{
  "schema": "cain42.proof.byzantine_index.v1",
  "generated": "2026-09-29T02:40:07Z",
  "rule": "fault model and topology read from each bundle's own files; 'NOT RECORDED IN BUNDLE' where absent",
  "packages": [
    {
      "claim_id": "C42-PBFT-QC",
      "status": "VERIFIED",
      "public_label": "DISPOSABLE CLUSTER VERIFIED",
      "environment": [
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": [
        {
          "cluster_id": "cain42-pbft-qc-evidence",
          "nodes": 4,
          "node_source": "signer sets / placement in the bundle",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": "NOT RECORDED IN BUNDLE",
      "providers": "NOT RECORDED IN BUNDLE",
      "fault_injected_and_observed": "A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "pbft-evolution2-2026-09-24/PBFT_QC_BUNDLE.json",
          "sha256": "f96088a8edf710b38b3cf22a7c25dd04e2758f7ff7ae9583b8eddf4b04cb2dde"
        },
        {
          "file": "pbft-evolution2-2026-09-24/verify_pbft_qc_bundle.py.txt",
          "sha256": "ba452ce42528f11f7f5235727a65cae25a34072bc52b4711fd72581615d06009"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json  (or index.html in a browser)",
      "limits": "disposable cluster on one host"
    },
    {
      "claim_id": "C42-FAST-PATH",
      "status": "VERIFIED",
      "public_label": "DISPOSABLE CLUSTER VERIFIED",
      "environment": [
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": [
        {
          "cluster_id": "cain42-pbft-qc-evidence",
          "nodes": 4,
          "node_source": "signer sets / placement in the bundle",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3,
        4
      ],
      "quorum_note": "several values: a larger one is the fast path (all members must sign)",
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": "NOT RECORDED IN BUNDLE",
      "providers": "NOT RECORDED IN BUNDLE",
      "fault_injected_and_observed": "The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "pbft-evolution3-2026-09-24/PBFT_QC_BUNDLE.json",
          "sha256": "43e1c61004d3d53a1f76d96f72a7241ef59793a2f77d9beda5f6b40559e9c9a4"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json",
      "limits": "bounded model (single slot, 3 views); not deployed live"
    },
    {
      "claim_id": "C42-FAST-PATH-LATENCY",
      "status": "BENCHMARKED",
      "public_label": "IMPLEMENTED",
      "environment": [
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": "NOT RECORDED IN BUNDLE",
      "quorum_values_in_certificates": "NOT RECORDED IN BUNDLE",
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": "NOT RECORDED IN BUNDLE",
      "providers": "NOT RECORDED IN BUNDLE",
      "fault_injected_and_observed": "The fast path did NOT produce a measurable latency improvement on this host (paired A/B, 95% CI includes 0).",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [],
      "verify": "scripts/cain42_bft/pbft_ab_bench.py (results in the certification)",
      "limits": "negative result; host CPU-bound"
    },
    {
      "claim_id": "C42-DAG-ORDER",
      "status": "VERIFIED",
      "public_label": "DISPOSABLE CLUSTER VERIFIED",
      "environment": [
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": [
        {
          "cluster_id": "cain42-dag-evidence",
          "nodes": 4,
          "node_source": "signer sets / placement in the bundle",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3,
        4
      ],
      "quorum_note": "several values: a larger one is the fast path (all members must sign)",
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": "NOT RECORDED IN BUNDLE",
      "providers": "NOT RECORDED IN BUNDLE",
      "fault_injected_and_observed": "DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "dag-evolution4-2026-09-24/DAG_CLUSTER_EVIDENCE.json",
          "sha256": "10c08dab4e70a7a5782b9aafe92e7c88e63038085cce3a8a143abb660797bc09"
        },
        {
          "file": "dag-evolution4-2026-09-24/verify_dag_bundle.py.txt",
          "sha256": "f544555b9275d412bdd2b459cf780d351058b3755792f44dfb7f8377a5d58fd5"
        }
      ],
      "verify": "python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json",
      "limits": "disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured"
    },
    {
      "claim_id": "C42-INDEPENDENT-FAILURE-DOMAINS",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-02",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia",
        "sjc"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "four-server-cluster-2026-09-27/PBFT_QC_BUNDLE.json",
          "sha256": "0ed32a92d4c58c3517679c6c0ca7c318a45960c01b5b63e7ce87db677b6a3b71"
        },
        {
