# Expected verdict — L0-5 fixture (pOre) Fixture: https://pore-l0-5.surge.sh Host: Surge (static, CDN). One file, `200.html`, is served with HTTP 200 and `Content-Type: text/html` for every path that is not a deployed file. `index.html` is the same shell. `robots.txt` is deployed, `User-agent: *` / `Allow: /`. Declared door request (commerce): `GET https://pore-l0-5.surge.sh/pay` Documents declared as published by the site: `/openapi.json`, `/llms.txt`, `/.well-known/ai`; `/robots.txt` is added by the tester. This verdict was written from reading tester 0.1.2's source and from probing the host directly with curl, Python urllib and Node fetch (all four client profiles were exercised by hand). The reference tester itself was not run. ## Per requirement - **L0-1 — PASS.** `pore-l0-5.surge.sh` resolves, connects on 443, and the certificate verifies (Surge's wildcard `*.surge.sh` cert). - **L0-2 — PASS.** `GET /pay` answers 200 to browser-UA, python-urllib, curl and node-fetch. Same status across all four profiles. - **L0-3 — PASS.** The 200 body is the application shell, not a challenge page; it carries none of the tester's challenge markers, and the refusal branch (>=400 with text/html) does not fire. - **L0-4 — FAIL (incidental, not the designed wrongness).** The tester probes the undeclared verb: `POST /pay`. Surge's static edge answers 404 to POST while the declared GET answers 200. That is the documented failure mode ("answered the undeclared verb with something other than 405"), a property of a static host, not of the shell. Declared method GET, probe POST -> 404. - **L0-5 — PASS under 0.1.2. This is the designed wrongness, and the pass is the finding.** `/openapi.json` is not a document. It is the SPA catch-all: HTTP 200, `Content-Type: text/html`, body = the application shell. The same is true of `/llms.txt` and `/.well-known/ai`. L0-5 asks only for a 2xx to every client profile, so parity passes on a shell that is not the document. The robots half passes: `/robots.txt` is `Allow: /`, so `can_fetch("*", "/pay")` is true. Substantively the door is wrong: it answers 200 text/html to every path, `/openapi.json` included. The owed 0.2 clause ("a 2xx whose body is an HTML page, for a document whose format is not HTML, is not the document") is what turns this PASS into a FAIL. No requirement text needs to change for that to happen. ## Note on the host, unasked Surge injects its own `robots.txt` (`User-agent: *` / `Disallow: /`) when the site does not deploy one. That is the L0-5 provenance case almost verbatim: a CDN-managed setting serving rules the origin never wrote. I deployed an allow-all `robots.txt` so this fixture tests the shell, not the CDN default. If you want the CDN-injected-disallow as its own fixture, it is one deploy away and I will say so in the verdict.