profile.md:57tests/conformance/interop/interop-matrix.test.ts; packages/asp/src/fake-check-provider.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-UNSUPPORTED-COVERAGE-VISIBLE unsupported coverage remains explicit
INTEROP-NO-OPCORE-FAST-PATHspec/08-conformance.md:175; spec/09-outer-seam.md:35; docs/conformance/requirements.mdtests/conformance/interop/interop-matrix.test.ts; tests/conformance/interop/helpers/interop-harness.ts; scripts/conformance/run-interop-suite.ts; scripts/conformance/interop-report-catalog.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-NO-OPCORE-FAST-PATH rejects privileged fast-path tokens in interop artifacts
INTEROP-PRIVATE-CLAIMSspec/08-conformance.md:17; docs/conformance/requirements.mdtests/conformance/interop/interop-report.test.ts; scripts/conformance/interop-report-catalog.ts; scripts/conformance/run-interop-suite.ts; tests/conformance/fixtures/interop/interop-conformance-report.valid.jsonINTEROP-PRIVATE-CLAIMS keeps interop evidence private and non-authoritative
HOSTILE-MALFORMED-INITIALIZEspec/08-conformance.md:158; spec/11-core-profile.md:86; schemas/initialize.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; tests/conformance/hostile/helpers/hostile-host-harness.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/provider-runtime.tsHOSTILE-MALFORMED-INITIALIZE rejects malformed provider initialize without silent allow
HOSTILE-MALFORMED-ASSESSMENTspec/08-conformance.md:81; spec/11-core-profile.md:69; schemas/check-assessment.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/assessment-validator.tsHOSTILE-MALFORMED-ASSESSMENT rejects malformed provider Assessment without silent allow
HOSTILE-FORGED-HOST-FIELDSspec/08-conformance.md:81; spec/09-outer-seam.md:92; schemas/check-assessment.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/provider-host-owned-fields.ts; packages/asp/src/assessment-validator.tsHOSTILE-FORGED-HOST-FIELDS rejects provider-minted decision authority assurance and receipt fields
HOSTILE-STALE-ASSESSMENTspec/08-conformance.md:122; spec/11-core-profile.md:66; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/assessment-validator.tsHOSTILE-STALE-ASSESSMENT rejects stale validAsOf without silent allow
HOSTILE-MISSING-REQUIRED-PROVIDERspec/08-conformance.md:158; spec/11-core-profile.md:87; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-support.tsHOSTILE-MISSING-REQUIRED-PROVIDER keeps missing required provider non-allow and visible
HOSTILE-OPTIONAL-DEGRADED-PROVIDERspec/08-conformance.md:158; spec/09-outer-seam.md:120; schemas/outer-host.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; tests/conformance/hostile/helpers/hostile-host-harness.tsHOSTILE-OPTIONAL-DEGRADED-PROVIDER keeps optional degradation visible while required coverage can allow
HOSTILE-UNSUPPORTED-REQUIRED-CAPABILITYspec/08-conformance.md:158; spec/09-outer-seam.md:119; schemas/outer-host.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/provider-runtime.ts; packages/asp/src/fake-check-provider.tsHOSTILE-UNSUPPORTED-REQUIRED-CAPABILITY treats missing advertised required capability as unsupported
HOSTILE-INCOMPLETE-REQUIRED-COVERAGEspec/08-conformance.md:158; spec/11-core-profile.md:103; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-evaluation.tsHOSTILE-INCOMPLETE-REQUIRED-COVERAGE rejects incomplete required coverage
HOSTILE-PROVIDER-ERRORspec/08-conformance.md:140; spec/11-core-profile.md:86; schemas/error.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/provider-supervision.tsHOSTILE-PROVIDER-ERROR reports provider error as non-allow degraded coverage
HOSTILE-CANCELLED-PROVIDER-REQUESTspec/02-transport-and-lifecycle.md:68; spec/08-conformance.md:140; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-evaluation.tsHOSTILE-CANCELLED-PROVIDER-REQUEST reports cancelled provider request as non-allow degraded coverage
HOSTILE-SLOW-PROVIDER-TIMEOUTspec/08-conformance.md:140; spec/11-core-profile.md:86; schemas/error.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/json-rpc-peer.ts; packages/asp/src/provider-supervision.tsHOSTILE-SLOW-PROVIDER-TIMEOUT reports slow provider timeout as non-allow degraded coverage
