#!/usr/bin/env python3 """CAIN-42 E28 clean-room verifier. Imports NOTHING from CAIN. python3 verify_e28.py [bundle-dir] Re-derives, from the published artifacts only: identity-envelope structure, ids and signatures; transaction bindings from the agent-signed requests; delegation-token signatures and the per-dimension subset rule along every chain; lineage-edge hashes, signatures, links and the compressed path proof; lease signatures; the governance-receipt hash chain; revocation and replay outcomes; RFC 6962 inclusion and consistency proofs and the signed tree head; bench, invariant, mutation, conformance and scale results; the certificate signature; and the bundle hashes and signature. Prints one JSON object; exit 0 only when every check holds. """ from __future__ import annotations import base64 import hashlib import json import sys from pathlib import Path from cryptography.exceptions import InvalidSignature from cryptography.hazmat.primitives.asymmetric import ed25519 D_ENVELOPE = "CAIN42/E28-IDENTITY-ENVELOPE/v1" D_E25_ENVELOPE = "CAIN42/E25-AGENCY-ENVELOPE/v1" D_TX = "CAIN42/E28-TRANSACTION-BINDING/v1" D_DELEGATION = "CAIN42/E28-BOUNDED-DELEGATION/v1" D_LINEAGE = "CAIN42/E28-LINEAGE-EDGE/v1" D_RECEIPT = "CAIN42/E28-GOVERNANCE-RECEIPT/v1" D_TREE_HEAD = "CAIN42/E28-TREE-HEAD/v1" D_LEASE = "CAIN42/E28-AUTONOMY-LEASE/v1" D_PASSPORT = "CAIN42/E28-EXECUTION-PASSPORT/v1" D_IDENTITY = "CAIN42/E28-EXECUTION-IDENTITY/v1" D_CERT = "CAIN42/E27-GOVERNANCE-CERTIFICATE/v1" D_MASTER = "CAIN42/E28-MASTER/v1" ENVELOPE_FIELDS = {"schema", "version", "envelope_id", "kind", "issuer_domain", "issuer_pub", "subject_identity_id", "identity_version", "identity_digest", "subject_pub", "sponsor", "lineage_root_principal", "lineage_depth", "audience", "transaction_binding", "lease_id", "delegation_id", "capability_ceiling", "revocation_epoch", "not_before", "expires_at", "nonce", "authority"} DIMS = {"capabilities": "set", "resources": "prefix", "tools": "set", "data_scopes": "set", "org_scopes": "set", "regions": "set", "max_transaction_value": "max", "economic_budget": "max", "max_executions": "max", "risk_ceiling": "max", "max_autonomy_ms": "max", "max_depth": "max", "downstream_delegation": "bool", "subagent_creation": "bool", "not_before": "time_start", "expires_at": "time_end"} CATEGORY_TARGETS = {"identity": 75, "delegation": 50, "replay_fork": 50, "cross_domain": 50, "model_runtime_substitution": 50, "credential": 50, "memory_identity_confusion": 50, "protocol_boundary": 50} EPISTEMIC = {"VERIFIED", "ATTESTED", "OBSERVED", "CLAIMED", "SIMULATED", "UNKNOWN"} def canonical(o) -> bytes: return json.dumps(o, sort_keys=True, separators=(",", ":"), ensure_ascii=True).encode() def h(o) -> str: return hashlib.sha256(canonical(o)).hexdigest() def digest(domain: str, body) -> str: return h({"domain": domain, "body": body}) def verify(pub: str, sig: str, domain: str, body) -> bool: try: ed25519.Ed25519PublicKey.from_public_bytes(base64.b64decode(pub)).verify( base64.b64decode(sig), digest(domain, body).encode()) return True except (InvalidSignature, ValueError, TypeError): return False def leaf(b: bytes) -> bytes: return hashlib.sha256(b"\x00" + b).digest() def node(l: bytes, r: bytes) -> bytes: return hashlib.sha256(b"\x01" + l + r).digest() def mth(leaves): n = len(leaves) if n == 0: return hashlib.sha256(b"").digest() if n == 1: return leaves[0] k = 1 while k * 2 < n: k *= 2 return node(mth(leaves[:k]), mth(leaves[k:])) def verify_inclusion(lh: bytes, index: int, size: int, path, root: bytes) -> bool: if index >= size: return False fn, sn, r = index, size - 1, lh for p in path: if sn == 0: return False if fn & 1 or fn == sn: r = node(p, r) if not fn & 1: while fn and not fn & 1: fn >>= 1 sn >>= 1 else: r = node(r, p) fn >>= 1 sn >>= 1 return sn == 0 and r == root def verify_consistency(m: int, n: int, path, old: bytes, new: bytes) -> bool: if m == n: return not path and old == new if m == 0 or m > n or not path: return False p = list(path) if m & (m - 1) == 0: p = [old] + p fn, sn = m - 1, n - 1 while fn & 1: fn >>= 1 sn >>= 1 fr = sr = p[0] for c in p[1:]: if sn == 0: return False if fn & 1 or fn == sn: fr = node(c, fr) sr = node(c, sr) if not fn & 1: while fn and not fn & 1: fn >>= 1 sn >>= 1 else: sr = node(sr, c) fn >>= 1 sn >>= 1 return fr == old and sr == new and sn == 0 def tx_digest(e: dict) -> str: return digest(D_TX, {"tenant": e.get("tenant_id"), "transaction_id": e.get("transaction_id"), "operation": e.get("operation"), "target": e.get("execution_target"), "parameters": e.get("parameters"), "capabilities": list(e.get("requested_capabilities") or []), "adapter": e.get("execution_adapter"), "principal": e.get("principal_identity")}) def subset_ok(c: dict, p: dict) -> list: bad = [] for d, kind in DIMS.items(): cv, pv = c.get(d), p.get(d) if kind == "set" and "*" not in pv and not set(cv) <= set(pv): bad.append(d) elif kind == "prefix" and not all(any(x.startswith(q) for q in pv) for x in cv): bad.append(d) elif kind == "max" and not cv <= pv: bad.append(d) elif kind == "bool" and cv and not pv: bad.append(d) elif kind == "time_start" and not cv >= pv: bad.append(d) elif kind == "time_end" and not cv <= pv: bad.append(d) return bad class Checker: def __init__(self): self.checks = 0 self.passed = 0 self.problems = [] def check(self, name, ok, detail=""): self.checks += 1 if ok: self.passed += 1 else: self.problems.append(f"{name}: {detail}"[:300]) def load(d: Path, name: str): return json.loads((d / name).read_text()) def check_envelope(c: Checker, tag: str, d: dict, issuer_pub: str): e = d.get("envelope", {}) c.check(f"{tag}.fields", set(e) == ENVELOPE_FIELDS, sorted(set(e) ^ ENVELOPE_FIELDS)) c.check(f"{tag}.schema", e.get("schema") == "cain.e28.identity-envelope" and str(e.get("version", "")).startswith( "1."), e.get("schema")) want = "eid_" + digest(D_ENVELOPE, {k: v for k, v in e.items() if k != "envelope_id"})[:32] c.check(f"{tag}.id", want == e.get("envelope_id"), e.get("envelope_id")) c.check(f"{tag}.issuer", e.get("issuer_pub") == issuer_pub, "issuer key differs") c.check(f"{tag}.signature", verify(issuer_pub, d.get("signature_b64", ""), D_ENVELOPE, {k: e[k] for k in sorted(e)}), "bad signature") c.check(f"{tag}.no_authority", e.get("authority") == "NONE", e.get("authority")) ttl = e.get("expires_at", 0) - e.get("not_before", 0) cap = 30_000 if e.get("kind") == "TRANSACTION" else 3_600_000 c.check(f"{tag}.ttl", 0 < ttl <= cap, ttl) if e.get("kind") == "TRANSACTION": c.check(f"{tag}.bound", bool(e.get("transaction_binding")), "unbound transaction envelope") def main() -> int: d = Path(sys.argv[1] if len(sys.argv) > 1 else ".") c = Checker() try: art = load(d, "E2E_ARTIFACTS.json") e2e = load(d, "END_TO_END.json") except (OSError, ValueError) as x: print(json.dumps({"result": "ERROR", "checks": 0, "passed": 0, "problems": [str(x)]})) return 1 ipub = art["issuer_pub"] # ---- envelopes + transaction binding + request proof of possession for i, s in enumerate(art["session_envelopes"]): check_envelope(c, f"session[{i}]", s, ipub) c.check("session.version_bumped_after_change", art["session_envelopes"][1]["envelope"]["identity_version"] > art["session_envelopes"][0]["envelope"]["identity_version"], "no version bump") c.check("session.digest_changed_after_change", art["session_envelopes"][1]["envelope"]["identity_digest"] != art["session_envelopes"][0]["envelope"]["identity_digest"], "digest reused across a model change") for i, (t, r) in enumerate(zip(art["transaction_envelopes"], art["e25_requests"])): check_envelope(c, f"tx[{i}]", t, ipub) te = t["envelope"] c.check(f"tx[{i}].binding_recomputed", te["transaction_binding"] == tx_digest(r["body"]), "binding does not match the signed request") c.check(f"tx[{i}].request_signed_by_subject", verify(te["subject_pub"], r["signature_b64"], D_E25_ENVELOPE, r["body"]), "request not signed by the identity key") c.check(f"tx[{i}].single_audience", te["audience"] == [art["domain"]], te["audience"]) nonces = [t["envelope"]["nonce"] for t in art["transaction_envelopes"]] c.check("tx.nonces_unique", len(set(nonces)) == len(nonces), "duplicate envelope nonce") # ---- identities for iid, rec in art["identities"].items(): c.check(f"identity[{iid[:12]}].digest", digest(D_IDENTITY, rec["body"]) == rec["digest"], "digest mismatch") c.check(f"identity[{iid[:12]}].labels", set(rec["body"]["labels"].values()) <= EPISTEMIC, rec["body"]["labels"]) # ---- delegation tokens toks = {t["token_id"]: t for t in art["delegation_tokens"]} for tid, t in toks.items(): b = t["body"] c.check(f"token[{tid[:12]}].id", "dlg_" + digest(D_DELEGATION, b)[:32] == tid, "token id") c.check(f"token[{tid[:12]}].signature", verify(t["signer_pub"], t["signature_b64"], D_DELEGATION, b), "sig") c.check(f"token[{tid[:12]}].no_authority", b.get("authority") == "NONE", b.get("authority")) if b["parent"]: p = toks.get(b["parent"]) c.check(f"token[{tid[:12]}].parent_known", p is not None, "orphan") if p: c.check(f"token[{tid[:12]}].subset", not subset_ok(b["constraints"], p["body"]["constraints"]), subset_ok(b["constraints"], p["body"]["constraints"])) c.check(f"token[{tid[:12]}].depth", b["depth"] == p["body"]["depth"] + 1, "depth") c.check(f"token[{tid[:12]}].continuity", p["body"]["delegate"] == b["delegator"], "discontinuous") c.check(f"token[{tid[:12]}].depth_limit", b["depth"] <= p["body"]["constraints"]["max_depth"], "depth beyond limit") # ---- lineage L = art["lineage"] pubs = {n["id"]: n.get("pub", "") for n in L["nodes"]} prev = "0" * 64 for i, e in enumerate(L["edges"]): b = e["body"] c.check(f"lineage[{i}].link", b["prev"] == prev, "broken link") c.check(f"lineage[{i}].hash", digest(D_LINEAGE, b) == e["edge_hash"], "hash") c.check(f"lineage[{i}].signature", verify(e["signer_pub"], e["signature_b64"], D_LINEAGE, b), "sig") if pubs.get(b["src"]): c.check(f"lineage[{i}].signer_is_source", pubs[b["src"]] == e["signer_pub"], "signer is not the source") prev = e["edge_hash"] pp = L["path_proof"] root = bytes.fromhex(pp["root"]) c.check("lineage.compressed_root", mth([leaf(bytes.fromhex(e["edge_hash"])) for e in L["edges"]]) == root, "compressed root") for it in pp["items"]: c.check(f"lineage.path[{it['index']}]", verify_inclusion(leaf(bytes.fromhex(it["edge"]["edge_hash"])), it["index"], pp["size"], [bytes.fromhex(x) for x in it["path"]], root), "path edge not included") c.check("lineage.path_root_is_human", pp["nodes"][0] in pubs and pp["nodes"][0] == art["identities"][ pp["nodes"][-1]]["body"]["principal"], pp["nodes"]) # ---- leases for i, l in enumerate(art["leases"]): c.check(f"lease[{i}].signature", verify(ipub, l["signature_b64"], D_LEASE, l["fields"]), "sig") c.check(f"lease[{i}].no_authority", l["fields"]["authority"] == "NONE", l["fields"]["authority"]) # ---- receipts R = art["receipts"] rpub, rs = R["signer_pub"], R["receipts"] prev = "0" * 64 for i, r in enumerate(rs): b = r["body"] c.check(f"receipt[{i}].seq", b["seq"] == i, b["seq"]) c.check(f"receipt[{i}].link", b["prev"] == prev, "broken chain") c.check(f"receipt[{i}].hash", digest(D_RECEIPT, b) == r["receipt_hash"], "hash") c.check(f"receipt[{i}].signature", verify(rpub, r["signature_b64"], D_RECEIPT, b), "sig") prev = r["receipt_hash"] allow = [r for r in rs if r["body"]["authorization_result"] == "ALLOW"] c.check("receipts.allow_have_e8_evidence", all(len(r["body"]["evidence_references"]) >= 3 for r in allow), "ALLOW receipt without kernel evidence