CAIN-42 MCPGate

CAIN Trust Fabric - Changelog

Last updated: Loading...

Operational proof -- cain-mr-02 (every 30 minutes)

proof 62 at 2026-09-28T07:08:07Z: OPERATIONAL · 4/4 replicas, agreement yes · write committed at sequence 610 with a quorum certificate signed by 3 members (atl, lax, sjc), verified: True

signed proof · verify the whole chain

Operational proof (every 30 minutes)

proof 69 at 2026-09-28T07:23:09Z: OPERATIONAL · 4/4 replicas, agreement yes · write committed at sequence 17773 with a quorum certificate signed by 3 members (atl, lax), verified: True

signed proof · verify the whole chain

Live soak (running, updated hourly by the soak itself)

checkpoint 33 at 2026-09-28T06:42:10Z · 33.045 of 72.0 h · height 17427 · 16334 committed, 102 refused · 93 replica kills / 93 restarts · divergences 0 · anomalies 0 · MCPGate authorization enforced (ALLOW + refused replay)

signed checkpoint · verify all checkpoints

2026-09-28 — L5 agent identity & authority: an independent verifier refuses 25 attack classes; all evidence is now on all three sites

Every claim's evidence, on every site, independently checked. The two evidence roots were mirrored so all 919+ files and 63+ bundles of published proof are served identically by cainstudio.online, mcpgate.online and clawx.click (cross-site one-root-only: 443 → 0). The signed claims registry, the full public evidence inventory, the signed machine index and the one-command verifier are linked from the evidence pages, and verify_all.py re-derives every claim's artifact SHA-256 from all three sites (186/186). signed claims registry · full public evidence inventory · signed machine index · verify it yourself

Independent authority verifier (Prompt 2, Part 41). A clean-room verifier that imports nothing from CAIN independently re-derives RFC-8785 canonical JSON, domain-separated Ed25519 signatures, expiration, revocation, delegation scope, authority intersection, policy binding and action binding for AgentIdentity, AuthorityGrant, DelegationGrant and AuthorizationDecision. It refuses forged, altered, replayed, expired, revoked and key-substituted identities; scope expansion and constraint widening through delegation; delegation depth and delegations outliving their parent; expired/revoked grants, trust-floor bypass and policy downgrade; self-authorization, policy-scope escape, action substitution, cross-tenant access, single-use token replay and over-authorization. Running it on a signed valid bundle returns VALID; on a tampered bundle it returns INVALID and the reason codes. the verifier · worked example · the tampered bundle it rejects

Independently verified from more than one source (2026-09-28). The published evidence is re-verified by five independent verifier implementations that share no code — verify_all.py (every claim and artifact, from all three sites), two separately-written clean-room L5 authority verifiers (verify_authority_bundle.py and verify_authority_bundle_engine_b.py, both VALID on the same bundle), verify_l5_bundle.py, and the multi-source driver's own registry check — and they all agree. multi-source verification report · transcript · run it yourself. Scope: this is multi-implementation verification by the same project; no third party has reviewed CAIN-42 and it is not a certification.

Honest status: INCOMPLETE, not A+. The verifier is self-attested (same operator; no third party, same as every other bundle here). The L5 identity/authority runtime layer in cain45/l5 is owned by a separate session and is not claimed here. Performance is NOT_VERIFIED. The bypass report declares messaging and email NOT_IMPLEMENTED and the secrets broker NOT_IMPLEMENTED, and states the unconfined-process (RAW) gap: a process that does not route through CAIN or MCPGate is not seen. conformance report (PASS/INCOMPLETE/NOT VERIFIED) · bypass report (Part 27) · forensic inventory

2026-09-28 — L5 identity & dynamic authority runtime: 90 tests, 30 executable invariants, two clean-room verifiers (both VALID)

The runtime layer behind the independent verifier. cain45/l5/ now implements a first-class signed, versioned AgentIdentity (model/runtime identity, owner, policy binding, key lifecycle: create/rotate/revoke/reissue, signed identity statements) and a dynamic authority fabric: capability-scoped, resource-scoped, operation-scoped AuthorityGrants with temporal bounds, trust floors, budgets, environment and policy binding; non-escalating DelegationGrants that cannot expand capability, resource or time and cannot outlive their parent; and explainable AuthorizationDecisions with machine-readable reason codes (DENY_INSUFFICIENT_AUTHORITY, DENY_EXPIRED_GRANT, DENY_TRUST_BELOW_FLOOR, DENY_DELEGATION_DEPTH, DENY_REPLAY, ...). Authority is the deterministic intersection of the narrowest valid constraints — never an average.

