{
  "schema": "cain42.proof.negative_evidence.v1",
  "generated": "2026-09-29T02:40:05Z",
  "rule": "failures and fixes are published; every row is read from the signed registry or from git",
  "counts": {
    "failed_claims": 2,
    "defects_fixed": 19
  },
  "entries": [
    {
      "kind": "FAILED_CLAIM",
      "id": "C42-SOAK-72H",
      "statement": "72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run.",
      "current_status": "FAILED (published as failed)",
      "limits": "liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required",
      "evidence": [
        "soak-72h-2026-09-25/verify_soak.py.txt",
        "soak-72h-2026-09-25/REPRODUCE.txt",
        "soak-72h-2026-09-25/checkpoint-0024.json"
      ]
    },
    {
      "kind": "FAILED_CLAIM",
      "id": "C42-SOAK-72H-MULTIREGION",
      "statement": "72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): FAILED by its own pre-committed rule. Checkpoint 0032 (hour 32, 2026-09-28T05:42Z) carries no MCPGate enforcement evidence -- its checkpoint authorization did not commit (CONSENSUS_TIMEOUT) -- and the verifier requires it in every checkpoint, so no later hour can turn the verdict into PASS. At 37.7 h: 107 replica kills / 107 restarts, 0 divergences, 0 anomalies, 37 of 38 checkpoints valid (48 quorum certificates each). The soak keeps running to ~2026-09-29 21:40Z for the record.",
      "current_status": "FAILED (published as failed)",
      "limits": "one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required",
      "evidence": [
        "soak-multiregion-2026-09-26/REPRODUCE.txt",
        "soak-multiregion-2026-09-26/verify_soak.py.txt",
        "soak-multiregion-2026-09-26/checkpoint-0032.json",
        "l5-trajectory-system-2026-09-28/soak_verification_transcript.txt"
      ]
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "3ef3422",
      "commit": "3ef34228a53e1698e017c1a7872c94d674b8a3fc",
      "date": "2026-09-18",
      "failure_and_fix": "fix(cain42): close a live capability-token authorization bypass, remove fabricated public-evidence claims",
      "detail": "Forensic audit of the CAIN-42 enforcement path found and fixed a real,\nlive-reproduced authorization bypass: MCPTransparentInterceptor's\nActionCapabilityToken fast path (cain/mcp_proxy.py) granted ALLOW to any\nself-signed token whose embedded public key matched its own signature --\nit never checked the key belonged to a REGISTERED identity. Any caller\ncould forge their own keypair, self-sign a token for any principal/action,\nand bypass the entire quorum/risk-floor evaluation. Reproduced end-to-end\nbefore the fix (decision=ALLOW for an unregistered \"attacker-agent\"), then\nfixed via a new _verif",
      "regression_tests": [
        "tests/test_cain42_public_evidence_honesty.py",
        "tests/test_cain_trust_kernel.py",
        "tests/test_mcp_proxy_capability_forgery.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "7f6e071",
      "commit": "7f6e071cf5fedb87dc6c4f5533d6e821c4692fcc",
      "date": "2026-09-19",
      "failure_and_fix": "fix(cain42): close a live fabricated-postcondition bug, add world-state reconciliation gate",
      "detail": "cain/mcp_proxy.py::MCPTransparentInterceptor (the actual live MCP enforcement\nboundary) stamped \"_cain_attestation\": {\"verified\": True} onto every tool\nresponse unconditionally, regardless of whether any real check ran. Two\nexisting tests had locked in the fabrication as expected behavior. Now\nreports authorization_verified (genuinely true) separately from\npostcondition_status (honestly UNVERIFIED unless a registered checker ran\nand confirmed the effect; fails closed on checker errors). Added\nINV-42-26 NO_FABRICATED_POSTCONDITION.",
      "regression_tests": [
        "tests/test_cain42_formal_invariants.py",
        "tests/test_cain42_trust_state_machine.py",
        "tests/test_cain42_world_state.py",
        "tests/test_cain_phase2.py",
        "tests/test_phase2_virality.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "1a187ea",
      "commit": "1a187ea9a1bddcb2316319d71cde6e3d10e43bf1",