reference") c.check("receipts.allow_nonces_unique", len({r["body"]["transaction_nonce"] for r in allow}) == len(allow), "an ALLOW nonce appears twice") c.check("receipts.timestamps_monotonic", all(rs[i]["body"]["authorization_timestamp"] <= rs[i + 1]["body"]["authorization_timestamp"] for i in range(len(rs) - 1)), "time goes backwards") txb = {t["envelope"]["transaction_binding"] for t in art["transaction_envelopes"]} c.check("receipts.allow_bound_to_envelopes", all(r["body"]["action_digest"] in txb for r in allow), "ALLOW receipt for an unbound transaction") revoked = set(art["revoked_identities"]) after = [r for r in rs if r["body"]["authorization_timestamp"] >= art["revoked_at"] and r["body"]["execution_identity"] in revoked] c.check("revocation.no_allow_after", after and all(r["body"]["authorization_result"] == "DENY" for r in after), "revoked identity got ALLOW") rp = [r for r in rs if r["receipt_hash"] == art["replay_receipt"]] c.check("replay.denied", rp and rp[0]["body"]["authorization_result"] == "DENY", "replay not refused") c.check("replay.reason", rp and any("REPLAY" in x or "REVOKED" in x for x in rp[0]["body"] ["authorization_reasons"]), rp[0]["body"]["authorization_reasons"] if rp else "") c.check("revocation.cascade_to_subagent", len(revoked) >= 2, sorted(revoked)) tokrev = set(art["delegation_revoked"]) c.check("revocation.tokens", all(t["token_id"] in tokrev for t in art["delegation_tokens"] if t["body"]["delegate"] in revoked), "live token for a revoked identity") # ---- transparency log lg = art["log"] leaves = [leaf(canonical(e)) for e in lg["entries"]] n = len(leaves) sth = lg["tree_head"] c.check("log.sth_signature", verify(sth["pub"], sth["signature_b64"], D_TREE_HEAD, sth["body"]), "sth sig") c.check("log.sth_size", sth["body"]["size"] == n, sth["body"]["size"]) c.check("log.sth_root", sth["body"]["root"] == mth(leaves).hex(), "root mismatch") c.check("log.indexes", [e["index"] for e in lg["entries"]] == list(range(n)), "index gap") root = mth(leaves) for p in lg["inclusion"]: c.check(f"log.inclusion[{p['index']}]", p["leaf"] == leaves[p["index"]].hex() and verify_inclusion( leaves[p["index"]], p["index"], n, [bytes.fromhex(x) for x in p["path"]], root), "inclusion") for p in lg["consistency"]: c.check(f"log.consistency[{p['old_size']}]", p["old_root"] == mth(leaves[:p["old_size"]]).hex() and verify_consistency(p["old_size"], n, [bytes.fromhex(x) for x in p["path"]], bytes.fromhex(p["old_root"]), root), "consistency") ev = {e["event"] for e in lg["entries"]} for need in ("REGISTRATION", "ATTESTATION", "DELEGATION", "MODEL_CHANGE", "LEASE", "REVOCATION"): c.check(f"log.has_{need}", need in ev, sorted(ev)) # ---- passport pp = art.get("passport") if pp: c.check("passport.signature", verify(ipub, pp["signature_b64"], D_PASSPORT, pp["body"]), "sig") c.check("passport.not_portable", pp["body"]["authority"]["value"]["portable"] is False, "portable authority") labels = [v["status"] for v in pp["body"].values() if isinstance(v, dict) and "status" in v] c.check("passport.labels", labels and set(labels) <= EPISTEMIC, sorted(set(labels))) c.check("passport.hardware_unknown", pp["body"]["attestation"]["value"]["hardware"] == "UNKNOWN", "hw") # ---- end to end want = ["EXTERNAL_AGENT", "CAIN_CONNECT", "PORTABLE_EXECUTION_IDENTITY", "BOUNDED_AUTHORITY", "DELEGATED_SUBAGENT", "MODEL_RUNTIME_CHANGE", "REAUTHORIZATION", "GOVERNED_ACTION", "E8", "MCP_A2A_API", "EXECUTION", "SUBAGENT_BOUNDED", "GOVERNANCE_RECEIPT", "INDEPENDENT_VERIFICATION", "REVOCATION", "FAILED_REPLAY"] got = [s["step"] for s in e2e["steps"]] c.check("e2e.steps_in_order", got == want, got) for s in e2e["steps"]: c.check(f"e2e.