#!/usr/bin/env python3 """Clean-room verifier for the CAIN-42 Evolution 9 proof bundle. IMPORTS NO CAIN-42 CODE. Standard library plus `cryptography` (Ed25519). It: 1. checks every file in MANIFEST.json against its SHA-256; 2. checks the P1-P15 invariant matrix is complete and every check holds; 3. re-verifies the Ed25519 signature over the proof and the master proof; 4. checks the master module digests match the proof, and the required schemas are present; 5. checks no private-key material is present in the public-safe samples. It proves the bundle is intact and self-consistent. It does NOT prove the code is correct, that CAIN is certified, or that hardware attestation exists. Usage: python3 verify_e9.py """ from __future__ import annotations import base64 import hashlib import json import sys from pathlib import Path from cryptography.exceptions import InvalidSignature from cryptography.hazmat.primitives.asymmetric import ed25519 REQUIRED_SCHEMAS = ("AgentPassport", "AgentBOM", "AgentProvenance", "CapabilityAttestation", "DelegationChain", "CollectivePassport", "AgentStateSnapshot") FORBIDDEN = ("private_key", "private key", "-----begin", "secret_key", "password") def canon(o) -> bytes: return json.dumps(o, sort_keys=True, separators=(",", ":"), ensure_ascii=True).encode() def digest(domain: str, fields: dict) -> str: return hashlib.sha256(canon({"domain": domain, **fields})).hexdigest() def verify(pub_b64: str, sig_b64: str, domain: str, fields: dict) -> bool: try: ed25519.Ed25519PublicKey.from_public_bytes(base64.b64decode(pub_b64)).verify( base64.b64decode(sig_b64), digest(domain, fields).encode()) return True except (InvalidSignature, ValueError, TypeError): return False def main() -> int: if len(sys.argv) < 2: print("usage: python3 verify_e9.py ") return 2 d = Path(sys.argv[1]) problems: list = [] checks = 0 manifest = json.loads((d / "MANIFEST.json").read_text()) for name, want in manifest["files"].items(): got = hashlib.sha256((d / name).read_bytes()).hexdigest() checks += 1 if got != want: problems.append(f"file {name}: sha256 mismatch") proof = json.loads((d / "CAIN42_EVOLUTION9_PROOF.json").read_text()) master = json.loads((d / "CAIN42_EVOLUTION9_MASTER_PROOF.json").read_text()) inv = proof.get("invariants") or {} ids = {c.get("id") for c in inv.get("checks", [])} expected = {f"P{i}" for i in range(1, 16)} checks += 1 if ids != expected: problems.append(f"invariant ids {sorted(ids)} != expected {sorted(expected)}") for c in inv.get("checks", []): if not c.get("holds"): problems.append(f"invariant {c.get('id')} does not hold: {c.get('detail')}") checks += 1 if inv.get("all_hold") is not True or inv.get("failed"): problems.append("invariant matrix all_hold is not true") body = {k: v for k, v in proof.items() if k not in ("signature_b64", "signer_public_key_b64")} checks += 1 if not verify(proof.get("signer_public_key_b64", ""), proof.get("signature_b64", ""), "CAIN42/E9-PROOF/v1", body): problems.append("proof signature does not verify") mbody = {k: v for k, v in master.items() if k not in ("signature_b64", "signer_public_key_b64")} checks += 1 if not verify(master.get("signer_public_key_b64", ""), master.get("signature_b64", ""), "CAIN42/E9-MASTER/v1", mbody): problems.append("master signature does not verify") checks += 1 if master.get("modules") != {k: v["sha256"] for k, v in (proof.get("modules") or {}).items()}: problems.append("master module digests do not match the proof") checks += 1 schemas = proof.get("schemas") or {} if set(schemas) != set(REQUIRED_SCHEMAS): problems.append("published schemas are incomplete") checks += 1 samples = (d / "SAMPLE_ARTIFACTS.json").read_text().lower() if any(f in samples for f in FORBIDDEN): problems.append("public-safe samples contain private-key material") print(json.dumps({"bundle": str(d), "checks": checks, "problems": problems, "result": "INTACT" if not problems else "FAILED"}, indent=2)) return 0 if not problems else 1 if __name__ == "__main__": raise SystemExit(main())