#!/usr/bin/env python3 """Clean-room verifier for the CAIN-42 Evolution 7 + 8 proof bundle. IMPORTS NO CAIN-42 CODE. Uses only the standard library plus `cryptography` (Ed25519). It: 1. checks every file listed in MANIFEST.json against its SHA-256; 2. checks the two invariant matrices are well-formed and every check holds; 3. re-verifies the Ed25519 signature over each signed proof and over the master proof; 4. checks the module digests recorded in the master proof against the digests in the proofs. It proves the bundle is intact and self-consistent. It does NOT prove the code is correct or that CAIN is certified; the verifier was written by the same operator. Usage: python3 verify_e7_e8.py """ from __future__ import annotations import base64 import hashlib import json import sys from pathlib import Path from cryptography.exceptions import InvalidSignature from cryptography.hazmat.primitives.asymmetric import ed25519 def canon(o) -> bytes: return json.dumps(o, sort_keys=True, separators=(",", ":"), ensure_ascii=True).encode() def h(o) -> str: return hashlib.sha256(canon(o)).hexdigest() def digest(domain: str, fields: dict) -> str: return h({"domain": domain, **fields}) def verify(pub_b64: str, sig_b64: str, domain: str, fields: dict) -> bool: try: ed25519.Ed25519PublicKey.from_public_bytes(base64.b64decode(pub_b64)).verify( base64.b64decode(sig_b64), digest(domain, fields).encode()) return True except (InvalidSignature, ValueError, TypeError): return False def check_invariant_matrix(proof: dict, prefix: str, expected: set) -> list: problems = [] inv = proof.get("invariants") or {} checks = inv.get("checks") or [] ids = {c.get("id") for c in checks} if ids != expected: problems.append(f"{prefix}: invariant ids {sorted(ids)} != expected {sorted(expected)}") for c in checks: if not c.get("holds"): problems.append(f"{prefix}: invariant {c.get('id')} does not hold: {c.get('detail')}") if inv.get("all_hold") is not True: problems.append(f"{prefix}: all_hold is not true") if inv.get("failed"): problems.append(f"{prefix}: failed list is non-empty: {inv['failed']}") return problems def main() -> int: if len(sys.argv) < 2: print("usage: python3 verify_e7_e8.py ") return 2 d = Path(sys.argv[1]) problems: list = [] checks = 0 manifest = json.loads((d / "MANIFEST.json").read_text()) for name, want in manifest["files"].items(): got = hashlib.sha256((d / name).read_bytes()).hexdigest() checks += 1 if got != want: problems.append(f"file {name}: sha256 mismatch") e7 = json.loads((d / "CAIN42_EVOLUTION7_PROOF.json").read_text()) e8 = json.loads((d / "CAIN42_EVOLUTION8_PROOF.json").read_text()) master = json.loads((d / "CAIN42_EVOLUTION7_8_MASTER_PROOF.json").read_text()) problems += check_invariant_matrix(e7, "E7", {f"I{i}" for i in range(1, 13)}) checks += 1 problems += check_invariant_matrix(e8, "E8", {f"K{i}" for i in range(1, 23)}) checks += 1 for proof, domain in ((e7, "CAIN42/E7-PROOF/v1"), (e8, "CAIN42/E8-PROOF/v1")): body = {k: v for k, v in proof.items() if k != "signature_b64"} pub = (proof.get("signer") or {}).get("public_key_b64", "") checks += 1 if not pub or not verify(pub, proof.get("signature_b64", ""), domain, body): problems.append(f"{domain}: signature does not verify") body = {k: v for k, v in master.items() if k not in ("signature_b64", "signer_public_key_b64")} checks += 1 if not verify(master.get("signer_public_key_b64", ""), master.get("signature_b64", ""), "CAIN42/E7E8-MASTER/v1", body): problems.append("master proof: signature does not verify") checks += 1 flat_e7 = {k: v["sha256"] for k, v in (e7.get("modules") or {}).items()} if master.get("modules") != flat_e7: problems.append("master module digests do not match the E7 proof") result = {"bundle": str(d), "checks": checks, "problems": problems, "result": "INTACT" if not problems else "FAILED"} print(json.dumps(result, indent=2)) return 0 if not problems else 1 if __name__ == "__main__": raise SystemExit(main())