Purpose
What this record standardizes.
Defines safe, removable evidence for PHP, rewrites, headers, protected paths, assets, JSON delivery, UTC, and writable local storage on the actual host.
Portable intelligence-operation artifacts require inspectable boundaries, deterministic evidence, explicit recovery, and no silent loss or identity overclaim.
Normative requirements
What conforming implementations must, should, and may do.
The diagnostic endpoint disclose no secrets, environment variables, absolute paths, session contents, or private configuration.
Stable promotion require evidence from the actual target hosting account.
The documentation instruct operators to remove or disable the endpoint after testing.
Each result include pass, fail, or not-tested with a non-sensitive explanation.
Game interaction mapping
What players and interfaces do.
Data contract
Inputs and outputs.
Inputs
- Browser-local artifact
- Applicable standard
- Declared source context
Outputs
- Reviewable result
- Reason code
- Local export
- Preserved original
State contract
Allowed or expected transitions.
| From | Event | To |
|---|---|---|
| received | requirement evaluated | accepted, quarantined, or rejected-with-source-untouched |
Evidence and provenance
Review requirements for claims and consequential state.
- Record source artifact ID, canonical digest, UTC event time, responsible local role label, and reason code.
- Do not convert a digest, label, or generated statement into an identity or authoritative fact claim.
User-interface requirements
How the requirement must appear at the point of use.
- Show the record code and requirement level at the point of use.
- Expose the reason for pass, fail, quarantine, recovery, or rejection.
- Provide direct links to canonical human and machine records.
Accessibility requirements
Equivalent access to essential information and controls.
- Essential information is available without reliance on color, audio, motion, or a graph alone.
- Keyboard, screen-reader, reduced-motion, high-zoom, mobile, and print equivalents are documented.
Telemetry events
Minimum event records for implementation review.
standard.target-hosting-smoke-evidence.evaluated
Required fields:
Abuse and exploit cases
What the implementation must anticipate.
- A participant attempts to remove unknown data during import or migration.
- A digest or declared label is presented as proof of human identity or approval.
- A consequential record is overwritten without a reason or preserved original.
Failure and recovery
Fail-closed behavior and recovery path.
Fail closed for irreversible publication or overwrite. Preserve original content, show the failing requirement, and allow export or non-destructive recovery.
Retain the original artifact and review event, clone any repaired draft, and require a new explicit validation event before continuing.
Example implementation
A concise fictional game implementation.
The local tool evaluates HOST-01, writes a UTC reason-coded result, and exposes both original and resulting artifacts for export.
Open complete mission examples →Related records and examples
Continue through the operating model.
Supporting research
Deep links into complete canonical reports.
Revision history
Published changes to this record.
Initial HOST-01 publication for IARPG-OPS-2 release-candidate hardening.