Attested Execution Framework
The coverage declaration
What the reference verifier's suite covers and what it does not, entry by entry. This page renders fixture-coverage.json and adds nothing to it; the JSON is the declaration, per AEF 1201.
aef-reference-verifier 0.4.0against 1200/0.2, generated 14 August 2026
Suite version
Under AEF 1201 C10 the suite version is the digest of the coverage declaration as served, which the file cannot contain and this page computes from the same bytes it links:
sha-256:f851528b8d6e7e3acbaf8a711b9e20450ae38c0534136bd4f786265797ac07b9
Suite source packages/aef/test.ts at sha-256:728c1769a3c95bb6…; additional documents applied: 1300/0.2, 1300/0.1, 1201/0.1, 1301/0.1, 1400/0.1.
Produced with AEF 1201 v0.1 and extended in each session since. Under AEF 1201 C5, only entries whose inputs are retained byte-identical are fixtures; entries that regenerate their inputs each time the suite executes are generated tests and discharge no C-requirement. This is the suite's fourth version and the first to carry retirements: five expectations pinned under earlier documents were superseded by the AEF 1300 v0.2 and AEF 1200 v0.2 rulings, each retired with its reason below and re-pinned under the ruled expectation, per AEF 1201 C12. The suite version under C10 is the sha-256 digest of this file as served, which this file cannot contain.
The entries
| Entry | Kind | Exercises |
|---|---|---|
| canonical form sorts object keys | generated | 1300/R4 |
| canonical form is stable across key insertion order | generated | 1300/R4 |
| REQUIRED TO FAIL: non-integer numbers are rejected | generated, fails | 1300/R5 |
| REQUIRED TO FAIL: undefined is rejected rather than dropped | generated, fails | 1300/R5 |
| a well-formed record passes with qualifications | generated | 1200/V2 |
| REQUIRED TO FAIL: one flipped byte anywhere in the record isolates seal-integrity | generated, fails | 1200/V8, 1200/V9, 1200/V4 |
| REQUIRED TO FAIL: a broken act log chain isolates ordering | generated, fails | 1200/V21, 1200/V9 |
| REQUIRED TO FAIL: an act outside the declared boundary isolates scope-membership | generated, fails | 1200/V15 |
| REQUIRED TO FAIL: truncation, with no closing entry isolates termination | generated, fails | 1300/R13, 1200/V44 |
| REQUIRED TO FAIL: a capture time after the seal time isolates time | generated, fails | 1200/V26 |
| REQUIRED TO FAIL: a declaration that does not match the record isolates declaration-binding | generated, fails | 1300/R15, 1200/V43 |
| REQUIRED TO FAIL: an output artifact that does not match its digest isolates artifact-binding | generated, fails | 1200/V18 |
| a fatal check that cannot run yields INCONCLUSIVE, not FAIL and not PASS | generated | 1200/V36 |
| V6: PASS is never emitted alongside a qualification | generated | 1200/V6 |
| V7: every emitted qualification carries a registry class | generated | 1200/V7 |
| V5: the negative claims block is present and non-empty | generated | 1200/V5 |
| V42: no conclusion-bearing field describes a result as certified, guaranteed, proven, or assured | generated | 1200/V42 |
| V10: the key binding reports which of identity or continuity was achieved | generated | 1200/V10, 1200/V11, 1200/V13 |
| the published example record verifies as shippedaer.json, declaration.json | pinned | 1200/V2 |
| REQUIRED TO FAIL: the published tampered copyaer.tampered.json, declaration.json | pinned, fails | 1200/V8, 1200/V9 |
| the published verification result matches what the verifier produces nowverification-result.json | pinned | 1200/V1 |
| a reviewer holding only the record, with no artifacts, still gets a usable outcomeaer.json, declaration.json | pinned | 1200/V19, 1200/V41 |
