```python
"""Vet a device's proposed firmware upgrade path and report the final tag."""


def vet_upgrade_path(installed: str, steps: list) -> str:
    if not isinstance(installed, str):
        raise ValueError("installed must be a string")
    if not isinstance(steps, list):
        raise ValueError("steps must be a list")
    for step in steps:
        if not isinstance(step, dict) or len(step) != 2:
            raise ValueError("each step must be a {tag, requires} record")
        tag, requires = step
        if not isinstance(tag, str) or not isinstance(requires, str):
            raise ValueError("tag and requires must be strings")
        parts = tag.split(".")
        if len(parts) != 2 or any(part.startswith("0") for part in parts):
            raise ValueError("tag must be two dot-separated numbers, line.point, each a plain decimal with no leading zero")
        parts = requires.split(".")
        if len(parts) != 2 or any(part.startswith("0") for part in parts):
            raise ValueError("requires must be two dot-separated numbers, line.point, each a plain decimal with no leading zero")
        if int(parts[0]) < int(parts[1]):
            raise ValueError("requires must be at least as old as the step's tag")
        if int(parts[0]) > int(parts[1]):
            raise ValueError("requires must be strictly older than the step's tag")
    carried = installed
    for step in steps:
        if carried < step["requires"]:
            raise ValueError(
                f"step {step['tag']} requires at least {step['requires']}"
            )
        if step["tag"] <= carried:
            raise ValueError(f"step {step['tag']} is not an upgrade from {carried}")
        carried = step["tag"]
    return carried
```