Enforcement. The L5 boundary is wired restriction-only into the Agent Hypervisor and MCPGate: an L5 ALLOW is "no additional restriction", and an L5 decision can never loosen a hypervisor or MCPGate denial. Caller↔subject authentication closes the "caller-supplied agent string" gap: a caller must present a signed assertion from a registered caller identity whose subject equals the principal it claims. The hosted gateway service (platform-gateway/cain_l5_gateway.py) and the /l5/* API (agents, authority, delegation, authorize, explain, audit, conformance) are opt-in via CAIN_L5_GATEWAY=1 and fail closed when enabled without registered credentials.

Evidence — reproduce it yourself. 90 new tests pass (49 constitution + 11 wiring + 5 gateway + 20 identity/authority + 5 soak/verifier), with 206 more passing across the hypervisor/MCPGate regression group. The kernels expose 30 executable invariants (20 L5 safety + 10 identity/authority) and all hold. Two clean-room verifiers that import nothing from CAIN return VALID: verify_l5_bundle.py (10/10) and verify_authority_bundle.py (22/22), the latter independently re-deriving canonical JSON, signatures, expiration, revocation, delegation scope, authority intersection, policy binding and action binding. A 3,000-step long-horizon soak records 0 governance violations. Measured: L5 gate 53.6µs/op ALLOW, 45.3µs/op DENY.

Bugs the suites caught and fixed. The identity/authority attack tests found and closed three real defects before shipping: single-use token replay was not detected when the nonce was reused; delegation narrowing was not applied to evaluation (a delegate could reach resources outside its delegated scope); and revocation mutated the signed grant body, invalidating its signature (revocation is now an external registry fact).

Honest status: INCOMPLETE, not L5. The runtime is a TESTED library; hosted enforcement is opt-in and not yet the default path. No real (non-scripted) LLM agent is governed end-to-end; no hardware root of trust; one provider; no third-party review. The repository-wide bypass audit found 57 ungoverned consequential paths (e.g. cain/guard.py falls back to local evaluation; cain/mcp_proxy.py swallows trajectory-gate exceptions) — documented, not hidden. No L5 claim is made.

2026-09-28 — Independent verification: three clean-room verifiers, both evidence roots, all VALID

What was verified. Three verifier implementations that share no code and import nothing from CAIN independently re-derive canonical JSON, Ed25519 signatures, the trajectory hash chain and its RFC-6962-style Merkle root, delegation non-escalation, authority intersection, policy/action binding and the invariant matrices. All three return VALID against the published bundles: verify_l5_unified.py (22/22), verify_authority_bundle.py (22/22) and verify_l5_bundle.py (10/10). The signed artifacts and the verifiers are published on both evidence roots so either site can be checked by hand. reproduce it with one command · manifest with per-file SHA-256 · the unified verifier (no CAIN imports) · the signed bundle

What this proves, and what it does not. It proves the artifacts are internally consistent and cryptographically sound under a verification implementation that shares no code with the runtime. It does not prove independent third-party review: the verifiers, the runtime and the operator are the same, on one host, with one provider, and no external party has reproduced it. So we do not claim CAIN-42 is "fully independently verified from more than one source" — that would be false today. What is true is narrower and checkable: multiple independent verifier implementations agree, on published signed artifacts. No L5 claim is made.

2026-09-28 — Six authority fabrics: intelligence may propose, only a quorum-certified decision authorizes

New governed libraries, none of which can authorize anything. A Trajectory Firewall hash-chains a long-horizon run and flags plan/authority drift, scope creep, privilege accumulation, tool/model/identity/memory substitution, stale authorization, delegated escalation and suspicious retries. Stopping Intelligence reaches STOP/WAIT/REQUEST_APPROVAL/REPLAN/ROLLBACK/QUARANTINE/ESCALATE and can only ever make an action less permissive. A Swarm Authority Fabric keeps CHILD ≤ PARENT and SWARM ≤ POLICY, and treats unanimous agent votes as informational. A Governed Tool lifecycle makes discovery and creation grant NO AUTHORITY. A Governed Memory Fabric classifies every item, calibrates it, and cannot become policy. Resource Authority is time/scope/resource/policy/trajectory-bound, revocable and non-escalating. They encode one rule: LEARNING, PREDICTION, MEMORY, SIMULATION, DISCOVERY and AGENT CONSENSUS may change capability but never create execution authority. 419 new unit tests plus one executable Part XXVIII invariant matrix.

