#!/usr/bin/env python3 """Clean-room verifier for the CAIN-42 E33 (Governed Agentic Operating Fabric) evidence bundle. Imports nothing from CAIN; needs only `cryptography`. It re-derives: * every operation's lifecycle (explicit state order, no skips; only REASSESS operations may carry an E8 binding and a proof; refused and routed operations never reached E8); * each executed operation's E31 proof against the published anchors, and that the operation record binds exactly that proof's E8 entry and E25 receipt; * the canonical agent-event chain (and that no event carries private reasoning); * the sidecar ABI transcript (forged / malformed / impersonating requests got errors, never results); * coverage maps, negotiation intersections, degraded-mode tables and chaos results with its own rules; and must REJECT every object in MALICIOUS.json. python3 verify_e33.py """ from __future__ import annotations import base64 import hashlib import json import sys from pathlib import Path from cryptography.exceptions import InvalidSignature from cryptography.hazmat.primitives.asymmetric import ed25519 D_PROOF = "CAIN42/E31-GOVERNANCE-PROOF/v1" D_E28 = "CAIN42/E28-GOVERNANCE-RECEIPT/v1" D_E25 = "CAIN42/E25-EXECUTION-RECEIPT/v1" D_E8 = "CAIN42/E8-KERNEL-EVIDENCE/v1" D_EVENT = "CAIN42/E33-CANONICAL-AGENT-EVENT/v1" D_CONTRACT = "CAIN42/E33-GOVERNANCE-CONTRACT/v1" D_ABI = "CAIN42/E33-ABI-REQUEST/v1" D_DISCOVERY = "CAIN42/E33-SERVICE-RECORD/v1" D_MANIFEST2 = "CAIN42/E33-GOVERNABILITY-MANIFEST-V2/v1" D_CERT2 = "CAIN42/E33-MACHINE-GOVERNANCE-CERTIFICATE/v1" D_MASTER = "CAIN42/E33-MASTER/v1" OP_STATES = ("DISCOVER", "IDENTIFY", "UNDERSTAND", "PROPOSE", "SIMULATE", "ASSESS", "AUTHORIZE", "COMMIT", "ENFORCE", "EXECUTE", "OBSERVE", "VERIFY", "PROVE", "LEARN", "RECOVER_ADAPT", "REASSESS") TERMINAL = ("DENIED", "ROUTED", "FAILED_CLOSED") FORBIDDEN_EVENT_FIELDS = ("chain_of_thought", "reasoning_trace", "hidden_thoughts", "scratchpad") GOVERNED = {"a2a", "mcp", "http", "rest", "websocket", "event_bus", "message_queue", "local_ipc", "database", "browser", "cloud_api"} OBSERVED = {"file", "collaboration"} CERT_CLAIMS = {"identity_verified", "authorization_verified", "execution_boundary_verified", "proof_generated", "evidence_verified", "conformance_passed", "revocation_tested", "recovery_tested", "protocol_adapter_tested"} class Bad(Exception): pass def _chk(o, p="$"): if isinstance(o, bool) or o is None or isinstance(o, int): return if isinstance(o, float): raise Bad(p) if isinstance(o, str): if not o.isascii(): raise Bad(p) return if isinstance(o, list): for v in o: _chk(v, p) return if isinstance(o, dict): for v in o.values(): _chk(v, p) return raise Bad(p) def cj(o) -> bytes: _chk(o) return json.dumps(o, sort_keys=True, separators=(",", ":"), ensure_ascii=True).encode() def hh(o) -> str: return hashlib.sha256(cj(o)).hexdigest() def dg(domain, body) -> str: return hh({"domain": domain, "body": body}) def sig_ok(pub, sig, domain, body) -> bool: try: ed25519.Ed25519PublicKey.from_public_bytes(base64.b64decode(pub)).verify(base64.b64decode(sig), dg(domain, body).encode()) return True except (InvalidSignature, ValueError, TypeError, Bad): return False def kid(pub) -> str: return hashlib.sha256(base64.b64decode(pub)).hexdigest()[:16] class C: def __init__(self): self.checks, self.passed, self.problems = 0, 