Grant Stellmacher
RegistryAEF

Attested Execution Framework

The coverage declaration

What the reference verifier's suite covers and what it does not, entry by entry. This page renders fixture-coverage.json and adds nothing to it; the JSON is the declaration, per AEF 1201.

aef-reference-verifier 0.4.0against 1200/0.2, generated 14 August 2026

Suite version

Under AEF 1201 C10 the suite version is the digest of the coverage declaration as served, which the file cannot contain and this page computes from the same bytes it links:

sha-256:f851528b8d6e7e3acbaf8a711b9e20450ae38c0534136bd4f786265797ac07b9

Suite source packages/aef/test.ts at sha-256:728c1769a3c95bb6; additional documents applied: 1300/0.2, 1300/0.1, 1201/0.1, 1301/0.1, 1400/0.1.

Produced with AEF 1201 v0.1 and extended in each session since. Under AEF 1201 C5, only entries whose inputs are retained byte-identical are fixtures; entries that regenerate their inputs each time the suite executes are generated tests and discharge no C-requirement. This is the suite's fourth version and the first to carry retirements: five expectations pinned under earlier documents were superseded by the AEF 1300 v0.2 and AEF 1200 v0.2 rulings, each retired with its reason below and re-pinned under the ruled expectation, per AEF 1201 C12. The suite version under C10 is the sha-256 digest of this file as served, which this file cannot contain.

