{
  "schema": "cain42.evolution14.proof.v1",
  "title": "CAIN-42 EVOLUTION-14-PROOF -- Governed Capability, Skill & Tool Supply-Chain Fabric",
  "generated_at": "2026-09-28T23:07:09+00:00",
  "commit": "3106ea9e1626871a44d15b879d1a864ca6846e6e",
  "bundle_name": "e14-capability-governance-2026-09-28",
  "modules": {
    "e14_capability": {
      "path": "cain45/l5/capability.py",
      "sha256": "7ddfefe8bb5dbb264af5d50a5c913c2e8f157784310931e2a535a1b030d5a959"
    },
    "e14_kernel_capability_bindings": {
      "path": "cain45/l5/kernel.py",
      "sha256": "e70cc8cd43d1a1f2a32f3aba7733298aea0cda19495676662091ec04d380b673"
    },
    "e14_hypervisor_capability_gate": {
      "path": "cain45/hypervisor.py",
      "sha256": "b184311ab8d82ae88262f4380818356bead241a851549cac8e33c62307b82ca0"
    },
    "e14_e13_bench_fix": {
      "path": "cain45/l5/decision.py",
      "sha256": "7a5d963b93fbba0d3ddc4981679c0caaccdbe566c5d724397bd7a2a4d0aad903"
    },
    "e14_control_plane": {
      "path": "cain45/l5/__init__.py",
      "sha256": "64156f70c30ff27d6d150436f56ffbd8260f13caede908b4570d4281b96366c2"
    },
    "e14_agent_cli": {
      "path": "scripts/cain45/cain_agent_cli.py",
      "sha256": "54928f453b739cc6f8388a42c6b969ba01351ef9543af1995dc91168774edac3"
    },
    "e14_l5_cli": {
      "path": "scripts/cain42_l5/cain_l5_cli.py",
      "sha256": "265e8c6cd63a7eb667f2b3b5adc038564145a1a4e5a9256f8a163e281bfb4fd1"
    },
    "e14_verifier": {
      "path": "scripts/cain45/verify_e14.py",
      "sha256": "1159acc0e6c07f1d625549567d0cfd2fa67648e080d976ea3b038ef0bf5448e7"
    }
  },
  "tests": {
    "tests/test_cain42_e14_capability.py": "a7ac1e54a557b89353501dfd8c0ae882ca6b8e960fd65c0d011aa5db232df28d",
    "tests/test_cain42_e14_adversarial.py": "812d2caa627ebdaeb43d34e266e79b0eed6d44d0bc134043612939d4f7f1ad39",
    "tests/test_cain42_e14_end_to_end.py": "4d9cd1f216c8a60067de204be6bc2e55eefa777b47df2f48408e6e93b9567e05"
  },
  "test_run": {
    "command": "python3 -m pytest tests/test_cain42_e14_capability.py tests/test_cain42_e14_adversarial.py tests/test_cain42_e14_end_to_end.py -q",
    "summary": "============================= 174 passed in 5.90s ==============================",
    "passed": 174,
    "failed": 0,
    "returncode": 0,
    "transcript_tail": [
      "tests/test_cain42_e14_capability.py .................................... [ 20%]",
      "........................................................................ [ 62%]",
      ".......                                                                  [ 66%]",
      "tests/test_cain42_e14_adversarial.py ................................... [ 86%]",
      ".............                                                            [ 93%]",
      "tests/test_cain42_e14_end_to_end.py ...........                          [100%]",
      "",
      "============================= 174 passed in 5.90s =============================="
    ]
  },
  "invariants": {
    "evolution": 14,
    "fabric": "cain42.l5.capability",
    "checks": [
      {
        "id": "C1",
        "invariant": "CAPABILITY IDENTITY IS DETERMINISTIC",
        "holds": true,
        "detail": "cap:ed104a4d9965c1d8"
      },
      {
        "id": "C2",
        "invariant": "CAPABILITY IDENTITY BINDS TO ITS ARTIFACT",
        "holds": true,
        "detail": "['CAPABILITY_ID_MISMATCH', 'MANIFEST_MISMATCH', 'ARTIFACT_SUBSTITUTION']"
      },
      {
