CAIN-42 hourly operational proofs for the live cluster cain-mr-02

Every 30 minutes a real write is committed through PBFT; its quorum certificate, every replica's state, and the
previous proof's hash are signed with the CAIN-42 evidence-root key.

Verify the whole chain (Python 3.8+, pip install cryptography, no CAIN code):
  B=https://clawx.click/evidence/hourly-proof-mr02/
  curl -so verify_hourly_proofs.py "${B}verify_hourly_proofs.py.txt"
  curl -so verify_pbft_qc_bundle.py "${B}verify_pbft_qc_bundle.py.txt"
  python3 verify_hourly_proofs.py "$B"

The verdict is PROVEN OPERATIONAL only if the latest proof is less than 1 hour old and every proof in the chain
verifies; otherwise it says how long the cluster has gone unproven.
