CAIN-42 governed evolution, live on the production gateway + MCPGate (2026-09-28T16:52:22Z, commit ba7035d)
==============================================================================================
Save the two .py.txt files as .py (Python 3 + `cryptography`; neither imports anything from CAIN):

  python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json          # offline
  python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json --live   # + all 3 sites publish the
        same governance key, and cain-mr-01's own record of sequences 22515,22517,22518,22517 carries each certified
        capability commitment in the ordered operation
  python3 verify_adaptive_bundle.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json         # recomputes every evolution
        decision the hosted gate took (Prompt 6 clean-room rules) and fails if CAIN's is more permissive

What the run shows (operator self-test tenant, scripted agent, scripted evaluator; all agent calls through the public
/fabric/mcp/enforce on cainstudio.online, mcpgate.online and clawx.click):
  - an agent's model and MCP tool configuration change only through the evolution gate: no evaluator report -> REJECT,
    a tool change that also widens authority -> QUARANTINE (undeployable), an unapproved model -> REJECT;
  - REQUIRE_APPROVAL: deploy with no approval or with the agent approving itself -> refused; an operator approves;
  - a deploy gives a new capability commitment: the old lease stops authorizing, cain-mr-01 certifies the new
    commitment, a re-issued lease works, and MCPGate refuses the tool the evolution disabled, on all three domains;
  - a model swapped outside the gate is refused; after a governed upgrade the old model is refused;
  - an agent-signed rollback is refused; an operator-signed rollback restores the previous version.

Try it (no account): a proposal not signed by the registered agent is refused before anything is recorded.
  curl -s -X POST https://mcpgate.online/fabric/mcp/system/cain-selftest-cagl5-evolution/evolution/propose \
       -H 'content-type: application/json' -d '{"proposal":{"agent_id":"urn:cain:identity:agent:cagl5-evo-primary",
       "trajectory_id":"t","change_type":"MODEL","current_version":"x","proposed_version":"y","changed_component":"model",
       "reason":"r","candidate":{"model":"m"},"proposer":"urn:cain:identity:agent:cagl5-evo-primary","signature":""}}'
  -> HTTP 401 {"detail":"PROPOSAL_NOT_SIGNED_BY_THE_REGISTERED_AGENT"}

What this is NOT: a customer deployment, an LLM agent, automatic regression rollback (rollback here is
operator-signed), hardware attestation or a third-party review. The evaluator's raw measurements are not
recomputed (its signature and the decision derived from them are). PRE-PRODUCTION.