          "file": "four-server-cluster-2026-09-27/verify_host_loss_bundle.py.txt",
          "sha256": "0f26f9c82d40d9c3da44d878ee25ecfab59413475765515475a314019a15b6cf"
        }
      ],
      "verify": "python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json",
      "limits": "one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered"
    },
    {
      "claim_id": "C42-LIVE-MULTI-REGION",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        },
        {
          "cluster_id": "cain-mr-02",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia",
        "sjc"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "multi-region-cluster-2026-09-26/PBFT_QC_BUNDLE.json",
          "sha256": "393d88099d4d62686abff3bf0da841808741717a0978626b04d34e678f35fd4b"
        },
        {
          "file": "hourly-proof-mr02/proof-000000.json",
          "sha256": "cfc616620eae2ddd7371b0393ca269edb07eb6cb704f17deea9be51d4bba9847"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; python3 verify_hourly_proofs.py <base>",
      "limits": "region placement is stated by the operator"
    },
    {
      "claim_id": "C42-PARTITION-BYZANTINE",
      "status": "VERIFIED",
      "public_label": "LIVE + DISPOSABLE CLUSTER VERIFIED",
      "environment": [
        "LIVE",
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": [
        {
          "cluster_id": "cain-byz-01",
          "nodes": "NOT RECORDED IN BUNDLE",
          "node_source": "NOT RECORDED IN BUNDLE",
          "fault_tolerance_f": "NOT RECORDED IN BUNDLE",
          "commit_quorum": "NOT RECORDED IN BUNDLE"
        },
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        },
        {
          "cluster_id": "cain-mr-02",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia",
        "sjc"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced).",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "partition-test-2026-09-26/PBFT_QC_BUNDLE.json",
          "sha256": "1f1d7d4a3af89f9f710aedc574a191048a5c1d7655513c185443f4135ea478c8"
        },
        {
          "file": "asymmetric-partition-2026-09-27/PBFT_QC_BUNDLE.json",
          "sha256": "3618882fe6ed8653886a92daed66009ec5d08e64c46476891f245eb70cdf97e6"
        },
        {
          "file": "byzantine-test-2026-09-26/PBFT_QC_BUNDLE.json",
          "sha256": "940ed6cf99124c78d57d1c49f0813a5b5dc061390303a90d8a8cce646a874994"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py",
      "limits": "partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours"
    },
    {
      "claim_id": "C42-DEGRADED-NETWORK",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-02",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia",
        "sjc"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "degraded-network-2026-09-27/PBFT_QC_BUNDLE.json",
          "sha256": "405e189d2ab18bbb435f10380174afc2db354d45f062ac4fe663ee2448f2d562"
        },
        {
          "file": "degraded-network-948b189-2026-09-27/PBFT_QC_BUNDLE.json",
          "sha256": "401686a4a9ad475a09f786d02760b8871336c3da61cc9bfd340b12d3e270f9f9"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json",
      "limits": "VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host"
    },
    {
      "claim_id": "C42-DISASTER-RECOVERY",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        },
        {
          "cluster_id": "cain-mr-02",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia",
        "sjc"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "storage-loss-drill-2026-09-27/PBFT_QC_BUNDLE.json",
          "sha256": "987c53f1dc8af84aa8243e08a6d0b1e3661e6d774adf53055ef91651b6bed74d"
        },
        {
          "file": "restore-drill-2026-09-26/PBFT_QC_BUNDLE.json",
          "sha256": "94162b7304d9484402c253dcdb881bc30665150a9cd0845d213eb4f3e3a30969"
        },
        {
          "file": "restore-validation/validation-2026-09-27.json",
          "sha256": "e6f9a8811e14bf880ba09ef6842a271ba89d3340932ee74e1be374bb4ed8bc8c"
        }
      ],
      "verify": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py <latest.json> --key <evidence-root.pub.json>",
      "limits": "same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica"
    },
    {
      "claim_id": "C42-ROLLBACK",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": "NOT RECORDED IN BUNDLE",
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "rollback-drill-2026-09-26/ROLLBACK.json",
          "sha256": "cdf5e71eadcdd18ff55eca385990ff7ac1f3f07e2b3f94f85641a960760a76de"
        }
      ],
      "verify": "compare the per-step status in ROLLBACK.json",
      "limits": "both engines share one storage format"
    },
    {
      "claim_id": "C42-HOSTED-CONSENSUS",
