{
  "generated_at": "2026-09-28T23:07:20+00:00",
  "commit": "3106ea9e1626871a44d15b879d1a864ca6846e6e",
  "modules": {
    "e7_world_state": {
      "path": "cain45/l5/world_state.py",
      "sha256": "9d03e69030fc26b5d97b0346b935325032671304478afdfa9e61ba596601e574"
    },
    "e7_consequence": {
      "path": "cain45/l5/consequence_governance.py",
      "sha256": "175a7ead84aafa96a15764b822ce971dd487a49e141b63c2e90411e3b1ca4503"
    },
    "e8_kernel": {
      "path": "cain45/l5/kernel.py",
      "sha256": "e70cc8cd43d1a1f2a32f3aba7733298aea0cda19495676662091ec04d380b673"
    },
    "e8_hypervisor_wiring": {
      "path": "cain45/hypervisor.py",
      "sha256": "b184311ab8d82ae88262f4380818356bead241a851549cac8e33c62307b82ca0"
    }
  },
  "tests": {
    "tests/test_cain42_e7_world_state.py": "162c16d45a97ef34b5d2249a0bca9369cff923327f66726f2108d745716e61a6",
    "tests/test_cain42_e8_kernel.py": "d273d156af92b89c8103d7bd5e17263f2dce5ce804ca391532eac4e152cdb3a1",
    "tests/test_cain42_e7_e8_wiring.py": "98cd8d8e4feef91f5ad9b7c1324e1c65d7728b00789859006b05d6304cabcd54",
    "tests/test_cain42_e7_e8_end_to_end.py": "c6cd5a2bebce37a350a1f181ddc365b48085fb7ef2c8342f89194e48d37bd70b"
  },
  "test_run": {
    "command": "python3 -m pytest tests/test_cain42_e7_world_state.py tests/test_cain42_e8_kernel.py tests/test_cain42_e7_e8_wiring.py tests/test_cain42_e7_e8_end_to_end.py -q",
    "summary": "============================== 65 passed in 1.61s ==============================",
    "passed": 65,
    "failed": 0,
    "returncode": 0,
    "transcript_tail": [
      "============================= test session starts ==============================",
      "collected 65 items",
      "",
      "tests/test_cain42_e7_world_state.py ...........................          [ 41%]",
      "tests/test_cain42_e8_kernel.py ........................                  [ 78%]",
      "tests/test_cain42_e7_e8_wiring.py ......                                 [ 87%]",
      "tests/test_cain42_e7_e8_end_to_end.py ........                           [100%]",
      "",
      "============================== 65 passed in 1.61s =============================="
    ]
  },
  "limitations": [
    "TESTED, not hosted: the fabric and kernel are libraries on the operator host; they are not services.",
    "The consequence gate and the kernel boundary are wired RESTRICTION-ONLY into the CAIN-45 hypervisor; they can add a refusal, never grant or loosen authority.",
    "The world state is the state an observer reports, not ground truth: every element carries its source, freshness, confidence, provenance and verification status.",
    "The digital twin is not a high-fidelity infrastructure twin and has no validated error bound.",
    "Long-horizon simulation depth is not reliability; uncertainty is tracked and contracts authority.",
    "Enforcement depth is APPLICATION/RUNTIME/CONTAINER, never OS or HARDWARE on this host.",
    "Prediction errors raise uncertainty; an agent-reported 'match' can never lower it.",
    "No hosted API surface is exposed for these fabrics; they are libraries plus a restriction-only hook. The CLI is `cain l5 e7-audit` / `e8-audit` / `e7e8-bundle` / `e7e8-verify`.",
    "No third party has reviewed these artefacts; the clean-room verifier shares no CAIN imports but was written by the same operator."
