# acp-evolution03-state-2026-10-05 -- CAIN ACP Evolution 03: quorum-certified governance state root

What this shows (IMPLEMENTATION-TESTED: real ACP ledger + production PBFT engine code, one process, one
host, in-process network; NOT deployed to the live clusters; no third-party review):

* every replica receipt commits to an RFC 6962 Merkle root over the full governance state; >= quorum
  matching receipts certify it; f Byzantine signers cannot certify a forged root (N=4, 5, 7);
* agents whose observed effect or own report contradicts their authorization are contained on every
  replica at the same sequence number, until a quorum release and a fresh trust attestation;
* governed memory never changes an authorization verdict.

Verify offline (needs only Python 3 + `cryptography`; imports no CAIN code):

    python3 verify_state_root.py E03_STATE_BUNDLE.json      # expect "verdict": "VERIFIED"

Then tamper with any receipt, snapshot value, dimension proof or evidence-log entry and run it again.
Bounded TLA+ model and TLC output: StateCertification.* / TLC_*.txt. Full report with limitations,
findings (incl. a critical fix to the earlier govkernel E03S layer) and IP/reproduction notes:
E03_STATE_FABRIC_REPORT.md. Implementation source is not published; SOURCE_COMMITMENTS.json pins it.