| approval-0001: authorization plus acceptance verifies, full set re-pinned under AEF 1300 v0.2's margin qualificationapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.json | pinned | 1301/A3, 1301/A4, 1301/A5, 1301/A6, 1301/A7, 1301/A8, 1301/A10, 1201/C6 |
| approval-0001: with the acceptance withheld, ACCEPTANCE-ABSENT is qualified, never fatalapproval-0001/aer.json, approval-0001/declaration.json | pinned | 1301/A7 |
| REQUIRED TO FAIL: an authorization whose referent is not this record's declaration isolates approval-bindingapproval-0001/aer.rtf-referent-mismatch.json, approval-0001/declaration.json | pinned, fails | 1301/A4, 1301/A5, 1200/V45 |
| REQUIRED TO FAIL: a relation declared distinct under the operator's own key isolates approval-relationapproval-0001/aer.rtf-relation-mismatch.json, approval-0001/declaration.json | pinned, fails | 1301/A10, 1200/V46 |
| REQUIRED TO FAIL: an authorization that postdates the first captured act isolates approval-timingapproval-0001/aer.rtf-authorization-postdates.json, approval-0001/declaration.json | pinned, fails | 1301/A6, 1200/V47 |
| REQUIRED TO FAIL: an approval record with no type member isolates approval-formapproval-0001/aer.rtf-malformed-approval.json, approval-0001/declaration.json | pinned, fails | 1301/A1, 1301/A3, 1200/V27 |
| REQUIRED TO FAIL: an acceptance placed inside the record it would accept isolates approval-formapproval-0001/aer.rtf-acceptance-in-record.json, approval-0001/declaration.json | pinned, fails | 1301/A2 |
| REQUIRED TO FAIL: approval required by the declaration and absent from the record isolates approval-formapproval-0001/aer.rtf-approval-required-absent.json, approval-0001/declaration.json | pinned, fails | 1200/V29, 1300/R24 |
| REQUIRED TO FAIL: an acceptance over some other record's digest isolates acceptance-bindingapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.rtf-referent-mismatch.json | pinned, fails | 1301/A8, 1200/V48 |
| REQUIRED TO FAIL: an acceptance declared distinct under the operator's own key isolates acceptance-bindingapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.rtf-relation-mismatch.json | pinned, fails | 1301/A10, 1301/A8, 1200/V48 |
| approval-0001: the self-approved record emits APPROVAL-IS-SELF-ASSERTION exactly once, full set re-pinned under AEF 1300 v0.2approval-0001/aer.selfapproved.json, approval-0001/declaration.selfapproved.json | pinned | 1301/A10, 1301/A11, 1201/C6 |
| approval-0001: an R24-form approval verifies in the 1300/0.1 record that carries it, challenge-0003 resolvedapproval-0001/aer.r24-form-approval.json, approval-0001/declaration.json | pinned | 1300/R24, 1200/V27 |
| run-0001: the published record's full qualification set, re-pinned under AEF 1300 v0.2's margin qualificationaer.json, declaration.json | pinned | 1200/V14, 1200/V19, 1200/V24, 1200/V25, 1200/V29, 1201/C6 |
| anchor-0001: an anchored declaration and record verify, full set re-pinned under AEF 1300 v0.2anchor-0001/aer.json, anchor-0001/declaration.json | pinned | 1400/T3, 1400/T4, 1400/T6, 1400/T8, 1201/C6, 1200/V49, 1200/V50, 1200/V51 |
| REQUIRED TO FAIL: anchor evidence binding a different digest than the sealed bytes isolates anchor-formanchor-0001/aer.rtf-anchor-digest-mismatch.json, anchor-0001/declaration.json | pinned, fails | 1400/T3, 1200/V49 |
| anchor-0001: a late declaration anchor leaves the before-relation not established, reported and not fatalanchor-0001/aer.late-decl-anchor.json, anchor-0001/declaration.late-anchor.json | pinned | 1400/T6, 1200/V50 |
| anchor-0001: a latency exceedance is a finding inside a declared boundary, not a failure of the recordanchor-0001/aer.latency-exceeded.json, anchor-0001/declaration.tight-latency.json | pinned | 1400/T8, 1200/V51 |