0, [] def check(self, name, ok, detail=""): self.checks += 1 if ok: self.passed += 1 else: self.problems.append(f"{name}: {detail}"[:300]) def load(d, n): return json.loads((d / n).read_text()) def proof_ok(p, att, an) -> bool: try: b = p["body"] k = an["proof_kids"].get(b["header"]["kid"]) e8 = att["e8_entry"] e8b = {x: y for x, y in e8.items() if x != "entry_hash"} return bool(k) and kid(k["pub"]) == b["header"]["kid"] and dg(D_PROOF, b) == p["proof_hash"] and \ sig_ok(k["pub"], p["signature_b64"], D_PROOF, b) and b["grants_authority"] is False and \ sig_ok(an["e28"], att["e28_receipt"]["signature_b64"], D_E28, att["e28_receipt"]["body"]) and \ sig_ok(an["e25"], att["e25_receipt"]["signature_b64"], D_E25, att["e25_receipt"]["body"]) and \ hashlib.sha256(cj({"domain": D_E8, **e8b})).hexdigest() == e8["entry_hash"] == \ b["enforcement"]["e8_entry_hash"] and e8["entry_hash"] in \ att["e28_receipt"]["body"]["evidence_references"] and e8["decision"] == "COMMITTED" and \ att["e25_receipt"]["body"]["status"] == "EXECUTED" except (KeyError, TypeError, ValueError, Bad): return False def op_problems(op, proofs, an) -> list: """Every reason this operation record is not a faithful governed operation.""" bad = [] try: hist = op["history"] seq = [h["to"] for h in hist] states = [s for s in seq if s not in TERMINAL] if states != list(OP_STATES[1:1 + len(states)]): bad.append("lifecycle_order") term = [s for s in seq if s in TERMINAL] if len(term) > 1 or (term and seq[-1] != term[0]): bad.append("terminal_not_last") f = op["fields"] if op["state"] == "REASSESS": if states != list(OP_STATES[1:]): bad.append("incomplete_lifecycle") pid = f["governance_proof"] pr = proofs.get(pid) if pr is None or not proof_ok(pr["proof"], pr["attachments"], an): bad.append("proof") else: att = pr["attachments"] if f["E8_binding"] != att["e8_entry"]["entry_hash"]: bad.append("e8_binding") if f["execution_receipt"] != att["e25_receipt"]["receipt_hash"]: bad.append("execution_receipt") if f["outcome"] != att["e25_receipt"]["body"]["result_hash"]: bad.append("outcome") if f["execution_identity"] != pr["proof"]["body"]["subject"]["execution_identity"]: bad.append("identity") if f["authorization"] != "ALLOW": bad.append("authorization") if f["capability_identity"] != pr["proof"]["body"]["action"]["capability"]: bad.append("capability") if f["policy_state"] != pr["proof"]["body"]["policy"]["policy_version"][:16]: bad.append("policy") if f["predicted_effect"].get("class") != "PREDICTION": bad.append("prediction_class") else: if f["E8_binding"] != "UNKNOWN" or f["governance_proof"] != "UNKNOWN": bad.append("refused_or_routed_but_bound_to_e8") if op["state"] == "ROUTED" and not str(f["authorization"]).startswith("ROUTED:"): bad.append("routed_label") if op["state"] == "DENIED" and f["authorization"] not in ("DENY", "UNKNOWN"): bad.append("denied_label") if f["delegation_chain"] in ("", None): bad.append("delegation_chain") except (KeyError, TypeError, ValueError, AttributeError) as e: bad.append(f"malformed:{type(e).