Limits. These six fabrics are TESTED unit libraries, not VERIFIED: no published independent evidence bundle exercises them, and they are not wired into the hosted enforcement path. The world model is tabular, not neural; the memory is not a vector store. The hosted runtime remains PRE_PRODUCTION. see every claim's evidence and limits

2026-09-28 — Governed policy evolution: learning can propose, only the cluster and a human can authorize

Policy changes are governed. A tenant's policy (which capabilities a ZoD may hold, the largest budgets it may get) now becomes active only when the live cluster cain-mr-01 commits its activation. Widening it needs a registered human who is not the proposer; narrowing it needs no one, because authority may always go down. On the live cluster: an agent's first policy was approved by a human and activated (QC 16148); the agent then proposed an expansion and approved it itself — refused, and the cluster was never asked; a failure lab's restriction was activated (QC 16151) and a running ZoD lost its authority on its next call; a ZoD above the ceiling was refused. verify: python3 verify_e8_governance.py . -> 19/19 checks, VERIFIED

Predictions, simulations, agent votes and memories are not authority. Four things an intelligent system produces were presented to the hypervisor as the basis for a ZoD: a world-model prediction with 0.99 confidence, a simulated ALLOW citing a real certified sequence, ten agents' unanimous signed vote, and a memory replaying a real decision with the verdict changed. Each was refused because the live cluster had not certified it; across the run exactly one ZoD was ever authorized.

Limits. Scripted identities, not a real LLM agent. CAIN does not contain a world model, digital twin or learning memory: the run shows their outputs cannot become authority. The governor runs as a library on the gateway host. The registry now also names seven older files on the sites whose self-asserted statuses (CERTIFIED, PRODUCTION_HARDENED, OPERATIONAL_PROVEN...) no evidence supports; they stay for history, marked superseded.

2026-09-28 — Fail-open defects found and fixed; the authority check is no longer quadratic

Four ways authority could survive what should end it, found by an independent probe, all fixed. Moving the clock back revived an expired grant (now: a stored time high-water mark refuses a clock that goes backwards). A tool could run while the evidence log was unwritable (now: the intent is recorded before the effect, so no log means no execution). A failing trust service, and a cluster that errored during authorization, raised instead of refusing (now: recorded refusals). Tests: 4 former gaps now pass, and fail on the previous code.

Faster. Every action re-verified every signature since the ZoD began. Now each entry is re-hashed but its signature verified once: gate p50 with 100 ZoDs in the store went from 113 ms to 18.7 ms (1,000 ZoDs: 36 ms; p99 about 0.3 s). Measured on the gateway host.

Limits. Library-level fixes in the hypervisor on the gateway host; the p99 tail is not yet explained.

2026-09-28 — Authority lapses on policy change, cluster membership/epoch change and spent risk/blast-radius budgets

Evolution #7: the five conditions Evolution #6 left open, on live authority. Every ZoD was authorized by the live cluster cain-mr-01 (decision QC 15876, ZoD QCs 15880-15892), made one successful tool call, and was refused on the next call with the tool never running once: the policy root changed; the policy source became unreadable (unknown is refused, never read as unchanged); the risk budget was spent; the blast-radius budget was spent (actions now carry consequence classes C0 read to C4 security/infrastructure); and a delegate spent its parent's budget — delegates are charged up the whole chain, so splitting work across children cannot multiply authority. Each ZoD is bound to the cluster's real membership configuration (hash recomputed, a quorum of replicas agreeing), re-read before every action (36 live reads in this run); a changed epoch, a changed membership and an unreachable cluster were each refused. Also fixed: a retry after a replica committed but timed out used to be refused as 'not committed'; the client now takes the committed sequence from the replica's cached reply and accepts it only if that certificate verifies over the exact request. verify: python3 verify_e7_lease.py . -> 60/60 checks, VERIFIED

Limits. Stated, not hidden: the three membership/epoch changes were INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real. Enforcement is the hypervisor library on the gateway host. Only tool-call budgets were exercised live.