| anchor-0001: a renewal binding this record's digest is held, with its proof honestly unverifiedanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.json | pinned | 1400/T10 |
| REQUIRED TO FAIL: a renewal over some other record's digest isolates anchor-renewalanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.rtf-mismatch.json | pinned, fails | 1400/T10, 1200/V52 |
| anchor-0001: V35 first case, an anchor predating the deprecation bounds the exposureanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/deprecations.json | pinned | 1200/V35, 1400/T11 |
| anchor-0001: V35 second case, an unanchored seal cannot be placed before the breakanchor-0001/aer.latency-exceeded.json, anchor-0001/declaration.tight-latency.json, anchor-0001/deprecations.json | pinned | 1200/V35, 1400/T11 |
| anchor-0001: a renewal predating the deprecation, under undeprecated algorithms, extends the chainanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.json, anchor-0001/deprecations.json | pinned | 1400/T10, 1400/T11, 1200/V35 |
| form-0002: a v0.2 record verifies with no unauthenticated-margin qualification, full set pinnedform-0002/aer.json, form-0002/declaration.json | pinned | 1300/R6, 1300/R2, 1201/C6, 1200/V53 |
| form-0002: the supersession member is reported, by canonical identity digestform-0002/aer.supersedes-run-0001.json, form-0002/declaration.json | pinned | 1300/R27, 1200/V53 |
| REQUIRED TO FAIL: a v0.2 seal time rewritten after sealing isolates seal-integrityform-0002/aer.rtf-sealedat-tampered.json, form-0002/declaration.json | pinned, fails | 1300/R6, 1200/V8 |
| REQUIRED TO FAIL: a v0.2 anchor stripped after sealing isolates seal-integrityform-0002/aer.rtf-anchor-stripped.json, form-0002/declaration.json | pinned, fails | 1300/R6, 1200/V8 |
| REQUIRED TO FAIL: an unknown member inside a v0.2 approval record isolates approval-formform-0002/aer.rtf-approval-unknown-member.json, form-0002/declaration.json | pinned, fails | 1300/R24, 1200/V27 |
| form-0002: an unknown record form is reported, not guessed at, and nothing else is checkedform-0002/aer.rtf-unknown-version.json, form-0002/declaration.json | pinned | 1300/R2, 1200/V53, 1200/V36 |
| REQUIRED TO FAIL: a v0.2 record without the supersedes member its form fixes isolates record-formform-0002/aer.rtf-missing-supersedes.json, form-0002/declaration.json | pinned, fails | 1300/R1, 1200/V53 |
Requirement coverage: 54 requirements of 1200/0.2
Asserted (28)
V2, V5, V6, V7, V8, V9, V10, V14, V15, V19, V21, V24, V26, V27, V29, V35, V36, V42, V43, V44, V45, V46, V47, V48, V49, V51, V52, V53
Asserted in part (9)
| V1 | three members of the shipped result are asserted, not the full AEF 1101 section 11 form |
|---|---|
| V4 | the failing check is asserted on FAIL; the INCONCLUSIVE branch is unasserted |
| V11 | asserted for the none mechanism only |
| V13 | asserted for one of five mechanisms; pin is implemented and unexercised; x509, certificate-transparency, and key-transparency are neither implemented nor exercised |
| V18 | the mismatch-is-fatal branch is asserted; provenance recording is unasserted |
| V25 | the qualification class is pinned; the reported interval value is unasserted |
| V41 | asserted for absent artifacts; absent roles and absent declared elements are unasserted |
| V50 | the not-established branch is pinned; the established branch is asserted in the worked examples' check status |
| V54 | every result carries per-check status and tests read it; no test asserts the status vocabulary itself |
Occurs unasserted (8)
The condition arises on every suite run and no test asserts it. A verifier that silently stopped satisfying any of these would still pass the suite.
