Proof that the live egress and toolargs decision stages are inside each decision's signed evidence — the change a digest catches.
Honest limits: this proves the digest recipe and tamper-detection, not that the decisions are true. The signing key is operator-held; this is not independent verification.
| Record | Digest | Stage verdicts |
|---|---|---|
| allowed | 28f24c54d94f7cd4fcd0deebf90e90a4… | egress=allow, toolargs=allow |
| egress_denied | 39a5803008499612b4caadd2734aa4aa… | egress=deny, toolargs=allow |
| toolargs_denied | 5f186779d1496ec8a404267d041a2afd… | egress=allow, toolargs=deny |
the 'allowed' record with its egress verdict flipped after signing. Detected: True.
Recorded digest 28f24c54d94f7cd4fcd0deebf90e90a4… vs re-derived
39a5803008499612b4caadd2734aa4aa….
python3 verify_stage_proof.py
Needs only the cryptography package; imports nothing from CAIN.