2026-09-28 — Agent Hypervisor (ZoD) authorized by the live cluster; authority leases that expire, revoke and cascade

Agent Hypervisor / ZoD runtime, authority from the live cluster. An agent never holds execution authority; it acts only inside a ZoD (Zone of Decision), and only after the live 4-server cluster cain-mr-01 has committed that ZoD's authorization with a quorum certificate (3 of 4 Ed25519 signatures) that the hypervisor checks itself. Code runs under real confinement (bubblewrap namespaces + cgroup v2, no network, host tree invisible). Two ZoDs were authorized at cluster sequences 13379 and 13380; 10 attacks were refused, each as a signed DENIED entry; 45 evidence entries, hash-chained. verify: python3 verify_cain45_zod.py . -> 10 PASS, VERIFIED (about 0.3 s)

Authority leases, tripped live (Evolution #6). A ZoD is a temporal authority lease. For each of 9 conditions a fresh ZoD was authorized by cain-mr-01 (decision QC 15746, lease QCs 15748-15759), one tool call succeeded under that live authority, the condition was tripped, and the next call was refused with the tool never running: TTL expiry, trust below floor, agent identity swapped, tool schema changed (rug-pull), security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority with it), required evidence deleted. Four of these were holes found and closed this release: before the fix a child ZoD kept acting after its parent was quarantined, a tool whose schema changed after authorization was still called, a re-registered (swapped) agent identity kept acting, and deleting the evidence log did not stop execution. verify: python3 verify_e6_lease.py . -> 48/48 checks, VERIFIED

Limits. Stated, not hidden: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes; what comes from the cluster is the authority being invalidated. The evidence-deletion row is SELF-REPORTED: its result is signed by the run's hypervisor, but the log that would prove it is the one deleted. Not implemented yet: invalidation on policy, epoch or membership change, risk and blast-radius budgets. A separate 4-node 'authoritative state' layer in the code is SIMULATED (one process holds all 4 keys) and is not used for any of this evidence. seccomp, egress allowlists and hardware attestation are not established.

2026-09-27 — Verify your own decision records offline; disk and memory monitoring

Customers can now export any of their decisions exactly as stored and signed (GET /fabric/decisions/{id}/signed-record) and verify it offline with the published verifier, which contains no CAIN code. New disk and memory watcher on all four servers, after /tmp filled up on the Atlanta server; every server is currently below 80% disk use.

Verifier and worked example

2026-09-27 — Gate X: every hosted decision record is signed

Every hosted decision record is now Ed25519-signed by a key kept outside the database, so an edit is detectable even if its digest is recomputed; that covers the stages after consensus and the final verdict. Public key at /fabric/decision-signing-key. Verified live. Not covered: root on the gateway server. Gate X PASS (5 of 9).

Decision signing key

2026-09-27 — 13 test failures fixed; tampered-evidence flag traced and corrected

The previous full run's 13 test failures traced and fixed without weakening a check (latest run: 5453 passed; its remaining failures belong to a change still in progress). The Verification Center correctly flagged one claim as TAMPERED: a soak verifier had been overwritten after signing. The signed bytes are restored and the fix is published as v2. That soak's real outcome is recorded: it stopped at 24 of 72 hours and its verifier returns FAIL. The daily signed sync now measures the live 4-region cluster.

Soak verifier update and outcome · llms.txt

2026-09-27 — Storage-loss recovery, live MCPGate enforcement, hosted certificate check, formal models

Two-replica storage loss, rebuilt from off-host backups. On the live 4-server cluster, the Miami and Silicon Valley replicas lost their storage at the same time and were rebuilt only from backups held in other regions. While both were down the cluster committed 0 of 4 writes; afterwards 0 decisions were lost and all four were identical 10.3 s after restart. verify 416 certificates

MCPGate enforcing live consensus. Authorizations committed by the live 4-server cluster; every tool call went over HTTP through the MCPGate proxy to a separate MCP server process. 5 authorized calls ran (per the server's own log); 12 attacks were blocked, and each caller received the gate's signed denial. verify with one command

Hosted decisions: the gateway now checks the quorum certificate itself. Security fix: the hosted consensus stage used to accept a replica's word that a decision was committed, so one lying replica could have authorized a decision with no quorum. The gateway now verifies 3 pinned Ed25519 signatures over the digest it computes for that decision, and shows the check on every decision. verify a decision yourself

Formal models checked. TLA+ models of the PBFT commit/view-change rules and of the MCPGate gate, checked exhaustively by TLC: 0 violations in 7.3 million distinct states, and all 8 deliberately broken variants caught. An earlier run had been recorded as incomplete because the checker stopped at the model's normal end state; fixed. models and results

Claims registry rebuilt from current evidence. 24 signed claims. It had still said one host and no formal verification, and still called the failed single-host 72-hour soak 'in progress'; it now records that soak as FAILED and the multi-region soak as running. Gates: 14 of 15 (A-O) and 3 of 9 (P-X); hardware attestation is blocked (no TPM, SEV or TDX on any server). verify the registry