V3, V17, V20, V23, V28, V30, V31, V37
Never arises (4)
No fixture or generated test produces the condition at all. V32, V33, and V34 await an earlier verification result to compare against; V16's declared-present-and-absent case has a failing branch in declared-elements and no fixture.
V16, V32, V33, V34
Not fixture-checkable (4)
Per AEF 1200 section 14: V12, V38, and V39 are checked by inspecting the verifier, and V40 is the document's one requirement on judgment.
V12, V38, V39, V40
Scoped unproducible (1)
V22 v0.2 scopes ORDER-UNCHAINED to record forms that do not require chaining, of which none exist, per resolution-0001; the condition is unproducible by any conformant input until such a form does, and it sits in its own bucket so the reason travels with the fact and the partition stays complete.
V22
Required to fail, and isolation
key-binding has no failing state in the implementation, because V13's stapled branches are expressible after AEF 1200 v0.2 and remain unimplemented, which the running failure list carries. anchor-ordering and algorithm-standing have no failing state by design: they report and decide nothing. record-form fails on a member-set violation and reports not-run on an unknown form. seal-latency's failing fixture fails it non-fatally, a finding inside a declared boundary. Of 22 checks, 5 have no failing entry counting generated tests, two of those by design; under C5, 12 of 22 have no failing fixture.
Checks with no failing fixture under C5: key-binding, declared-elements, role-disclosure, trust-base-reference, anchor-ordering, algorithm-standing.
Fifteen fatal-capable checks: record-form joined when R1's member-set test gave it a failing state. The withIsolatingFixture list counts generated tests for the seven pre-1301 checks; under C5, the approval, anchor, and form checks are the ones with pinned isolating fixtures.
Five entries pin complete qualification sets by class: the approval-0001 worked example, the self-approved record, run-0001, anchor-0001, and the form-0002 worked example. Eleven more assert one or more classes without pinning the full set. Every other entry still fails AEF 1201 C6 in part.
Retired expectations (5)
Under AEF 1201 C12 a retirement keeps the entry's identity and records why the pinned expectation no longer binds:
approval-0001: authorization plus acceptance verifies, with its full qualification set pinned by class (14 August 2026)
Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates UNAUTHENTICATED-SEAL-MARGIN
expectation superseded, not wrong: AEF 1300 v0.2's margin qualification joins every v0.1-form result; re-pinned under the same inputs with the thirteen-class set
approval-0001: the self-approved record emits APPROVAL-IS-SELF-ASSERTION exactly once, full set pinned (14 August 2026)
Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates the margin qualification
same supersession as above; re-pinned with the margin class
run-0001: the published record's full qualification set, pinned by class (14 August 2026)
Retired expectation: PASS_WITH_QUALIFICATIONS with the eleven-class set that predates the margin qualification
same supersession as above; re-pinned with the margin class
anchor-0001: an anchored declaration and record verify, full qualification set pinned by class (14 August 2026)
Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates the margin qualification
same supersession as above; re-pinned with the margin class
challenge-0003 reproduction: an R24-form approval fails approval-form under verifier 0.2.0 (14 August 2026)
Retired expectation: FAIL with failedCheck approval-form, pinned explicitly as the disputed behavior
resolution-0003 ruled against the pin: V27 v0.2 tests the form the record's claimed version defines, so a bare R24-form approval in a 1300/0.1 record verifies; re-pinned under the ruled expectation
The suite's own standing
The declaration records 8 failures against AEF 1201's requirements, listed with the rest of the series' state on the status page, and states the conformance claim's standing:
None exists and none can honestly be made. AEF 1201 C1 requires a suite version, and this suite does not yet satisfy the requirements that make its version meaningful. AEF 1201 section 12 states this.