__name__}") return bad def coverage(paths) -> dict: out = {} for p in paths: ch = "GOVERNED" if p["channel"] in GOVERNED else "OBSERVED" if p["channel"] in OBSERVED else "UNKNOWN" if p.get("through_cain") and p.get("e8") and ch == "GOVERNED": out[p["name"]] = "ENFORCED" elif p.get("through_cain") and not p.get("e8"): out[p["name"]] = "MONITORED" elif p.get("logged"): out[p["name"]] = "OBSERVED" elif ch == "UNKNOWN": out[p["name"]] = "UNKNOWN" else: out[p["name"]] = "BYPASSABLE" return out def rejected(m, an) -> bool: k, o = m["class"], m["object"] try: if k in ("identity", "authority", "capability", "policy", "action", "execution", "outcome", "delegation", "revocation"): return bool(op_problems(o["operation"], o["proofs"], an)) if k == "proof": return not proof_ok(o["proof"], o["attachments"], an) if k == "evidence": prev, bad = "0" * 64, False for i, e in enumerate(o["events"]): b = e["body"] if b["seq"] != i or b["prev"] != prev or dg(D_EVENT, b) != e["hash"] or hh(b["data"]) != b["data_digest"]: bad = True prev = e["hash"] return bad if k == "recovery": steps = [s["step"] for s in o["steps"]] return not (all(s["ok"] for s in o["steps"]) and steps == o["expected_order"]) if k == "learning": return o["claimed_state"] == "REASSESS" and o["actual_state"] != "REASSESS" if k == "evolution": return o["routed_kind_executed"] is True if k == "conformance": return o["claimed_level"] == "ENFORCED" and o["runtime"] not in ("generic_llm_agent", "mcp_agent", "a2a_agent") if k == "governance_coverage": return coverage(o["paths"]) != o["claimed_map"] except (KeyError, TypeError, ValueError, Bad): return True return False def main() -> int: d = Path(sys.argv[1]) if len(sys.argv) > 1 else Path(".") c = C() try: ops = load(d, "OPERATIONS.json") except (OSError, ValueError) as x: print(json.dumps({"result": "ERROR", "checks": 0, "passed": 0, "problems": [str(x)]})) return 2 an = ops["anchors"] proofs = ops["proofs"] states = {} for i, op in enumerate(ops["operations"]): p = op_problems(op, proofs, an) c.check(f"operation[{i}].{op['kind']}.{op['state']}", not p, p) states[op["state"]] = states.get(op["state"], 0) + 1 for s in ("REASSESS", "DENIED", "ROUTED"): c.check(f"operations.has_{s}", states.get(s, 0) > 0, states) ev = load(d, "EVENTS.json") prev = "0" * 64 for i, e in enumerate(ev["events"]): b = e["body"] c.check(f"event[{i}].chain", b["seq"] == i and b["prev"] == prev and dg(D_EVENT, b) == e["hash"] and hh(b["data"]) == b["data_digest"], "chain") c.check(f"event[{i}].no_private_reasoning", not any(f in b["data"] for f in FORBIDDEN_EVENT_FIELDS), "cot") prev = e["hash"] tr = load(d, "SIDECAR_TRANSCRIPT.json") for i, x in enumerate(tr["exchanges"]): req, resp, kind = x["request"], x["response"], x["kind"] if kind == "malformed": c.check(f"sidecar[{i}].malformed_refused", resp.get("error") == "ABI_MALFORMED", resp) continue body = {"abi": req["abi"], "op": req["op"], "args": req["args"]} valid = sig_ok(tr["abi_pub"], req["signature_b64"], D_ABI, body) if kind == "honest": c.check(f"sidecar[{i}].signature_valid", valid, "sig") c.check(f"sidecar[{i}].answered", resp.get("ok") is True, resp.get("error")) else: c.check(f"sidecar[{i}].{kind}_signature_invalid", not valid, "forged signature verifies") c.check(f"sidecar[{i}].