HOSTILE-PROVIDER-CRASHspec/08-conformance.md:140; spec/11-core-profile.md:86; schemas/error.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/provider-runtime.tsHOSTILE-PROVIDER-CRASH reports provider crash during initialize and active request
HOSTILE-QUARANTINED-PROVIDERspec/08-conformance.md:158; spec/11-core-profile.md:87; schemas/outer-host.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/provider-supervision.tsHOSTILE-QUARANTINED-PROVIDER keeps quarantined required provider non-allow and visible
HOSTILE-MISSING-AUTHORITYspec/07-host-obligations.md:53; spec/08-conformance.md:163; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-support.tsHOSTILE-MISSING-AUTHORITY rejects fresh complete coverage without required authority
HOSTILE-INSUFFICIENT-ASSURANCEspec/07-host-obligations.md:70; spec/08-conformance.md:166; schemas/verdict.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-support.tsHOSTILE-INSUFFICIENT-ASSURANCE rejects authorized coverage below required assurance
HOSTILE-POLICY-SELF-AUTHORIZATIONspec/10-installation-and-discovery.md:122; spec/08-conformance.md:175; schemas/asp-config.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-support.tsHOSTILE-POLICY-SELF-AUTHORIZATION rejects candidate policy self-authorization attempts
HOSTILE-DIRECT-WRITE-RISKspec/07-host-obligations.md:93; spec/09-outer-seam.md:178; schemas/edit-plan.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-edit-risk.tsHOSTILE-DIRECT-WRITE-RISK rejects direct-write provider risk and untrusted edit launch
HOSTILE-COMMAND-LIKE-EDIT-OUTPUTspec/06-role-act.md:46; spec/09-outer-seam.md:165; schemas/edit-plan.schema.jsontests/conformance/hostile/hostile-provider-matrix.test.ts; packages/asp/src/core-host-edit.tsHOSTILE-COMMAND-LIKE-EDIT-OUTPUT rejects command-like edit output before apply
HOSTILE-NO-OPCORE-FAST-PATHspec/08-conformance.md:175; spec/09-outer-seam.md:35; docs/conformance/requirements.mdtests/conformance/hostile/hostile-provider-matrix.test.ts; scripts/conformance/run-hostile-suite.ts; tests/conformance/fixtures/hostile/hostile-provider-conformance-report.valid.jsonHOSTILE-NO-OPCORE-FAST-PATH rejects privileged fast-path tokens in hostile suite artifacts
EDIT-HOST-REQUEST-PLAN-NO-WRITEspec/06-role-act.md:46; spec/09-outer-seam.md:165; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-REQUEST-PLAN-NO-WRITE returns provider EditPlan without mutating workspace
EDIT-HOST-POSITIVE-APPLYspec/07-host-obligations.md:93; spec/09-outer-seam.md:178; schemas/outer-host.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/core-host-edit.ts; packages/asp/src/workspace-edit-apply.tsEDIT-HOST-POSITIVE-APPLY validates and applies canonical EditPlan
EDIT-HOST-STALE-PLANspec/08-conformance.md:122; spec/09-outer-seam.md:165; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/edit-plan-validator.tsEDIT-HOST-STALE-PLAN rejects stale provider EditPlan before apply
EDIT-HOST-CAS-CONFLICTspec/03-data-model.md:82; spec/09-outer-seam.md:178; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/workspace-edit-apply.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-CAS-CONFLICT refuses apply after expected before digest changes
EDIT-HOST-PATH-POLICYspec/07-host-obligations.md:53; spec/09-outer-seam.md:178; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-PATH-POLICY validates create absence and requested scope
EDIT-HOST-UNKNOWN-PROPOSALspec/09-outer-seam.md:165; schemas/outer-host.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-UNKNOWN-PROPOSAL refuses unknown proposal identity
EDIT-HOST-DENIED-VALIDATIONspec/07-host-obligations.md:70; spec/08-conformance.md:166; schemas/verdict.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-DENIED-VALIDATION prevents apply
EDIT-HOST-INDETERMINATE-VALIDATIONspec/07-host-obligations.md:70; spec/08-conformance.md:166; schemas/verdict.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-INDETERMINATE-VALIDATION prevents apply
EDIT-HOST-COMMAND-LIKE-OUTPUTspec/06-role-act.md:46; spec/09-outer-seam.md:165; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/edit-plan-validator.tsEDIT-HOST-COMMAND-LIKE-OUTPUT rejects command-like provider output before apply