        "id": "C3",
        "invariant": "CAPABILITY DISCOVERY DOES NOT AUTHORIZE EXECUTION",
        "holds": true,
        "detail": "CAPABILITY_NOT_ADMITTED:DISCOVERED"
      },
      {
        "id": "C4",
        "invariant": "TOOL TRUST DOES NOT EQUAL AUTHORITY",
        "holds": true,
        "detail": "['NO_CAPABILITY_LEASE']"
      },
      {
        "id": "C5",
        "invariant": "SKILL TRUST DOES NOT EQUAL AUTHORITY",
        "holds": true,
        "detail": "['NO_CAPABILITY_LEASE']"
      },
      {
        "id": "C6",
        "invariant": "PLUGIN TRUST DOES NOT EQUAL AUTHORITY",
        "holds": true,
        "detail": "['NO_CAPABILITY_LEASE']"
      },
      {
        "id": "C7",
        "invariant": "CAPABILITY GRANTS CANNOT EXCEED ISSUER AUTHORITY",
        "holds": true,
        "detail": "GRANT_EXCEEDS_ISSUER_AUTHORITY:CALL_MCP_TOOL:tool:kv.get"
      },
      {
        "id": "C8",
        "invariant": "DELEGATED CAPABILITY CANNOT EXCEED PARENT CAPABILITY",
        "holds": true,
        "detail": "CHILD_EXCEEDS_PARENT_CAPABILITY:READ_DATA:db"
      },
      {
        "id": "C9",
        "invariant": "CAPABILITY INTERSECTION CANNOT INCREASE AUTHORITY",
        "holds": true,
        "detail": "[['READ_DATA', 'db']]"
      },
      {
        "id": "C10",
        "invariant": "CAPABILITY LEASE IS BOUNDED IN TIME",
        "holds": true,
        "detail": "bounded"
      },
      {
        "id": "C11",
        "invariant": "CAPABILITY LEASE IS CRYPTOGRAPHICALLY BOUND",
        "holds": true,
        "detail": "['LEASE_SIGNATURE_INVALID', 'LEASE_SUBSTITUTED']"
      },
      {
        "id": "C12",
        "invariant": "MATERIAL CAPABILITY MUTATION INVALIDATES AFFECTED AUTHORIZATION",
        "holds": true,
        "detail": "('SUSPICIOUS_CHANGE', ['CAPABILITY_NOT_INVOKABLE:SUSPENDED', 'LEASE_REVOKED'])"
      },
      {
        "id": "C13",
        "invariant": "REVOKED CAPABILITY CANNOT AUTHORIZE EXECUTION",
        "holds": true,
        "detail": "['CAPABILITY_NOT_INVOKABLE:REVOKED', 'CAPABILITY_REVOKED', 'GRANT_REVOKED', 'LEASE_REVOKED']"
      },
      {
        "id": "C14",
        "invariant": "EXPIRED CAPABILITY CANNOT AUTHORIZE EXECUTION",
        "holds": true,
        "detail": "GRANT_EXPIRED"
      },
      {
        "id": "C15",
        "invariant": "UNKNOWN CAPABILITY STATE CANNOT AUTHORIZE EXECUTION",
        "holds": true,
        "detail": "['CAPABILITY_NOT_INVOKABLE:UNKNOWN', 'CAPABILITY_UNKNOWN', 'GRANT_UNKNOWN', 'LEASE_SIGNATURE_INVALID', 'LEASE_TTL_EXCEEDS_POLICY', 'LEASE_UNKNOWN']"
      },
      {
        "id": "C16",
        "invariant": "CAPABILITY COMPOSITION CANNOT SILENTLY BYPASS RISK GOVERNANCE",
        "holds": true,
        "detail": "COMPOSITION_DENY:SECRET_EXFILTRATION"
      },
      {
        "id": "C17",
        "invariant": "CAPABILITY CONSEQUENCES ENTER E7",
        "holds": true,
        "detail": "['CONSEQUENCE_DENY:financial=50000.0>=10000.0']"
      },
      {
        "id": "C18",
        "invariant": "CAPABILITY DECISIONS ENTER E13",
        "holds": true,
        "detail": "['DECISION_NOT_AUTHORIZING:DENIED', 'DECISION_SUBSTITUTION']"
      },
      {
        "id": "C19",
        "invariant": "CAPABILITY EXECUTION ENTERS E8",
        "holds": true,
        "detail": "EXECUTED"
      },
      {
        "id": "C20",
        "invariant": "CREDENTIALS CANNOT MINT AUTHORITY",
        "holds": true,