{kind}_refused", resp.get("error") == "ABI_UNAUTHENTICATED", resp) ct = load(d, "CONTRACTS.json") for i, x in enumerate(ct["contracts"]): b = x["body"] c.check(f"contract[{i}].signature", sig_ok(x["pub"], x["signature_b64"], D_CONTRACT, b), "sig") c.check(f"contract[{i}].enforces_only_proven", set(b["enforces"]) <= set(x["probe_passed"]), sorted(set(b["enforces"]) - set(x["probe_passed"]))) c.check(f"contract[{i}].no_authority", b["authority"] == "NONE", b["authority"]) cv = load(d, "COVERAGE.json") for i, a in enumerate(cv["architectures"]): mine = coverage(a["paths"]) c.check(f"coverage[{i}].recomputed", mine == a["map"], "map differs") c.check(f"coverage[{i}].universal_consistent", a["universal"] == all(v == "ENFORCED" for v in mine.values()), "universal") ng = load(d, "NEGOTIATIONS.json") for i, x in enumerate(ng["negotiations"]): caps = sorted(set(x["a"]["capabilities"]) & set(x["b"]["capabilities"]) & set(x["a_grants"]) & set(x["b_grants"])) c.check(f"negotiation[{i}].intersection", x["result"]["agreement"]["capabilities"] == caps, caps) c.check(f"negotiation[{i}].no_authority", x["result"]["agreement"]["authority_created"] is False, "authority") dm = load(d, "DEGRADED_MODES.json") for m, spec in dm["modes"].items(): for r in dm["routes"]: allowed = r in dm["results"][m]["permitted"] prohibited = "*" in spec["prohibited"] or r in spec["prohibited"] or \ (spec["allowed"] and r not in spec["allowed"]) or not spec["allowed"] c.check(f"degraded.{m}.{r}", allowed != prohibited, f"allowed={allowed}") ch = load(d, "CHAOS.json") for x in ch["results"]: c.check(f"chaos.{x['fault']}", set(x["after"]) <= set(x["before"]), x["grew"]) im = load(d, "IMMUNE_INCIDENT.json") for x in im["immune"]: c.check(f"immune.{x['signal']}", all(s["ok"] for s in x["steps"]) and [s["step"] for s in x["steps"]] == im["immune_order"], "steps") c.check("incident.steps", all(s["ok"] for s in im["incident"]["steps"]) and [s["step"] for s in im["incident"]["steps"]] == im["incident_order"], "steps") cm = load(d, "CERTS_MANIFESTS.json") for i, x in enumerate(cm["certificates"]): c.check(f"certificate[{i}].signature", sig_ok(x["pub"], x["signature_b64"], D_CERT2, x["body"]), "sig") c.check(f"certificate[{i}].scoped_claims", set(x["body"]["claims"]) <= CERT_CLAIMS, sorted(x["body"]["claims"])) c.check(f"certificate[{i}].no_authority", x["body"]["grants_authority"] is False, "authority") for i, x in enumerate(cm["manifests"]): c.check(f"manifest[{i}].signature", sig_ok(x["pub"], x["signature_b64"], D_MANIFEST2, x["body"]), "sig") c.check(f"manifest[{i}].declares_unknowns", bool(x["body"]["unknown_states"]), "unknowns") for i, x in enumerate(cm["discovery"]): pub = cm["trusted_operators"].get(x["body"]["operator"], "") c.check(f"discovery[{i}].signed_by_trusted", sig_ok(pub, x["signature_b64"], D_DISCOVERY, x["body"]), "sig") e2e = load(d, "END_TO_END.json") c.check("e2e.ok", e2e["ok"] is True, "e2e") c.check("e2e.steps", len(e2e["steps"]) == 27, len(e2e["steps"])) for s in e2e["steps"]: c.check(f"e2e.{s['step']}", s["ok"] is True, s["step"]) cf = load(d, "CONFORMANCE.json") for rk, r in cf["runtimes"].items(): c.check(f"conformance.{rk}.status_legal", r["status"] in ("SUPPORTED", "PARTIAL", "SIMULATED", "OBSERVED", "ENFORCED", "UNKNOWN"), r["status"]) c.check(f"conformance.{rk}.enforced_only_when_measured", r["status"] != "ENFORCED" or ( r.get("measured") and r.get("refuses_out_of_scope") and r.get("proof_coverage_milli") == 1000), r) c.check("conformance.revocation", cf["revocation"] is True, "revocation") mal = load(d, "MALICIOUS.json") classes = set() for i, m in enumerate(mal["objects"]): c.check(f"malicious[{i}].