EDIT-HOST-DIRECT-WRITE-RISKspec/07-host-obligations.md:93; spec/09-outer-seam.md:178; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/core-host-edit-risk.ts; packages/asp/src/edit-plan-validator.tsEDIT-HOST-DIRECT-WRITE-RISK rejects direct-write output and untrusted edit launch
EDIT-HOST-MALFORMED-OUTPUTspec/08-conformance.md:81; spec/09-outer-seam.md:165; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/edit-plan-validator.tsEDIT-HOST-MALFORMED-OUTPUT rejects malformed provider proposal
EDIT-HOST-HOST-FIELD-SMUGGLINGspec/08-conformance.md:81; spec/09-outer-seam.md:92; schemas/edit-plan.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/provider-host-owned-fields.ts; packages/asp/src/edit-plan-validator.tsEDIT-HOST-HOST-FIELD-SMUGGLING rejects provider-owned decisions apply receipts authority and assurance fields
EDIT-HOST-MISSING-AUTHORITYspec/07-host-obligations.md:53; spec/08-conformance.md:163; schemas/outer-host.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-MISSING-AUTHORITY refuses apply without edit authority
EDIT-HOST-INSUFFICIENT-ASSURANCEspec/07-host-obligations.md:70; spec/08-conformance.md:166; schemas/outer-host.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-INSUFFICIENT-ASSURANCE refuses advisory isolation apply
EDIT-HOST-CONCURRENT-APPLYspec/07-host-obligations.md:93; spec/09-outer-seam.md:178; schemas/outer-host.schema.jsontests/conformance/edit/edit-apply-host-profile.test.ts; packages/asp/src/core-host-edit.tsEDIT-HOST-CONCURRENT-APPLY serializes concurrent apply attempts
EDIT-HOST-NO-OPCORE-FAST-PATHspec/08-conformance.md:175; spec/09-outer-seam.md:35; docs/conformance/requirements.mdtests/conformance/edit/edit-apply-host-profile.test.ts; scripts/conformance/run-edit-host-suite.ts; tests/conformance/fixtures/edit/edit-host-conformance-report.valid.jsonEDIT-HOST-NO-OPCORE-FAST-PATH rejects privileged fast-path tokens in edit artifacts
ASSURANCE-ADVISORY-REPORTINGspec/07-host-obligations.md:70; spec/08-conformance.md:166; schemas/assurance.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; tests/conformance/edit/helpers/edit-host-harness.ts; packages/asp/src/core-host-edit.tsASSURANCE-ADVISORY-REPORTING reports advisory refusal without blocking authority
ASSURANCE-GATED-BOUNDARYspec/07-host-obligations.md:53; spec/09-outer-seam.md:178; schemas/outer-host.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; packages/asp/src/core-host-edit.ts; packages/asp/src/core-host-evaluation.tsASSURANCE-GATED-BOUNDARY reports gated apply and the controlled gate and interactive boundaries
ASSURANCE-MEDIATED-WRITE-DOWNGRADEspec/07-host-obligations.md:93; spec/08-conformance.md:166; schemas/assurance.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; tests/conformance/shared/provider-fixtures.ts; packages/asp/src/core-host-edit.tsASSURANCE-MEDIATED-WRITE-DOWNGRADE refuses mediated-write claims without host-mediated evidence
ASSURANCE-ISOLATED-DOWNGRADEspec/07-host-obligations.md:93; spec/08-conformance.md:166; schemas/assurance.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; tests/conformance/shared/provider-fixtures.ts; packages/asp/src/core-host-edit.tsASSURANCE-ISOLATED-DOWNGRADE refuses isolated claims without enforced write isolation
ASSURANCE-DIRECT-WRITE-REFUSALspec/07-host-obligations.md:93; spec/09-outer-seam.md:178; schemas/edit-plan.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; packages/asp/src/core-host-edit-risk.ts; packages/asp/src/edit-plan-validator.tsASSURANCE-DIRECT-WRITE-REFUSAL rejects direct-write provider output and untrusted edit launch
ASSURANCE-TRANSACTION-GUARANTEE-BOUNDspec/07-host-obligations.md:93; schemas/assurance.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; packages/asp/src/core-host-support.ts; packages/asp/src/host-receipts.tsASSURANCE-TRANSACTION-GUARANTEE-BOUND only observes accepted none transaction guarantees
ASSURANCE-FAILED-APPLY-NO-SUCCESSFUL-RECEIPTspec/08-conformance.md:158; spec/09-outer-seam.md:178; schemas/outer-host.schema.jsontests/conformance/assurance/assurance-mode-honesty.test.ts; packages/asp/src/fake-check-provider.ts; packages/asp/src/core-host-edit.tsASSURANCE-FAILED-APPLY-NO-SUCCESSFUL-RECEIPT prevents false successful apply receipts