#!/usr/bin/env python3 """Clean-room verifier for CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json. Imports nothing from CAIN; stdlib (+ `cryptography` for the signature). Checks (each printed PASS / FAIL / SKIPPED; SKIPPED is never counted as PASS): 1 bundle_sha256 equals the SHA-256 of the canonical JSON of the bundle without its hash and signature 2 the Ed25519 signature over that hash verifies against the embedded public key 3 internal consistency: counts equal what the per-attack list implies; every claim's "supported" equals "all its tests PASSED"; every attack BLOCKED/SUCCEEDED from a handler added here carries a passing positive control and simulated=true 4 the overall status is not stronger than the evidence: claims may not be all-supported while any listed test failed 5 (--files DIR) every source file hash matches the file in DIR 6 (--sites) the same bundle bytes are served on cainstudio.online, mcpgate.online and clawx.click Exit code 0 only if nothing FAILED. Signature verification proves integrity since signing by the key holder, NOT independent review. """ import argparse, base64, hashlib, json, os, sys, urllib.request def canonical(o): return json.dumps(o, sort_keys=True, separators=(",", ":"), ensure_ascii=False).encode() def main(): ap = argparse.ArgumentParser() ap.add_argument("bundle", nargs="?") ap.add_argument("--files", help="repo root to re-hash sources against") ap.add_argument("--sites", action="store_true", help="fetch the bundle from all three sites and compare bytes") ap.add_argument("--path", help="override the bundle path on every site (default: try the API route, then the static paths)") a = ap.parse_args() results = [] def rec(name, status, detail=""): results.append((name, status)); print(f"{status:8} {name}" + (f" -- {detail}" if detail else "")) raw = None if a.sites: bodies = {} for h in ("cainstudio.online", "mcpgate.online", "clawx.click"): paths = [a.path] if a.path else ["/api/v1/frontier-trust/bundle.json", "/proof/bundle/v2/CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json", "/evidence/CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json"] bodies[h] = None for pth in paths: try: body = urllib.request.urlopen(f"https://{h}{pth}", timeout=20).read() json.loads(body) # a 200 that is an HTML error page must not count bodies[h] = body; break except Exception: continue if bodies[h] is None: rec(f"fetch {h}", "FAIL", "no candidate path served the bundle") got = {h: hashlib.sha256(b).hexdigest() for h, b in bodies.items() if b} rec("same bytes on all three sites", "PASS" if len(got) == 3 and len(set(got.values())) == 1 else "FAIL", json.dumps(got)) raw = next((b for b in bodies.values() if b), None) if raw is None: if not a.bundle: print("give a bundle path or --sites"); return 2 raw = open(a.bundle, "rb").read() b = json.loads(raw) body = {k: v for k, v in b.items() if k not in ("bundle_sha256", "signature")} h = hashlib.sha256(canonical(body)).hexdigest() rec("bundle_sha256 recomputed", "PASS" if h == b.get("bundle_sha256") else "FAIL", h[:16]) sig = b.get("signature") if not sig: rec("signature", "SKIPPED", "bundle is unsigned") else: try: from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey Ed25519PublicKey.from_public_bytes(base64.b64decode(sig["public_key_b64"])).verify( base64.b64decode(sig["signature_b64"]), b["bundle_sha256"].encode()) rec("ed25519 signature", "PASS", "integrity since signing; signer is the author") except ImportError: rec("ed25519 signature", "SKIPPED", "install `cryptography` to verify") except Exception as e: rec("ed25519 signature", "FAIL", type(e).__name__) suite = b.get("attack_suite", {}) attacks = suite.get("attacks", []) derived = {} for x in attacks: derived[x["result"]] = derived.get(x["result"], 0) + 1 rec("suite counts match per-attack list", "PASS" if derived == suite.get("counts") and len(attacks) == suite.get("total") else "FAIL") added = set(suite.get("handlers_added_in_this_work", [])) bad = [x["attack_type"] for x in attacks if x["attack_type"] in added and x["result"] in ("ATTACK_BLOCKED", "ATTACK_SUCCEEDED") and not (x["evidence"].get("positive_control") is True and x["evidence"].get("simulated", True) is True)] rec("handlers added here: BLOCKED/SUCCEEDED only with a passing positive control", "PASS" if not bad else "FAIL", ",".join(bad)) conc = sum(1 for x in attacks if x["attack_type"] in added and x["result"] in ("ATTACK_BLOCKED", "ATTACK_SUCCEEDED")) rec(f"handler results conclusive: {conc}/{len(added)}", "INFO", "INCONCLUSIVE means a fixture/control could not run; it is not a pass") rec("handler results agree with per-attack list", "PASS" if suite.get("handlers_added_results") == { x["attack_type"]: x["result"] for x in attacks if x["attack_type"] in added} else "FAIL") outcomes = b.get("test_outcomes", {}) bad_claims = [c["claim"][:60] for c in b.get("claims", []) if c["supported"] != all(outcomes.get(t) == "PASSED" and v == "PASSED" for t, v in c["tests"].items())] rec("each claim's 'supported' equals 'all its tests PASSED'", "PASS" if not bad_claims else "FAIL", "; ".join(bad_claims)) failed = [t for t, s in outcomes.items() if s != "PASSED"] rec("no failed/errored test in the recorded run", "PASS" if not failed else "FAIL", ",".join(failed[:5])) rec("not_claimed and open_findings are present", "PASS" if b.get("not_claimed") and b.get("open_findings") else "FAIL") rec("status is not stronger than ", "PASS" if b.get("status") == "" else "FAIL", str(b.get("status"))) if a.files: bad = [] for s in list(b.get("sources", [])) + [{"path": t["file"], "sha256": t.get("sha256")} for t in b.get("test_runs", [])]: p = os.path.join(a.files, s["path"]) if not os.path.exists(p) or hashlib.sha256(open(p, "rb").read()).hexdigest() != s["sha256"]: bad.append(s["path"]) rec("source file hashes match", "PASS" if not bad else "FAIL", ",".join(bad)) else: rec("source file hashes match", "SKIPPED", "pass --files ") fails = [n for n, s in results if s == "FAIL"] print(f"\n{'VERIFIED' if not fails else 'REJECTED'}: {len(results) - len(fails)} not failed, {len(fails)} failed" f" ({sum(1 for _, s in results if s == 'SKIPPED')} skipped). This is not independent review.") return 1 if fails else 0 if __name__ == "__main__": sys.exit(main())