  ],
  "bundle_name": "e7-e8-predictive-kernel-2026-09-28",
  "signer": {
    "algorithm": "Ed25519",
    "public_key_b64": "md8Q1sFxicNp/95NjN8Bp8qTK03i9Cc5p+POmuUWJos=",
    "warning": "ephemeral key generated at build time; not a long-term identity"
  },
  "schema": "cain42.evolution8.proof.v1",
  "title": "CAIN-42 EVOLUTION-08-PROOF -- Mandatory Agent Governance Kernel",
  "invariants": {
    "evolution": 8,
    "kernel": "cain42.l5.kernel",
    "checks": [
      {
        "id": "K1",
        "invariant": "NO VALID AUTHORIZATION -> NO GOVERNED EXECUTION",
        "holds": true,
        "detail": "DENIED"
      },
      {
        "id": "K2",
        "invariant": "AUTHORIZATION CANNOT BE REPLAYED OUTSIDE ITS WINDOW",
        "holds": true,
        "detail": [
          "TOKEN_REPLAY",
          "TOKEN_SEQUENCE_REPLAY"
        ]
      },
      {
        "id": "K3",
        "invariant": "AUTHORIZATION CANNOT BE TRANSFERRED BETWEEN AGENTS",
        "holds": true,
        "detail": [
          "ACTION_PARAMETER_MISMATCH",
          "WRONG_AGENT"
        ]
      },
      {
        "id": "K4",
        "invariant": "AUTHORIZATION CANNOT BE USED FOR DIFFERENT PARAMETERS",
        "holds": true,
        "detail": [
          "ACTION_PARAMETER_MISMATCH"
        ]
      },
      {
        "id": "K5",
        "invariant": "CAPABILITY MUTATION INVALIDATES AFFECTED AUTHORIZATION",
        "holds": true,
        "detail": [
          "CAPABILITY_ROOT_MISMATCH"
        ]
      },
      {
        "id": "K6",
        "invariant": "POLICY MUTATION INVALIDATES AFFECTED AUTHORIZATION",
        "holds": true,
        "detail": [
          "POLICY_CHANGED"
        ]
      },
      {
        "id": "K7",
        "invariant": "REVOKED AUTHORITY CANNOT EXECUTE",
        "holds": true,
        "detail": [
          "TOKEN_REVOKED"
        ]
      },
      {
        "id": "K8",
        "invariant": "EXPIRED AUTHORITY CANNOT EXECUTE",
        "holds": true,
        "detail": [
          "TOKEN_EXPIRED"
        ]
      },
      {
        "id": "K9",
        "invariant": "DELEGATED AUTHORITY CANNOT EXCEED PARENT AUTHORITY",
        "holds": true,
        "detail": "refused"
      },
      {
        "id": "K10",
        "invariant": "CRITICAL ACTIONS REQUIRE MULTI-PARTY AUTHORIZATION",
        "holds": true,
        "detail": [
          "MULTI_PARTY_NOT_SATISFIED"
        ]
      },
      {
        "id": "K11",
        "invariant": "THE AGENT CANNOT DISABLE ITS OWN KILL MECHANISM",
        "holds": true,
        "detail": [
          "AGENT_STOP:agent:1"
        ]
      },
      {
        "id": "K12",
        "invariant": "PREDICTION CANNOT CREATE AUTHORITY",
        "holds": true,
        "detail": [
          "TOKEN_SIGNATURE_INVALID"
        ]
      },
      {
        "id": "K13",
        "invariant": "ENFORCEMENT DEPTH CLAIMS ARE BOUNDED BY WHAT IS INSTALLED",
        "holds": true,
        "detail": "depth claim bounded"
      },
      {
        "id": "K14",
        "invariant": "SAFE MODES CANNOT SILENTLY PERMIT MUTATION",
        "holds": true,
        "detail": "DENIED"
      },
      {
        "id": "K15",
        "invariant": "UNKNOWN GOVERNANCE STATE CANNOT SILENTLY BECOME ALLOW",
        "holds": true,
        "detail": "fail-closed"
      },
      {
        "id": "K16",
        "invariant": "A BYPASS PATH IS NEVER REPRESENTED AS GOVERNED EXECUTION",
        "holds": true,
        "detail": {
          "ENFORCED": 1,
          "MONITORED": 0,
          "OBSERVED": 0,
          "BYPASSABLE": 1,
          "UNKNOWN": 0
        }
      },
      {
        "id": "K17",
        "invariant": "EVIDENCE MUST IDENTIFY THE EXACT AUTHORIZATION USED",
        "holds": true,
        "detail": {
          "seq": 0,
          "decision": "DENIED",
          "state": "DENIED",
          "reasons": [
            "TOKEN_EXPIRED"
          ],
          "action_hash": "x"
        }
      },
      {
        "id": "K18",
        "invariant": "ACTUAL EXECUTION IS COMPARED WITH AUTHORIZED EXECUTION",
        "holds": true,
        "detail": []
      },
      {
        "id": "K19",
        "invariant": "EXECUTION DRIFT IS AN INCIDENT",
        "holds": true,
        "detail": [
          "TARGET_DRIFT"
        ]
      },
      {
        "id": "K20",
        "invariant": "NO EXECUTION MAY JUMP FROM PROPOSED TO EXECUTED",
        "holds": true,
        "detail": "refused"
      },
      {
        "id": "K21",
        "invariant": "KERNEL EVIDENCE IS HASH-CHAINED AND INTACT",
        "holds": true,
        "detail": "evidence intact"
      },
      {
        "id": "K22",
        "invariant": "A CHANGED WORLD STATE INVALIDATES AFFECTED AUTHORIZATION",
        "holds": true,
        "detail": [
          "WORLD_STATE_CHANGED"
        ]
      }
    ],
    "failed": [],
    "all_hold": true,
    "checked": 22
  },
  "scope": "canonical action, signed short-lived governance token, action-commit boundary, capability ratchet, execution path graph, enforcement depth, safe modes, stops",
  "doctrine": [
    "NO VALID GOVERNANCE TOKEN -> NO CONSEQUENT EXECUTION",
    "NO BYPASSABLE GOVERNANCE -> NO CLAIM OF ENFORCEMENT",
    "THE AGENT MAY REQUEST; THE KERNEL AUTHORIZES; THE EXECUTOR OBEYS"
  ],
  "signature_b64": "5Sr6Utod0d0rZmNuEgoJW/uIprfyWXo06mAMKu0OvOCMlNh3PHkXgYCQtzrAk3n1a7iRuEioIKGlTfvShkHPBw=="
}