      "date": "2026-09-19",
      "failure_and_fix": "feat(cain42): Epoch 7 -- close a real model-continuity gap in the live capability token",
      "detail": "Forensic re-audit of cain/mcp_proxy.py::MCPTransparentInterceptor (the\nconfirmed live MCP enforcement boundary) found ActionCapabilityToken bound\nWHO (principal), WHAT (action/resource/intent), and WHEN (timestamps) into\nits signed digest, but nothing about WHICH MODEL was reasoning when the\ntoken was authorized. A token minted while one model planned an action\ncould be executed after the underlying model was swapped, with no way for\nthe live path to notice -- exactly the gap Epoch 7's \"Model Continuity\nAttestation\" section describes.",
      "regression_tests": [
        "tests/test_cain42_formal_invariants.py",
        "tests/test_mcp_proxy_model_continuity.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "51ff3e7",
      "commit": "51ff3e7daa16fbd31ff6b4ef0202259270dbed60",
      "date": "2026-09-19",
      "failure_and_fix": "feat(cain42): Epoch 8 -- enforce identity expiry in the live capability-check path",
      "detail": "Forensic re-audit of identity_engine.py (the identity store behind\ncain/mcp_proxy.py's live capability-token enforcement) found Epoch 8's\ncore doctrine violated for real: \"a previously trusted agent must not\nretain unlimited authority forever.\" The `identities` table has an\n`expires_at` column and an EXPIRED state, and several functions\n(verify_credential, reactivate_identity) already lazily check expiry and\nauto-transition -- but get_identity(), the ONE function\n_verify_capability_principal actually calls to decide whether a\nprincipal is still trustworthy, did not. A credential could sit at\ns",
      "regression_tests": [
        "tests/test_cain42_formal_invariants.py",
        "tests/test_identity_trust_decay.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "2a20024",
      "commit": "2a200243700e91147b8bc89172b88d918b671e0e",
      "date": "2026-09-19",
      "failure_and_fix": "feat(cain42): Epoch 9 -- enforce parameter binding on the live capability token",
      "detail": "Forensic re-audit of cain/mcp_proxy.py::MCPTransparentInterceptor.evaluate_tool_call\n(the live MCP enforcement path patched in the three preceding sessions)\nfound Epoch 9's \"cryptographic authority binding\" doctrine violated for\nreal: `resource` and `intent` were computed purely from the tool name\n(f\"mcp:tool:{tool_name}\" / f\"execute_{tool_name}\"), completely blind to\nthe actual call arguments. The capability-token branch's binding check\nused only these two tool-name-derived strings. A token authorizing\ndelete_file with path=\"/tmp/scratch.txt\" therefore authorized ANY\ninvocation of delete_file",
      "regression_tests": [
        "tests/test_cain42_formal_invariants.py",
        "tests/test_cain_trust_kernel.py",
        "tests/test_identity_trust_decay.py",
        "tests/test_mcp_proxy_capability_forgery.py",
        "tests/test_mcp_proxy_model_continuity.py",
        "tests/test_mcp_proxy_parameter_binding.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "a075ca6",
      "commit": "a075ca6fa6ca70b158a87607c7a3c4ffba0af5b6",
      "date": "2026-09-22",
      "failure_and_fix": "fix(bft): WAL recovery must replay application state, not just commit_index",
      "detail": "Root-caused the rejoin/partition FAIL from the last certification run:\nWAL.recover() advanced the recovered sequence/view from COMMITTED_EXEC\nrecords but returned the checkpoint's (usually empty, since checkpoints\nare only taken every 10 sequences) state_data unchanged. A restarted\nreplica came back reporting the correct commit_index with EMPTY\napplication state -- silently diverging from the honest quorum while\nstill claiming to be caught up.",
      "regression_tests": [
        "tests/test_cain42_bft_hardening.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "ea86e41",
      "commit": "ea86e4105d2f57d68015a35955ff1e81283e4935",
      "date": "2026-09-22",
      "failure_and_fix": "fix(bft): state-transfer must allow sequence gaps, not require contiguity",