        "detail": "CREDENTIAL_IS_NOT_AUTHORITY"
      },
      {
        "id": "C21",
        "invariant": "SUBAGENTS CANNOT INHERIT UNLIMITED CAPABILITIES",
        "holds": true,
        "detail": "(('CALL_MCP_TOOL', 'tool:kv.get'),)"
      },
      {
        "id": "C22",
        "invariant": "COLLECTIVE CONSENSUS CANNOT CREATE CAPABILITY AUTHORITY",
        "holds": true,
        "detail": "CONSENSUS_REACHED"
      },
      {
        "id": "C23",
        "invariant": "MEMORY CANNOT CREATE CAPABILITY AUTHORITY",
        "holds": true,
        "detail": "AUTHORITY_CLAIM_UNTRUSTED"
      },
      {
        "id": "C24",
        "invariant": "MODEL OUTPUT CANNOT CREATE CAPABILITY AUTHORITY",
        "holds": true,
        "detail": "{'classification': 'CONTEXT_INPUT_TO_GOVERNANCE', 'authority': 'NONE', 'promotes_to_authority': False, 'digest': 'dcf2f3fb95323e5f69a594e86fd4266c7d925c1ced0d5d4147a643718415d8de'}"
      },
      {
        "id": "C25",
        "invariant": "TOOL OUTPUT CANNOT CREATE CAPABILITY AUTHORITY",
        "holds": true,
        "detail": "DATA"
      },
      {
        "id": "C26",
        "invariant": "PLUGIN UPDATES REQUIRE REVALIDATION",
        "holds": true,
        "detail": "('EXPECTED_CHANGE', 'ADMITTED')"
      },
      {
        "id": "C27",
        "invariant": "DEPENDENCY CHANGES CAN INVALIDATE CAPABILITY TRUST",
        "holds": true,
        "detail": "REVOKED"
      },
      {
        "id": "C28",
        "invariant": "CAPABILITY-TO-ACTION BINDING IS TAMPER RESISTANT",
        "holds": true,
        "detail": "(['ACTION_SUBSTITUTION'], ['CAPABILITY_LEASE_CHANGED', 'CAPABILITY_BINDING_DIGEST_UNVERIFIED'], ['CAPABILITY_DIGEST_UNVERIFIED', 'CAPABILITY_MANIFEST_DIGEST_UNVERIFIED'])"
      },
      {
        "id": "C29",
        "invariant": "REPLAYED CAPABILITY AUTHORIZATION IS REJECTED",
        "holds": true,
        "detail": "capability commit refused: nonce_replay=LEASE_REPLAY,TOKEN_REPLAY [record 63405a"
      },
      {
        "id": "C30",
        "invariant": "GOVERNANCE FAILURE FAILS CLOSED",
        "holds": true,
        "detail": "capability commit refused: governance=GOVERNANCE_ERROR:Attri"
      }
    ],
    "failed": [],
    "all_hold": true,
    "checked": 30
  },
  "attack_bench": {
    "bench": "CAIN-42-E14-Capability-Bench",
    "contained": 44,
    "total": 44,
    "all_contained": true
  },
  "schemas": [
    "ArtifactProvenance",
    "CapabilityConsequenceVector",
    "CapabilityCredentialBinding",
    "CapabilityDecisionBinding",
    "CapabilityGrant",
    "CapabilityLease",
    "CapabilityPassport",
    "CapabilityProposal",
    "CapabilitySandboxProfile",
    "DependencySpec",
    "GovernedCapability",
    "ToolManifest"
  ],
  "limitations": [
    {
      "limitation": "TESTED LIBRARY, NOT HOSTED SERVICE",
      "status": "INTERFACE READY",
      "evidence": "cain45.hypervisor capability_gate hook (restriction-only, fail-closed) runs before E7/E8 and the real MCPGate interceptor (cain.mcp_proxy); end-to-end test drives hv.call_tool through it",
      "test": "tests/test_cain42_e14_end_to_end.py",
      "note": "HOSTED_SERVICE = NOT_IMPLEMENTED: E14 is not wired into the hosted gateway on the three sites"
    },
    {
      "limitation": "NO FRAMEWORK ADAPTER",
      "status": "REDUCED",
      "evidence": "CapabilityAdapter contract + MCPProtocolAdapter (tools/list -> DISCOVERED capability with a schema-bound artifact digest; tools/call -> CanonicalAction)",
