```python
"""Vet a device's proposed firmware upgrade path and report the final tag."""

import re

def vet_upgrade_path(installed: str, steps):
    if not isinstance(installed, str):
        raise ValueError("Installed tag must be a string")
    if not isinstance(steps, list):
        raise ValueError("Upgrade steps must be a list")
    if not all(isinstance(step, dict) and len(step) == 2 and isinstance(step["tag"], str) and isinstance(step["requires"], str) for step in steps):
        raise ValueError("Upgrade steps must be {tag, requires} records")
    if not all(re.match(r'\d+\.\d+', tag) and re.match(r'\d+\.\d+', requires) for tag, requires in steps):
        raise ValueError("Tags must be two dot-separated decimal numbers")
    if not all(int(re.split('\.', tag)[0]) < int(re.split('\.', requires)[0]) for tag, requires in steps):
        raise ValueError("Tags must be strictly older than their requires")
    carried = installed
    for step in steps:
        if carried >= step["requires"]:
            raise ValueError(f"step {step['tag']} requires at least {step['requires']}")
        if step["tag"] <= carried:
            raise ValueError(f"step {step['tag']} is not an upgrade from {carried}")
        carried = step["tag"]
    return carried
```