{s['step']}", s["ok"] is True, s) # ---- bench / invariants / mutation / conformance / certificate / scale b = load(d, "SECURITY_RESULTS.json") c.check("bench.all_contained", b["contained"] == b["scenarios"], f"{b['contained']}/{b['scenarios']}") c.check("bench.ids_distinct", len({r["id"] for r in b["rows"]}) == len(b["rows"]) == b["scenarios"], "dup ids") c.check("bench.rows_contained", all(r["contained"] for r in b["rows"]), "row not contained") for cat, tgt in CATEGORY_TARGETS.items(): got_n = sum(1 for r in b["rows"] if r["category"] == cat) c.check(f"bench.category.{cat}", got_n >= tgt, f"{got_n} < {tgt}") c.check("bench.at_least_150", b["scenarios"] >= 150, b["scenarios"]) inv = load(d, "INVARIANTS.json") c.check("invariants.at_least_75", inv["total"] >= 75, inv["total"]) c.check("invariants.all_hold", inv["passed"] == inv["total"] and all(r["ok"] for r in inv["rows"]), "failed") ids = {r["id"] for r in inv["rows"]} c.check("invariants.laws_I1_I20", all(f"E28-I{i}" in ids for i in range(1, 21)), "missing law") mut = load(d, "MUTATION_RESULTS.json") c.check("mutation.no_unexplained_survivors", mut["unexplained_survivors"] == [], mut["unexplained_survivors"]) c.check("mutation.majority_killed", mut["killed"] * 2 > mut["mutants"], f"{mut['killed']}/{mut['mutants']}") conf = load(d, "CONFORMANCE_RESULTS.json") c.check("conformance.not_certification", conf["is_certification"] is False, "claims certification") c.check("conformance.all_tested", conf["tested"] == conf["total"], f"{conf['tested']}/{conf['total']}") c.check("conformance.all_pass", conf["passed"] == conf["total"], conf["dimensions"]) cert = load(d, "GOVERNANCE_CERTIFICATE.json") c.check("certificate.signature", verify(cert["issuer_pub"], cert["signature_b64"], D_CERT, {k: cert["fields"].get(k) for k in sorted(cert["fields"])}), "cert sig") c.check("certificate.scoped", "not universal safety" in " ".join(cert["fields"]["limitations"]), "unscoped") c.check("certificate.matches_conformance", cert["fields"]["adversarial_tests"] == b["scenarios"], "count") sc = load(d, "SCALE_RESULTS.json") c.check("scale.classified_synthetic", "SYNTHETIC" in sc["classification"], sc["classification"]) sizes = [r["agents"] for r in sc["rows"]] for n_ in (10, 100, 1000, 10000, 100000): c.check(f"scale.size_{n_}", n_ in sizes, sizes) c.check("scale.no_failures", all(r["failures"] == 0 for r in sc["rows"]), [r["failures"] for r in sc["rows"]]) c.check("scale.virtual_labelled", any(r["kind"].startswith("VIRTUAL") for r in sc["rows"] if r["agents"] == 100000), "100k not labelled virtual") # ---- claims + limitations cl = load(d, "E28_PUBLIC_CLAIMS.json") for k in cl["claims"]: c.check(f"claim.{k['id']}.evidence", all((d / f).exists() for f in k["evidence"]), k["evidence"]) lim = load(d, "KNOWN_LIMITATIONS.json") c.check("limitations.published", len(lim["limitations"]) >= 5, len(lim["limitations"])) c.check("limitations.zk_not_claimed", any("Zero-knowledge" in x and "NOT" in x for x in lim["limitations"]), "zk") # ---- bundle integrity sums = {} for line in (d / "SHA256SUMS").read_text().splitlines(): hx, name = line.split(" ", 1) sums[name] = hx for name, hx in sorted(sums.items()): c.check(f"sha256.{name}", hashlib.sha256((d / name).read_bytes()).hexdigest() == hx, "hash mismatch") sig = load(d, "SIGNATURE.json") c.check("signature.files_match_sums", sig["files"] == sums, "SIGNATURE files differ from SHA256SUMS") c.check("signature.master_digest", sig["master"]["hashes_digest"] == h(sig["files"]), "master digest") c.check("signature.valid", verify(sig["signer_public_key_b64"], sig["signature_b64"], D_MASTER, sig["master"]), "master signature") out = {"verifier": "verify_e28.py", "imports_cain": False, "checks": c.checks, "passed": c.passed, "result": "INTACT" if c.passed == c.checks else "BROKEN", "problems": c.problems[:50]} print(json.dumps(out)) return 0 if out["result"] == "INTACT" else 1 if __name__ == "__main__": sys.exit(main())