      "detail": "Found from a live full-pipeline certification run against the WAL-replay\nfix (a075ca6): rejoin still FAILed. The real cause was different from\nwhat that fix addressed -- apply_state_transfer_entries required\ncert.sequence == commit_index + 1 exactly, but PBFT legitimately burns\nsequence numbers on rounds that time out before reaching quorum (e.g. a\nsub-quorum submission during a partition test). A catching-up replica\nwhose local commit_index was 17 was offered the honest next real commit\nat seq=20 (18/19 were never committed by anyone) and refused it as a\n\"sequence gap\", staying permanently st",
      "regression_tests": [
        "tests/test_cain42_bft_hardening.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "d5e8f5d",
      "commit": "d5e8f5d3f44b1600ca1e33c3bb46a2a9b5233024",
      "date": "2026-09-22",
      "failure_and_fix": "fix(multi-region): real X25519 WireGuard keys, untrack committed private keys, honest manifest",
      "detail": "- setup-mesh.sh fallback (used whenever `wg` is absent, as on this host)\n  wrote SHA256(privkey) as the WireGuard public key. That is not a\n  Curve25519 key; every generated config was unable to handshake. Now\n  derives a real X25519 keypair via python cryptography or fails closed;\n  output dir is 0700/umask 077 and overridable via WG_MESH_OUTPUT_DIR.\n- Four WireGuard private keys were committed under generated/. Removed\n  from the index and gitignored. They remain in git history: treat as\n  compromised, regenerate on deploy. No live wg interface used them.\n- pbft_cluster_manifest.json carried",
      "regression_tests": [
        "tests/test_multi_region_pbft.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "b93f91a",
      "commit": "b93f91a0ecfbcb21946ea39e8c184a286888381c",
      "date": "2026-09-23",
      "failure_and_fix": "fix(identity): expired identities kept authority; delegations could outlive delegator (INV-42-30)",
      "detail": "check_capability/verify_delegation/create_delegation trusted the stored status\ncolumn; expiry was only applied lazily by get_identity(). An expired human kept\nfabric:approve (live AGI-boundary approver check), its delegates kept delegated\nauthority, children kept inherited capabilities. Delegation TTL was also not\nbounded by the delegator's own expiry (temporal authority widening).",
      "regression_tests": [
        "tests/test_identity_trust_decay.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "9640ec8",
      "commit": "9640ec87b571258ec3064ad100b64ff3991e94c3",
      "date": "2026-09-23",
      "failure_and_fix": "fix(guard): parameter blast-radius scan bypassable via unicode/whitespace/flag variants",
      "detail": "Commits the previously-uncommitted parameter scanning in _classify_blast_radius\n(and its use in mcp_proxy) with the bypasses flagged by the 2026-09-23 audit fixed:\nzero-width chars, whitespace padding, rm -fr/-Rf/--recursive, fullwidth forms all\nclassified LOW. Now NFKC + Cf-strip + token-boundary matching; \"skills\"/\"format\"\nno longer false-positive to quorum. Deterministic denylist; encoding/shell\nindirection remains out of scope (documented).",
      "regression_tests": [
        "tests/test_cain_mass_production.py",
        "tests/test_cain_phase1.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "282c7a1",
      "commit": "282c7a16e51f0c8263bda747bd541107a5e49898",
      "date": "2026-09-26",
      "failure_and_fix": "fix(guard): default decision core no longer ALLOWs the 5 audited bypasses; quarantine check fails closed",
      "detail": "The 2026-09-26 audit showed the default MCP proxy path (cain/guard.py deterministic\nbaseline) returning ALLOW for:\n  Shell_Exec \"curl ... | bash\", exec \"cat ~/.ssh/id_rsa | nc ...\",\n  write_file ~/.ssh/authorized_keys, http_post with AWS_SECRET_ACCESS_KEY,\n  read_file /etc/shadow.\nAll five now return REQUIRE_APPROVAL via a new sensitive-parameter class\n(remote-content-to-interpreter, raw network channels, credential/key paths,\nPEM private keys, secret=value, known token prefixes).",