{m['class']}.rejected", rejected(m, an), m["mutation"]) classes.add(m["class"]) need = {"identity", "authority", "capability", "policy", "delegation", "action", "execution", "evidence", "proof", "outcome", "revocation", "recovery", "learning", "evolution", "conformance", "governance_coverage"} c.check("malicious.classes", need <= classes, sorted(need - classes)) b = load(d, "SECURITY_RESULTS.json") c.check("bench.all_held", b["held"] == b["scenarios"], f"{b['held']}/{b['scenarios']}") c.check("bench.at_least_2000", b["scenarios"] >= 2000, b["scenarios"]) c.check("bench.26_categories", len(b["categories"]) >= 26, len(b["categories"])) for r in b["rows"]: c.check(f"bench.row.{r['id']}", r["held"] is True, r["detail"][:80]) inv = load(d, "INVARIANTS.json") c.check("invariants.at_least_500", inv["total"] >= 500, inv["total"]) c.check("invariants.all_hold", inv["passed"] == inv["total"], [r["id"] for r in inv["rows"] if not r["ok"]][:5]) c.check("invariants.40_laws", all(f"E33-L{i}" in {r["id"] for r in inv["rows"]} for i in range(1, 41)), "laws") mut = load(d, "MUTATION_RESULTS.json") c.check("mutation.all_killed", mut["killed"] == mut["mutants"] and not mut["survived"], mut["survived"]) c.check("mutation.at_least_10", mut["mutants"] >= 10, mut["mutants"]) sc = load(d, "SCALE_RESULTS.json") c.check("scale.synthetic_label", "SYNTHETIC" in sc["classification"], "label") got = {(r["dimension"], r["size"]) for r in sc["rows"]} for need_row in [("agents", n) for n in (10, 100, 1000, 10000, 100000)] + \ [("operations", n) for n in (1000, 10000, 100000, 1000000, 10000000)] + \ [("trust_domains", n) for n in (1, 10, 100, 1000)]: c.check(f"scale.{need_row[0]}.{need_row[1]}", need_row in got, "missing") for r in sc["rows"]: c.check(f"scale.{r['dimension']}.{r['size']}.no_failures", r["failures"] == 0, r["failures"]) reg = load(d, "REGISTERS.json") c.check("registers.cloud_not_deployed", all(v == "NOT DEPLOYED" for v in reg["cloud"].values()), "cloud") c.check("registers.no_market_moat", all(v["market_moat"] == "NOT ESTABLISHED" for v in reg["moat_graph"]["foundations"].values()), "moat") for it in reg["research_radar"]["items"]: c.check(f"research.{it['id']}.provenance", bool(it["source"]) and it["source"].startswith("https://"), it["id"]) lim = load(d, "KNOWN_LIMITATIONS.json") c.check("limitations.published", len(lim["limitations"]) >= 8, len(lim["limitations"])) cl = load(d, "E33_PUBLIC_CLAIMS.json") for k in cl["claims"]: c.check(f"claim.{k['id']}", all((d / f).exists() for f in k["evidence"]), k["evidence"]) sums = {} for line in (d / "SHA256SUMS").read_text().splitlines(): hx, name = line.split(" ", 1) sums[name] = hx for name, hx in sorted(sums.items()): c.check(f"sha256.{name}", hashlib.sha256((d / name).read_bytes()).hexdigest() == hx, "hash") sig = load(d, "SIGNATURE.json") c.check("signature.files", sig["files"] == sums, "files") c.check("signature.master_digest", sig["master"]["hashes_digest"] == hh(sig["files"]), "digest") c.check("signature.valid", sig_ok(sig["signer_public_key_b64"], sig["signature_b64"], D_MASTER, sig["master"]), "sig") out = {"verifier": "verify_e33.py", "imports_cain": False, "checks": c.checks, "passed": c.passed, "result": "INTACT" if c.passed == c.checks else "BROKEN", "problems": c.problems[:50]} print(json.dumps(out)) return 0 if out["result"] == "INTACT" else 1 if __name__ == "__main__": sys.exit(main())