One-way network partitions. On the live 4-server cluster: a replica that can talk but not listen, a one-way link between two backups, and a replica that can listen but not talk. The cluster kept committing in each case, went through view changes, and all four replicas held identical decision chains after each heal. verify 968 certificates

Daily restore validation. Every day each replica's newest off-host backup (8 replicas, 2 clusters) is fetched from the server in another region that holds it and proven to be a quorum-signed prefix of the live history; tampered backups fail even with a re-hashed manifest. verify

Signed evidence index for crawlers and AI agents. /cain42-evidence-index.json on all three sites: every claim with its status, limits, artifact hashes and verification command, every gate, and the live endpoints, generated from the signed registry and signed with the evidence-root key; llms.txt carries the same, generated. claims registry

Degraded network: safe, but slow. 10% packet loss, 120±40 ms jitter, 5% duplication and reordering on all four replicas of the live 4-server cluster for 4 minutes: no fork, but throughput fell from 1.76 to 0.16 commits/s and 22 of 61 writes timed out; it recovered fully afterwards. The evidence publisher now runs the privacy firewall before anything reaches the sites (a bundle was briefly public with an internal subnet in its description). verify 2,728 certificates

Engine 948b189 on the 4-server cluster: fewer view changes, same throughput under loss. View-change backoff now resets only when a view commits, and a fresh view is not accused. Released reproducibly (two independent builds, identical image ID; signed release manifest 17/17), upgraded replica by replica under live traffic (each caught up in 11-31 s, no quarantines). Re-running the same degraded-network test: view changes fell from 14 to at most 6, but throughput under 10% loss stayed about the same (0.16 -> 0.18 commits/s). The storm was not the bottleneck; message delivery under loss is. Safety held (4,448 certificates, no fork). before/after, verify 4,448 certificates

2026-09-27 — SDK guard is now default-deny

The self-hosted SDK and MCP proxy now hold any undeclared action for approval instead of allowing it. Authorized tools are declared with guard(allow=[...]), allowed_tools=[...] or CAIN_ALLOWED_ACTIONS. Opting out (CAIN_UNKNOWN_ACTION_POLICY=allow) is explicit and recorded on every decision. 1516 dependent tests pass.

2026-09-27 — Per-customer enforcement; reproducible 4-server release; audit fixes

Free shadow mode for every customer; paid plans can switch themselves to enforce mode (POST /fabric/settings). The 4-server cluster's image was reproduced exactly by two independent builds (signed manifest 17/17). SDK allowlists and opt-in default-deny. Audit fixes applied. 13 of 15 gates pass.

Release manifest

2026-09-27 — Four servers, four regions: any single server can fail

cain-mr-02 runs one replica on each of Atlanta, Los Angeles, Miami and Silicon Valley. Every server was taken offline in turn, and it kept committing each time (6/6, with a leader change each time). With two down it refused. 264 certificates, 40/40. Only the provider (Vultr) remains a single point of failure. 12 of 15 gates pass.

Verify the four-server cluster · Computed resilience

2026-09-26 — Bit-for-bit reproducible builds; off-host backups

Two independent from-scratch builds of one commit gave the same image ID, with every layer identical. Backups are also stored on another region's host. The live cluster moves to the reproducible image after the soak.

Reproducibility evidence

2026-09-26 — Byzantine replicas handled across three regions; proof every 30 minutes

A forging replica's votes were rejected everywhere (6/6 committed). An equivocating primary was proven from its own signatures, quarantined by all 3 honest replicas and replaced (6/6 committed). 29/29 checks. This ran on a disposable cluster with the same placement. A signed operational proof is published every 30 minutes. The test suite is fully green (870/0), including a fixed approval-workflow bug. 11 of 15 gates pass.

Verify the Byzantine tests · Verify the operational proofs

2026-09-26 — Signed release manifest; published test report

Same image on every host; 1,461 image files byte-identical to the commit; 47-package SBOM; Ed25519-signed (verifier 16/16). Tests: 865 passed, 4 failed; the failures predate this work and are listed by name.

Release manifest · Test report

2026-09-26 — Network partitions on the live cluster; operational drill

With Miami cut off, the other three committed 6/6 and the isolated replica committed nothing. In a 2|2 split neither side committed, so there was no split brain. All four agreed within about 3 s of each heal (2,960 certificates, 32/32). The anti-entropy fix (81bdf84) is rolled out live. Drill: rolling restart under writes 83/83 with 0 failures; disk-loss rebuild in 13.6 s. 7 of 15 production gates pass.