The entries

Show
Suite entries with kind, inputs, and requirements exercised
EntryKindExercises
canonical form sorts object keysgenerated1300/R4
canonical form is stable across key insertion ordergenerated1300/R4
REQUIRED TO FAIL: non-integer numbers are rejectedgenerated, fails1300/R5
REQUIRED TO FAIL: undefined is rejected rather than droppedgenerated, fails1300/R5
a well-formed record passes with qualificationsgenerated1200/V2
REQUIRED TO FAIL: one flipped byte anywhere in the record isolates seal-integritygenerated, fails1200/V8, 1200/V9, 1200/V4
REQUIRED TO FAIL: a broken act log chain isolates orderinggenerated, fails1200/V21, 1200/V9
REQUIRED TO FAIL: an act outside the declared boundary isolates scope-membershipgenerated, fails1200/V15
REQUIRED TO FAIL: truncation, with no closing entry isolates terminationgenerated, fails1300/R13, 1200/V44
REQUIRED TO FAIL: a capture time after the seal time isolates timegenerated, fails1200/V26
REQUIRED TO FAIL: a declaration that does not match the record isolates declaration-bindinggenerated, fails1300/R15, 1200/V43
REQUIRED TO FAIL: an output artifact that does not match its digest isolates artifact-bindinggenerated, fails1200/V18
a fatal check that cannot run yields INCONCLUSIVE, not FAIL and not PASSgenerated1200/V36
V6: PASS is never emitted alongside a qualificationgenerated1200/V6
V7: every emitted qualification carries a registry classgenerated1200/V7
V5: the negative claims block is present and non-emptygenerated1200/V5
V42: no conclusion-bearing field describes a result as certified, guaranteed, proven, or assuredgenerated1200/V42
V10: the key binding reports which of identity or continuity was achievedgenerated1200/V10, 1200/V11, 1200/V13
the published example record verifies as shippedaer.json, declaration.jsonpinned1200/V2
REQUIRED TO FAIL: the published tampered copyaer.tampered.json, declaration.jsonpinned, fails1200/V8, 1200/V9
the published verification result matches what the verifier produces nowverification-result.jsonpinned1200/V1
a reviewer holding only the record, with no artifacts, still gets a usable outcomeaer.json, declaration.jsonpinned1200/V19, 1200/V41
approval-0001: authorization plus acceptance verifies, full set re-pinned under AEF 1300 v0.2's margin qualificationapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.jsonpinned1301/A3, 1301/A4, 1301/A5, 1301/A6, 1301/A7, 1301/A8, 1301/A10, 1201/C6
approval-0001: with the acceptance withheld, ACCEPTANCE-ABSENT is qualified, never fatalapproval-0001/aer.json, approval-0001/declaration.jsonpinned1301/A7
REQUIRED TO FAIL: an authorization whose referent is not this record's declaration isolates approval-bindingapproval-0001/aer.rtf-referent-mismatch.json, approval-0001/declaration.jsonpinned, fails1301/A4, 1301/A5, 1200/V45
REQUIRED TO FAIL: a relation declared distinct under the operator's own key isolates approval-relationapproval-0001/aer.rtf-relation-mismatch.json, approval-0001/declaration.jsonpinned, fails1301/A10, 1200/V46
REQUIRED TO FAIL: an authorization that postdates the first captured act isolates approval-timingapproval-0001/aer.rtf-authorization-postdates.json, approval-0001/declaration.jsonpinned, fails1301/A6, 1200/V47
REQUIRED TO FAIL: an approval record with no type member isolates approval-formapproval-0001/aer.rtf-malformed-approval.json, approval-0001/declaration.jsonpinned, fails1301/A1, 1301/A3, 1200/V27
REQUIRED TO FAIL: an acceptance placed inside the record it would accept isolates approval-formapproval-0001/aer.rtf-acceptance-in-record.json, approval-0001/declaration.jsonpinned, fails1301/A2
REQUIRED TO FAIL: approval required by the declaration and absent from the record isolates approval-formapproval-0001/aer.rtf-approval-required-absent.json, approval-0001/declaration.jsonpinned, fails1200/V29, 1300/R24
REQUIRED TO FAIL: an acceptance over some other record's digest isolates acceptance-bindingapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.rtf-referent-mismatch.jsonpinned, fails1301/A8, 1200/V48
REQUIRED TO FAIL: an acceptance declared distinct under the operator's own key isolates acceptance-bindingapproval-0001/aer.json, approval-0001/declaration.json, approval-0001/acceptance.rtf-relation-mismatch.jsonpinned, fails1301/A10, 1301/A8, 1200/V48
approval-0001: the self-approved record emits APPROVAL-IS-SELF-ASSERTION exactly once, full set re-pinned under AEF 1300 v0.2approval-0001/aer.selfapproved.json, approval-0001/declaration.selfapproved.jsonpinned1301/A10, 1301/A11, 1201/C6
approval-0001: an R24-form approval verifies in the 1300/0.1 record that carries it, challenge-0003 resolvedapproval-0001/aer.r24-form-approval.json, approval-0001/declaration.jsonpinned1300/R24, 1200/V27
run-0001: the published record's full qualification set, re-pinned under AEF 1300 v0.2's margin qualificationaer.json, declaration.jsonpinned1200/V14, 1200/V19, 1200/V24, 1200/V25, 1200/V29, 1201/C6
anchor-0001: an anchored declaration and record verify, full set re-pinned under AEF 1300 v0.2anchor-0001/aer.json, anchor-0001/declaration.jsonpinned1400/T3, 1400/T4, 1400/T6, 1400/T8, 1201/C6, 1200/V49, 1200/V50, 1200/V51
REQUIRED TO FAIL: anchor evidence binding a different digest than the sealed bytes isolates anchor-formanchor-0001/aer.rtf-anchor-digest-mismatch.json, anchor-0001/declaration.jsonpinned, fails1400/T3, 1200/V49
anchor-0001: a late declaration anchor leaves the before-relation not established, reported and not fatalanchor-0001/aer.late-decl-anchor.json, anchor-0001/declaration.late-anchor.jsonpinned1400/T6, 1200/V50
anchor-0001: a latency exceedance is a finding inside a declared boundary, not a failure of the recordanchor-0001/aer.latency-exceeded.json, anchor-0001/declaration.tight-latency.jsonpinned1400/T8, 1200/V51
anchor-0001: a renewal binding this record's digest is held, with its proof honestly unverifiedanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.jsonpinned1400/T10
REQUIRED TO FAIL: a renewal over some other record's digest isolates anchor-renewalanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.rtf-mismatch.jsonpinned, fails1400/T10, 1200/V52
anchor-0001: V35 first case, an anchor predating the deprecation bounds the exposureanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/deprecations.jsonpinned1200/V35, 1400/T11
anchor-0001: V35 second case, an unanchored seal cannot be placed before the breakanchor-0001/aer.latency-exceeded.json, anchor-0001/declaration.tight-latency.json, anchor-0001/deprecations.jsonpinned1200/V35, 1400/T11
anchor-0001: a renewal predating the deprecation, under undeprecated algorithms, extends the chainanchor-0001/aer.json, anchor-0001/declaration.json, anchor-0001/renewal.json, anchor-0001/deprecations.jsonpinned1400/T10, 1400/T11, 1200/V35
form-0002: a v0.2 record verifies with no unauthenticated-margin qualification, full set pinnedform-0002/aer.json, form-0002/declaration.jsonpinned1300/R6, 1300/R2, 1201/C6, 1200/V53
form-0002: the supersession member is reported, by canonical identity digestform-0002/aer.supersedes-run-0001.json, form-0002/declaration.jsonpinned1300/R27, 1200/V53
REQUIRED TO FAIL: a v0.2 seal time rewritten after sealing isolates seal-integrityform-0002/aer.rtf-sealedat-tampered.json, form-0002/declaration.jsonpinned, fails1300/R6, 1200/V8
REQUIRED TO FAIL: a v0.2 anchor stripped after sealing isolates seal-integrityform-0002/aer.rtf-anchor-stripped.json, form-0002/declaration.jsonpinned, fails1300/R6, 1200/V8
REQUIRED TO FAIL: an unknown member inside a v0.2 approval record isolates approval-formform-0002/aer.rtf-approval-unknown-member.json, form-0002/declaration.jsonpinned, fails1300/R24, 1200/V27
form-0002: an unknown record form is reported, not guessed at, and nothing else is checkedform-0002/aer.rtf-unknown-version.json, form-0002/declaration.jsonpinned1300/R2, 1200/V53, 1200/V36
REQUIRED TO FAIL: a v0.2 record without the supersedes member its form fixes isolates record-formform-0002/aer.rtf-missing-supersedes.json, form-0002/declaration.jsonpinned, fails1300/R1, 1200/V53

