# Evolution 14 limitations (classified)

| Limitation | Status | Evidence | Test | Note |
|---|---|---|---|---|
| TESTED LIBRARY, NOT HOSTED SERVICE | **INTERFACE READY** | cain45.hypervisor capability_gate hook (restriction-only, fail-closed) runs before E7/E8 and the real MCPGate interceptor (cain.mcp_proxy); end-to-end test drives hv.call_tool through it | `tests/test_cain42_e14_end_to_end.py` | HOSTED_SERVICE = NOT_IMPLEMENTED: E14 is not wired into the hosted gateway on the three sites |
| NO FRAMEWORK ADAPTER | **REDUCED** | CapabilityAdapter contract + MCPProtocolAdapter (tools/list -> DISCOVERED capability with a schema-bound artifact digest; tools/call -> CanonicalAction) | `tests/test_cain42_e14_capability.py::test_mcp_adapter_*` | A2A, LangGraph, AutoGen, CrewAI, OpenAI Agents SDK adapters: NOT_IMPLEMENTED |
| HARDWARE ATTESTATION | **INTERFACE READY** | AttestationProvider interface; SoftwareConfigurationAttestationProvider implemented; TPM / TEE / SECURE_BOOT / CONFIDENTIAL_COMPUTING slots return NOT_IMPLEMENTED and admit nothing | `tests/test_cain42_e14_capability.py::test_hardware_providers_are_honest_slots` | HARDWARE_ATTESTATION = UNKNOWN (no hardware root of trust has been tested) |
| MULTI-HOST / SCALE | **STILL UNKNOWN** | PERFORMANCE.json: single host, single process (plus a single-host multi-process run) | `scripts/cain45/build_evolution14_bundle.py measure()` | MULTI_HOST_SCALE = UNVERIFIED; no multi-host run of E14 exists |
| THIRD-PARTY REPRODUCTION | **INSTRUMENTED** | REPRODUCE.txt + clean-room verifier with no CAIN imports | `python3 verify_e14.py <bundle>` | no independent party has reproduced it |
| SEMANTIC TRUTH | **STILL UNKNOWN** | HASH_INTEGRITY != SEMANTIC_TRUTH: digests prove what was bound, not that a tool behaves as its manifest says; behaviour-signature drift is only used where measured | `-` | E12 corroboration remains the only source-independence mechanism |
| E13 BENCH: 2 of 36 scenarios were forced true ('... or True') | **ELIMINATED** | trajectory_rollback and state_root_mismatch now exercise a cache that saw the later sequence / committed root; both genuinely contained | `tests/test_cain42_e14_capability.py::test_e13_bench_rollback_and_state_root_scenarios_are_real` | found by the E14 audit; the E13 bundle is rebuilt with the fix |
| E13 TEST VECTOR 'unknown_cannot_be_allowed' was a constant True | **ELIMINATED** | the vector now attempts UNKNOWN -> ALLOWED and records whether it is refused | `scripts/cain45/build_evolution13_bundle.py _unknown_cannot_be_allowed` | found by E14 audit |
| E8 token bindings for E9-E13 digests pass when the live value is absent (lenient) | **REDUCED** | the six E14 capability bindings are STRICT (absent live value -> *_UNVERIFIED refusal); the E9-E13 fields keep their existing lenient semantics to avoid changing earlier evolutions | `cain45.l5.capability _c28 (CAPABILITY_DIGEST_UNVERIFIED)` | E9-E13 fields: unchanged |
| E13 DecisionTrace includes every transition the fabric recorded ('... or True' filter) | **STILL UNKNOWN** | found by the E14 audit; the trace over-includes, it never omits | `-` | not changed in E14 (low severity; changing it alters E13 trace digests) |
| SANDBOX PROFILE ENFORCEMENT | **INSTRUMENTED** | profiles are evaluated by policy at lease/commit; confinement_mapping() states per control what cain45.confine enforces at OS level (cgroup cpu/memory, deny-all network, seccomp) and what is policy-evaluated only (allowlisted egress, per-path allowlists, browser/GUI/cloud/db) | `tests/test_cain42_e14_capability.py::test_sandbox_*` | not an OS sandbox by itself |
| VULNERABILITY INTELLIGENCE | **STILL UNKNOWN** | no vulnerability database is integrated; VULNERABILITY_INTELLIGENCE = UNKNOWN everywhere | `tests/test_cain42_e14_capability.py::test_transitive_privilege_escalation_is_found` | - |
| POLICY CONFLICTS / COUNTERFACTUALS / PRIVATE REASONING (from E13) | **STILL UNKNOWN** | unchanged by E14: deterministic precedence (not a prover), bounded counterfactuals, no chain-of-thought read or stored | `-` | out of E14 scope |
