## MODIFIED Requirements ### Requirement: Bounded provider feedback control envelope The registered bidirectional reliable `control.ack.v1` flow SHALL define an ASCII `VGF1` envelope with a direction byte, type byte, big-endian payload length, and exact payload bytes. Only host termination, rumble, and HDR feedback SHALL be valid from the gateway to the client. Only IDR, FEC/loss feedback, and an empty terminal receipt SHALL be valid from the client to the gateway. The terminal receipt SHALL be valid only while the same session awaits receipt of its one terminal event and MUST NOT be forwarded to the provider. The envelope SHALL contain no provider address, certificate, credential, or opaque provider packet. #### Scenario: Host termination forwarding - **WHEN** the Apollo adapter receives an authenticated host termination packet - **THEN** the gateway forwards a bounded `VGF1` termination envelope over reliable Verse control and reports the provider state separately #### Scenario: Terminal event receipt - **WHEN** a client receives the reliable typed terminal event - **THEN** it sends the empty terminal receipt and the gateway owns bounded tunnel closure without forwarding the receipt to the provider #### Scenario: Unauthorized or malformed feedback - **WHEN** feedback is disabled by policy, has an invalid direction/type/length, contains a forbidden provider field, or sends a terminal receipt outside the awaiting-terminal state - **THEN** the gateway rejects it without forwarding or provider mutation