      "test": "tests/test_cain42_e14_capability.py::test_mcp_adapter_*",
      "note": "A2A, LangGraph, AutoGen, CrewAI, OpenAI Agents SDK adapters: NOT_IMPLEMENTED"
    },
    {
      "limitation": "HARDWARE ATTESTATION",
      "status": "INTERFACE READY",
      "evidence": "AttestationProvider interface; SoftwareConfigurationAttestationProvider implemented; TPM / TEE / SECURE_BOOT / CONFIDENTIAL_COMPUTING slots return NOT_IMPLEMENTED and admit nothing",
      "test": "tests/test_cain42_e14_capability.py::test_hardware_providers_are_honest_slots",
      "note": "HARDWARE_ATTESTATION = UNKNOWN (no hardware root of trust has been tested)"
    },
    {
      "limitation": "MULTI-HOST / SCALE",
      "status": "STILL UNKNOWN",
      "evidence": "PERFORMANCE.json: single host, single process (plus a single-host multi-process run)",
      "test": "scripts/cain45/build_evolution14_bundle.py measure()",
      "note": "MULTI_HOST_SCALE = UNVERIFIED; no multi-host run of E14 exists"
    },
    {
      "limitation": "THIRD-PARTY REPRODUCTION",
      "status": "INSTRUMENTED",
      "evidence": "REPRODUCE.txt + clean-room verifier with no CAIN imports",
      "test": "python3 verify_e14.py <bundle>",
      "note": "no independent party has reproduced it"
    },
    {
      "limitation": "SEMANTIC TRUTH",
      "status": "STILL UNKNOWN",
      "evidence": "HASH_INTEGRITY != SEMANTIC_TRUTH: digests prove what was bound, not that a tool behaves as its manifest says; behaviour-signature drift is only used where measured",
      "test": "-",
      "note": "E12 corroboration remains the only source-independence mechanism"
    },
    {
      "limitation": "E13 BENCH: 2 of 36 scenarios were forced true ('... or True')",
      "status": "ELIMINATED",
      "evidence": "trajectory_rollback and state_root_mismatch now exercise a cache that saw the later sequence / committed root; both genuinely contained",
      "test": "tests/test_cain42_e14_capability.py::test_e13_bench_rollback_and_state_root_scenarios_are_real",
      "note": "found by the E14 audit; the E13 bundle is rebuilt with the fix"
    },
    {
      "limitation": "E13 TEST VECTOR 'unknown_cannot_be_allowed' was a constant True",
      "status": "ELIMINATED",
      "evidence": "the vector now attempts UNKNOWN -> ALLOWED and records whether it is refused",
      "test": "scripts/cain45/build_evolution13_bundle.py _unknown_cannot_be_allowed",
      "note": "found by E14 audit"
    },
    {
      "limitation": "E8 token bindings for E9-E13 digests pass when the live value is absent (lenient)",
      "status": "REDUCED",
      "evidence": "the six E14 capability bindings are STRICT (absent live value -> *_UNVERIFIED refusal); the E9-E13 fields keep their existing lenient semantics to avoid changing earlier evolutions",
      "test": "cain45.l5.capability _c28 (CAPABILITY_DIGEST_UNVERIFIED)",
      "note": "E9-E13 fields: unchanged"
    },
    {
      "limitation": "E13 DecisionTrace includes every transition the fabric recorded ('... or True' filter)",
      "status": "STILL UNKNOWN",
      "evidence": "found by the E14 audit; the trace over-includes, it never omits",
      "test": "-",
      "note": "not changed in E14 (low severity; changing it alters E13 trace digests)"
    },
    {
      "limitation": "SANDBOX PROFILE ENFORCEMENT",
      "status": "INSTRUMENTED",
