The light service maps the node's lockKind (igneum_getFinalityCheckpoints, 2.0.2 line) to lock_state beside every certificate
it answers with; core.js reads it as one step on /light and /receipt, refuses an unknown kind and a receipt that claims final
under a reported recovery lock; the pages print "recovery lock, not final" on the result, the receipt file carries lock_state,
the one-file verifier prints it; the shared terms block defines the recovery lock; /oracle says recovery locks are not accepted
by the Sepolia verifiers (two-thirds rule only, so every stored root passed the final rule). Node and browser negative cases
added. On a node before the field nothing changes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>