Requirement coverage: 54 requirements of 1200/0.2

Asserted (28)

V2, V5, V6, V7, V8, V9, V10, V14, V15, V19, V21, V24, V26, V27, V29, V35, V36, V42, V43, V44, V45, V46, V47, V48, V49, V51, V52, V53

Asserted in part (9)

Requirements asserted in part, with what remains unasserted
V1three members of the shipped result are asserted, not the full AEF 1101 section 11 form
V4the failing check is asserted on FAIL; the INCONCLUSIVE branch is unasserted
V11asserted for the none mechanism only
V13asserted for one of five mechanisms; pin is implemented and unexercised; x509, certificate-transparency, and key-transparency are neither implemented nor exercised
V18the mismatch-is-fatal branch is asserted; provenance recording is unasserted
V25the qualification class is pinned; the reported interval value is unasserted
V41asserted for absent artifacts; absent roles and absent declared elements are unasserted
V50the not-established branch is pinned; the established branch is asserted in the worked examples' check status
V54every result carries per-check status and tests read it; no test asserts the status vocabulary itself

Occurs unasserted (8)

The condition arises on every suite run and no test asserts it. A verifier that silently stopped satisfying any of these would still pass the suite.

V3, V17, V20, V23, V28, V30, V31, V37

Never arises (4)

No fixture or generated test produces the condition at all. V32, V33, and V34 await an earlier verification result to compare against; V16's declared-present-and-absent case has a failing branch in declared-elements and no fixture.

V16, V32, V33, V34

Not fixture-checkable (4)

Per AEF 1200 section 14: V12, V38, and V39 are checked by inspecting the verifier, and V40 is the document's one requirement on judgment.

V12, V38, V39, V40

Scoped unproducible (1)

V22 v0.2 scopes ORDER-UNCHAINED to record forms that do not require chaining, of which none exist, per resolution-0001; the condition is unproducible by any conformant input until such a form does, and it sits in its own bucket so the reason travels with the fact and the partition stays complete.

V22

Required to fail, and isolation

key-binding has no failing state in the implementation, because V13's stapled branches are expressible after AEF 1200 v0.2 and remain unimplemented, which the running failure list carries. anchor-ordering and algorithm-standing have no failing state by design: they report and decide nothing. record-form fails on a member-set violation and reports not-run on an unknown form. seal-latency's failing fixture fails it non-fatally, a finding inside a declared boundary. Of 22 checks, 5 have no failing entry counting generated tests, two of those by design; under C5, 12 of 22 have no failing fixture.

Checks with no failing fixture under C5: key-binding, declared-elements, role-disclosure, trust-base-reference, anchor-ordering, algorithm-standing.

Fifteen fatal-capable checks: record-form joined when R1's member-set test gave it a failing state. The withIsolatingFixture list counts generated tests for the seven pre-1301 checks; under C5, the approval, anchor, and form checks are the ones with pinned isolating fixtures.

Five entries pin complete qualification sets by class: the approval-0001 worked example, the self-approved record, run-0001, anchor-0001, and the form-0002 worked example. Eleven more assert one or more classes without pinning the full set. Every other entry still fails AEF 1201 C6 in part.

Retired expectations (5)

Under AEF 1201 C12 a retirement keeps the entry's identity and records why the pinned expectation no longer binds:

approval-0001: authorization plus acceptance verifies, with its full qualification set pinned by class (14 August 2026)

Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates UNAUTHENTICATED-SEAL-MARGIN

expectation superseded, not wrong: AEF 1300 v0.2's margin qualification joins every v0.1-form result; re-pinned under the same inputs with the thirteen-class set

approval-0001: the self-approved record emits APPROVAL-IS-SELF-ASSERTION exactly once, full set pinned (14 August 2026)

Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates the margin qualification

same supersession as above; re-pinned with the margin class

run-0001: the published record's full qualification set, pinned by class (14 August 2026)

Retired expectation: PASS_WITH_QUALIFICATIONS with the eleven-class set that predates the margin qualification

same supersession as above; re-pinned with the margin class

anchor-0001: an anchored declaration and record verify, full qualification set pinned by class (14 August 2026)

Retired expectation: PASS_WITH_QUALIFICATIONS with the twelve-class set that predates the margin qualification

same supersession as above; re-pinned with the margin class

challenge-0003 reproduction: an R24-form approval fails approval-form under verifier 0.2.0 (14 August 2026)

Retired expectation: FAIL with failedCheck approval-form, pinned explicitly as the disputed behavior

resolution-0003 ruled against the pin: V27 v0.2 tests the form the record's claimed version defines, so a bare R24-form approval in a 1300/0.1 record verifies; re-pinned under the ruled expectation

The suite's own standing

The declaration records 8 failures against AEF 1201's requirements, listed with the rest of the series' state on the status page, and states the conformance claim's standing:

None exists and none can honestly be made. AEF 1201 C1 requires a suite version, and this suite does not yet satisfy the requirements that make its version meaningful. AEF 1201 section 12 states this.