      "status": "VERIFIED",
      "public_label": "LIVE VERIFIED",
      "environment": [
        "LIVE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key).",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "hosted-consensus-2026-09-27/decision.json",
          "sha256": "f9e53b72eeaedfc256eb5b7b0e426321c6aaeb63c2b5ea1e54da1fba93cdf27e"
        },
        {
          "file": "hosted-consensus-2026-09-27/qc.json",
          "sha256": "4314a03ae57da8075806951a4a999d170c5215c3cd8680a3e5633f1bc22d85ba"
        },
        {
          "file": "hosted-consensus-2026-09-27/verify_hosted_decision.py.txt",
          "sha256": "e3a4ceff12c81987af5672cf047ab9935e0e0d95a1ec7b61bf14e39091b1f3f1"
        }
      ],
      "verify": "python3 verify_hosted_decision.py --live https://cainstudio.online membership.json  (see REPRODUCE.txt)",
      "limits": "enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced"
    },
    {
      "claim_id": "C42-SOAK-72H",
      "status": "FAILED",
      "public_label": "FAILED",
      "environment": [
        "DISPOSABLE_CLUSTER"
      ],
      "clusters": [
        {
          "cluster_id": "cain42-soak72-1b28cf3",
          "nodes": 4,
          "node_source": "signer sets / placement in the bundle",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3,
        4
      ],
      "quorum_note": "several values: a larger one is the fast path (all members must sign)",
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": "NOT RECORDED IN BUNDLE",
      "providers": "NOT RECORDED IN BUNDLE",
      "fault_injected_and_observed": "72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "soak-72h-2026-09-25/verify_soak.py.txt",
          "sha256": "deed0270d115ba2cf509820cc7ec464fa835c76420971921558d4e14ac1e0cb4"
        },
        {
          "file": "soak-72h-2026-09-25/REPRODUCE.txt",
          "sha256": "afacde250be9afcf3112a6050b2eec0f67e0b77224ea985e57e6f844928c6d1d"
        },
        {
          "file": "soak-72h-2026-09-25/checkpoint-0024.json",
          "sha256": "07cec42fd5b8456bf6b5b83560dfd4e8c18e18aa84012e7a37216c57adb1ac63"
        }
      ],
      "verify": "python3 verify_soak.py https://clawx.click/evidence/soak-72h-2026-09-25/  (prints VERDICT: FAIL)",
      "limits": "liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required"
    },
    {
      "claim_id": "C42-SOAK-72H-MULTIREGION",
      "status": "FAILED",
      "public_label": "FAILED",
      "environment": [
        "LIVE",
        "OFFLINE"
      ],
      "clusters": [
        {
          "cluster_id": "cain-mr-01",
          "nodes": 4,
          "node_source": "live topology in the signed registry",
          "fault_tolerance_f": 1,
          "commit_quorum": 3
        }
      ],
      "quorum_values_in_certificates": [
        3
      ],
      "quorum_note": null,
      "fault_assumptions": "n = 3f + 1 per cluster; up to f arbitrarily faulty replicas; see each cluster's f",
      "regions": [
        "atl",
        "lax",
        "mia"
      ],
      "providers": [
        "vultr"
      ],
      "fault_injected_and_observed": "72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): FAILED by its own pre-committed rule. Checkpoint 0032 (hour 32, 2026-09-28T05:42Z) carries no MCPGate enforcement evidence -- its checkpoint authorization did not commit (CONSENSUS_TIMEOUT) -- and the verifier requires it in every checkpoint, so no later hour can turn the verdict into PASS. At 37.7 h: 107 replica kills / 107 restarts, 0 divergences, 0 anomalies, 37 of 38 checkpoints valid (48 quorum certificates each). The soak keeps running to ~2026-09-29 21:40Z for the record.",
      "state_roots_sample": "NOT RECORDED IN BUNDLE",
      "evidence_hashes": [
        {
          "file": "soak-multiregion-2026-09-26/REPRODUCE.txt",
          "sha256": "a981f6a68fd3104bc64f85cdc773f2f77add11d8cae7b0fcfeee35e6bccdbfef"
        },
        {
          "file": "soak-multiregion-2026-09-26/verify_soak.py.txt",
          "sha256": "8d9f0a48faf4fea54c38c3795d8b76103cf3dfb3bc92ffe0709a5c9825c7141d"
        },
        {
          "file": "soak-multiregion-2026-09-26/checkpoint-0032.json",
          "sha256": "5d347d80796fff7d3c87c4ac47c8652dfa9d287930db2c7b1d5548377c25249d"
        },
        {
          "file": "l5-trajectory-system-2026-09-28/soak_verification_transcript.txt",
          "sha256": "6620c4d6b382644169d1ffce552e0c6aa3acbc08d27c188cfe9b98b8c9a3d834"
        }
      ],
      "verify": "python3 verify_soak.py https://clawx.click/evidence/soak-multiregion-2026-09-26/  (prints INVALID checkpoint-0032.json and VERDICT: FAIL)",
      "limits": "one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required"
    }
  ]
}
