Build the policy error blocking a spec, or None when it is allowed.
The one place that turns this config's policy fields into an error, so callers that need the message without raising (a launch advisory, a selector footer) cannot drift from callers that raise.
The spec to check, or None to ask for the error that
describes a deny-all policy blocking default resolution.
Where the spec was declared, prefixed to the message.
Infer a provider for a bare name before matching, the
way create_model does. Set this on preflight checks against
text a user typed; leave it off where the caller already holds a
canonical spec, so resolution stays off hot paths such as the
recent-models cache.