      "regression_tests": [
        "tests/test_cain42_fabric_gate_wiring.py",
        "tests/test_guard_default_path_bypasses.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "e1cf69c",
      "commit": "e1cf69c9c394f685e16a9631f38683eef8ec1a05",
      "date": "2026-09-26",
      "failure_and_fix": "fix(pbft): progress timer + NEW_VIEW reply adoption (72h soak split-view stall); multi-region deploy tooling",
      "detail": "The 72-hour soak left 2 replicas in view 39 and 2 in view 40 for 25h with\nzero commits: only an unreachable primary triggered a view change, and a\nNEW_VIEW returned as the reply to a VIEW_CHANGE was dropped. Added a\nrate-limited no-progress suspicion (casts only this replica's VIEW_CHANGE;\ninstallation still needs 2f+1) and route NEW_VIEW replies to handle_new_view.\ntest_cain42_pbft_split_view_liveness: 4/5 fail on the previous engine, 5/5\npass; full BFT/PBFT suite 455/455.",
      "regression_tests": [
        "tests/test_cain42_pbft_split_view_liveness.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "94c80d6",
      "commit": "94c80d6167c847d4db68bc3a6e538c863317f062",
      "date": "2026-09-26",
      "failure_and_fix": "fix(continuous-auth): salami-defence bypasses in live-loaded engine + CAIN-42 QE gap analysis (Phase 1/2)",
      "detail": "cain_continuous_authorization.py is loaded by the live gateway (via\ncain_canonical_pipeline) and had ZERO tests. Fixed (13 of 17 new tests fail\non the old code):\n- negative cost/records were authorized and LOWERED the window total, letting\n  later real spend under the ceiling; NaN poisoned the sum and switched the\n  defence off for the whole window -> invalid input refused, never counted\n- scope '/data/public' matched '/data/public_secrets' -> boundary match\n- declared intent max_allowed_spend_cents was never enforced -> enforced\n- QUARANTINE_REQUIRED via salami_score>=1.5 unreachable (capped ",
      "regression_tests": [
        "none added in this commit"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "ef46929",
      "commit": "ef46929f20dfe896128ff13c795d9e823ea68b03",
      "date": "2026-09-27",
      "failure_and_fix": "feat(sdk): guard and MCP proxy are default-deny; undeclared actions held for approval",
      "detail": "Authorized tools are declared via guard(allow=[...]), allowed_tools=[...] or\nCAIN_ALLOWED_ACTIONS; CAIN_UNKNOWN_ACTION_POLICY=allow is an explicit, recorded\nopt-out (CLAWX uses it: its capability gates are its authorization layer).\nTest suite declares its tools by name (never *). 70 guard-dependent files:\n1516 passed, 0 failed. Homepage card corrected (audit bypasses fixed in 282c7a1).",
      "regression_tests": [
        "tests/conftest.py",
        "tests/test_cain42_fabric_gate_wiring.py",
        "tests/test_cain42_public_truth_layer.py",
        "tests/test_frontier_enforcement.py",
        "tests/test_guard_default_path_bypasses.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "a68f4df",
      "commit": "a68f4df9205f1f84b110ef4c990ea07700be8f79",
      "date": "2026-09-27",
      "failure_and_fix": "fix: previous full run's 13 test failures traced and fixed; tampered soak verifier restored to signed bytes (v2 beside it); daily sync measures live cain-mr-02",
      "detail": "- consensus tests now build digest-bound proposals (engine check 3b since 2026-09-23); 173 pass\n- OPA policy re-signed after reviewed fix abac85f; enclave test requires honest SOFTWARE_SIMULATED label (71b37d0)\n- verify_soak.py.txt restored to the bytes the claims registry signed (Verification Center showed TAMPERED); fix published as verify_soak.v2.py.txt; soak outcome FAIL/stopped at 24h recorded\n- fabric_daily_sync collect_nodes: live 4-region replicas (overlay status + image read on each host) instead of retired local containers\n- AI_VERIFY.json identical on both roots; tests updated for L",
      "regression_tests": [
        "tests/distributed/test_cain34_pbft_cluster.py",
        "tests/distributed/test_cain42_equivocation_quarantine.py",
        "tests/test_cain_sandbox_evolution.py",