      "evidence": "profiles are evaluated by policy at lease/commit; confinement_mapping() states per control what cain45.confine enforces at OS level (cgroup cpu/memory, deny-all network, seccomp) and what is policy-evaluated only (allowlisted egress, per-path allowlists, browser/GUI/cloud/db)",
      "test": "tests/test_cain42_e14_capability.py::test_sandbox_*",
      "note": "not an OS sandbox by itself"
    },
    {
      "limitation": "VULNERABILITY INTELLIGENCE",
      "status": "STILL UNKNOWN",
      "evidence": "no vulnerability database is integrated; VULNERABILITY_INTELLIGENCE = UNKNOWN everywhere",
      "test": "tests/test_cain42_e14_capability.py::test_transitive_privilege_escalation_is_found",
      "note": "-"
    },
    {
      "limitation": "POLICY CONFLICTS / COUNTERFACTUALS / PRIVATE REASONING (from E13)",
      "status": "STILL UNKNOWN",
      "evidence": "unchanged by E14: deterministic precedence (not a prover), bounded counterfactuals, no chain-of-thought read or stored",
      "test": "-",
      "note": "out of E14 scope"
    }
  ],
  "performance_summary": {
    "capability_registration_cold_fabric": 1426.52,
    "manifest_canonicalization": 41.67,
    "provenance_validation": 152.67,
    "dependency_graph_lookup": 397.81,
    "grant_evaluation": 145.73,
    "lease_issuance": 424.91,
    "lease_validation": 577.38,
    "revocation_lookup": 0.28,
    "capability_composition_10_caps": 6.42,
    "capability_drift_detection": 5.37,
    "sandbox_policy_evaluation": 2.07,
    "capability_action_binding_18_checks": 1815.85,
    "replay_verification": 716.65
  },
  "status": {
    "E14": "TESTED",
    "HOSTED_SERVICE": "NOT_IMPLEMENTED",
    "HARDWARE_ATTESTATION": "UNKNOWN",
    "VULNERABILITY_INTELLIGENCE": "UNKNOWN",
    "MULTI_HOST_SCALE": "UNVERIFIED",
    "THIRD_PARTY_REPRODUCTION": "NOT_PERFORMED",
    "FRAMEWORK_ADAPTERS": {
      "MCP": "IMPLEMENTED (protocol-level reference adapter, tools/list + tools/call)",
      "A2A": "NOT_IMPLEMENTED",
      "LangGraph": "NOT_IMPLEMENTED",
      "AutoGen": "NOT_IMPLEMENTED",
      "CrewAI": "NOT_IMPLEMENTED",
      "OpenAI Agents SDK": "NOT_IMPLEMENTED"
    },
    "SEMANTIC_TRUTH": "HASH_INTEGRITY != SEMANTIC_TRUTH",
    "OUTSIDE_THE_BOUNDARY": "UNCONTROLLED / UNVERIFIED / UNKNOWN"
  },
  "signing_key": {
    "class": "EPHEMERAL",
    "algorithm": "Ed25519",
    "public_key_b64": "GGgbKjgMkklw7dEcvdEK9c7wmgu7qsNFz9RPYJ4ko50=",
    "note": "generated for this build only and discarded; not a production trust root"
  },
  "chain": [
    "E9 AGENT IDENTITY",
    "E10 COLLECTIVE GOVERNANCE",
    "E11 INTENT / COMMUNICATION",
    "E12 PERCEPTION / EVIDENCE",
    "E13 GOVERNED COGNITION / DECISION",
    "E14 CAPABILITY / SKILL / TOOL GOVERNANCE",
    "E7 CONSEQUENCE GOVERNANCE",
    "E8 ACTION COMMIT BOUNDARY",
    "GOVERNANCE AUTHORIZATION TOKEN",
    "MCPGATE",
    "EXECUTION",
    "EVIDENCE"
  ],
  "laws": [
    "A CAPABILITY IS A POWER SURFACE",
    "DISCOVERY != TRUST != AUTHORITY != AUTHORIZATION",
    "A TOOL / SKILL / PLUGIN / MODEL / CREDENTIAL IS NOT AUTHORITY",
    "EFFECTIVE CAPABILITY IS AN INTERSECTION, NEVER A SUM",
    "UNVERIFIED POWER MUST NOT EXECUTE"
  ],
  "evidence_level": "TESTED",
  "environment_class": "operator host, single process, pre-production",
  "signer_public_key_b64": "GGgbKjgMkklw7dEcvdEK9c7wmgu7qsNFz9RPYJ4ko50=",
  "signature_b64": "4EKBU5rkziZ5pt/HIqOCWpv7KfFBCHMicMEYoAMNVcqU9W4xTQKpJ79CKGXdp7xNYnIKsqIWXOJZEOHRV29dBg=="
}