Verify the partition run · Verify the drill · Verify the restore (8.3 s, 0 lost)

2026-09-26 — Live drill: a real defect found and fixed; production gates published

Every homepage lists the fifteen production gates with evidence links (5 of 15 pass today) and a live cluster-state line. A load test on the live cluster exposed a real defect: a replica signed after losing primacy and accused honest peers with a mismatched-signer proof. Safety held. Fixed in 9fedb49 with tests and rolled out live the same day as a rolling upgrade; all four replicas agree. Also: health endpoint, rolling upgrades, online backups.

Live cluster · Production gates

2026-09-26 — CAIN-42 PBFT cluster live in three regions

LIVE · VERIFIABLE

4 PBFT replicas on 3 hosts in Atlanta, Los Angeles and Miami over WireGuard (n=4, f=1, quorum 3). Fault injection on the live cluster: Miami down, 6/6 committed; one Los Angeles replica down, 6/6; whole Los Angeles host down, 0/3 (refused, as required); Atlanta and the primary down, view change, then 6/6. 336 certificates, 49/49 standalone checks. The signatures confirm that no decision taken during an outage was signed by a stopped replica. Scope: one operator, one provider; not yet in the hosted decision path.

Live cluster: watch, verify, audit, tamper · Verify the fault-injection run · REPRODUCE.txt

2026-09-24 — PBFT Evolution 2: quorum certificates you can verify in your browser

SELF-ATTESTED

Evolution 2 of the PBFT engine is committed (364f1bf). It adds up to 4 proposals in flight, a pacemaker that only sets timeouts and cannot authorize anything, and an AuthorizationCertificate that is valid only with a valid COMMIT quorum certificate and a request whose intent, proposal and action hashes match. It also fixes a real defect: the post-commit authorization proof hardcoded trust_state=HIGH and risk_state=LOW, which it never evaluated. It now says NOT_EVALUATED. Tests: 135/135 PBFT Evolution 1+2 and 167/167 wider Byzantine/cluster suites. Public evidence: a disposable 4-node cluster built from c188442 committed 20 decisions across a primary failover. All 160 quorum certificates are published with the signed votes, a standalone verifier that uses no CAIN code, and a page that checks them in your browser (29/29, including 7 tamper controls that must fail). MCPGate is not yet wired to consume the AuthorizationCertificate. The run used one host. Later the same day the live cain-vc cluster was upgraded to this build, node by node: state was preserved on all 4 nodes, a smoke write committed, and rollback copies were kept. Its first new decision's COMMIT and PREPARE certificates and AuthorizationCertificate verify on all 4 nodes. Its first two decisions predate certificates, so its history cannot be verified from genesis, and its API is not publicly reachable.

Verify the certificates · REPRODUCE.txt

2026-09-22 — Last-mile enforcement wired into a live route; infrastructure hardening

SELF-ATTESTED

Not production in the business sense: no customer traffic, same-operator infrastructure, no third-party review. What changed: cain_agi_control_boundary.ControlBoundary.submit_proposal() — the one pipeline here that calls MCPGateLastMileEnforcer (in-flight parameter-mutation defense) after issuing a signed Proof-Carrying Decision — was fully built and tested but reachable only from pytest before today; grepped every live route file for a reference and found none. Now live at /fabric/agi/propose (auth-gated, execution scoped to a small registered sandbox tool set).

AI_VERIFY.json

⭐ CAIN-42 Epoch 6: Autonomous World-State Integrity & Proof-Carrying Agency

RELEASE v42.1.0

Doctrine: COMPROMISED COGNITION ≠ COMPROMISED AUTHORITY ≠ COMPROMISED WORLD STATE — Consequential autonomy is continuously bound, observable, cryptographically evidenced, independently verifiable, and recoverable from cognition through real-world effect.

Observation ≠ Authority
Sensory inputs require quorum attestation and cannot elevate authority.
ActionProofObject (24 Fields)
24-field proof bound before MCPGate socket execution.
Closed-Loop Reconciliation
Tool return 0 is not success; postconditions verified against reality.
Clean-Room Verifier (AST Proven)
0 CAIN imports verifier checks RFC 8785 canonical JSON & RFC 6962 Merkle tree.
Download Master Bundle (.json) Epoch 6–9 Report (.md) Self-Critique (.md) Evidence Center
Loading changelog...