        "tests/test_clawx_site.py",
        "tests/test_cluster_evidence_publication.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "6207f30",
      "commit": "6207f30726d6f4bef6d9104efe8c763b47d05c06",
      "date": "2026-09-28",
      "failure_and_fix": "fix(cain45): fail-open defects found by the Evolution #7 fail-closed probe; evidence check no longer quadratic",
      "detail": "Found by session f9's independent probe (Phase 32); all were real, all now refuse:\n- D1 clock rollback revived an expired grant (and a clock of 0 was accepted):\n  a persisted time high-water mark; a clock behind it (or behind the ZoD's\n  creation) refuses, and a grant issued in the future is refused.\n- D2 execution without evidence: call_tool invoked the tool, and run()/\n  spawn_process launched, before anything was written. The intent\n  (TOOL_CALL_REQUESTED / EXECUTION_REQUESTED) is now appended BEFORE the effect,\n  so an unwritable log means no execution; a tool failure is TOOL_FAILED.\n- A r",
      "regression_tests": [
        "tests/test_cain45_authority_gaps.py",
        "tests/test_cain45_fail_closed.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "92c2c47",
      "commit": "92c2c47c170190ee4178048c00ae62b4f7be27a1",
      "date": "2026-09-28",
      "failure_and_fix": "security(gateway): close anonymous writes on /api/v1/control/sovereign/* (found by the Evo7 forensic map)",
      "detail": "Anonymous callers could:\n- have the node key sign seccomp/eBPF \"profiles\" for any tenant and agent\n  (generate-profile, generate-ebpf-spec; no eBPF is ever loaded);\n- have KMS sign their own text into the WORM transparency log and apply\n  trust penalties to ANY tenant's subject (audit-call), i.e. trust\n  poisoning from the internet;\n- read every tenant's kernel-violation records (GET violations).\nThe writes now go through the existing tenant write gate (validated API\nkey; a declared tenant must equal the key's). The violations read is\nlimited to the key's tenant, or the demo tenant for anonymo",
      "regression_tests": [
        "none added in this commit"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "fd3a92e",
      "commit": "fd3a92e9fec6ad92cc2c01bcbeef1746fcc2dbf1",
      "date": "2026-09-28",
      "failure_and_fix": "fix(cain42-e6): lease bundle verifier cross-checks result rows against the signed chain",
      "detail": "Session 79 found that verify_e6_lease.py never compared the run's summary\nfields (tool_ran_after_trip, refused_after_trip, ...) with the evidence\nchain, so a doctored LEASE_RUN.json still printed VERIFIED. For the\nevidence-deletion case, PASS rested only on those unsigned fields.",
      "regression_tests": [
        "tests/test_e6_lease_bundle.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    },
    {
      "kind": "DEFECT_FIXED",
      "id": "040cee2",
      "commit": "040cee21e6a6e5c548acc3b6fa30785d6dbac81c",
      "date": "2026-09-28",
      "failure_and_fix": "fix(cain42-l5): Prompt 3 continuous trajectory governance -- 13 fail-open defects closed, verifier recomputes",
      "detail": "Probing cain45/l5/trajectory_governance.py (written by an earlier session, never committed) returned ALLOW\nor escaped containment on 13/13 attacks: agent-self-signed / unsigned lease, lease for another agent or\ntrajectory, lease with no expiry, empty scope = unlimited, missing policy/context = wildcard, PAUSED /\nESCALATED / REAUTHORIZATION_REQUIRED trajectories still ALLOWed, containment reviving a TERMINATED\ntrajectory and relaxing QUARANTINE, and plan_binding never checked.",
      "regression_tests": [
        "tests/test_cain42_l5_constitution.py",
        "tests/test_cain42_l5_identity_authority.py",
        "tests/test_cain42_l5_soak_and_verifier.py",
        "tests/test_cain42_l5_trajectory_governance.py",
        "tests/test_cain42_l5_trajectory_prompt3.py",
        "tests/test_cain42_l5_wiring.py",
        "tests/test_cain45_governance.py",
        "tests/test_cain45_world_model.py"
      ],
      "current_status": "FIXED (commit is in the deployed history)"
    }
  ]
}
