{
 "bundle": "boundary-hardening-2026-10-06",
 "generated": "2026-10-06T23:14:42+00:00",
 "test_run": {
  "tests": 322,
  "failures": 0,
  "errors": 0,
  "skipped": 0,
  "passed": 322
 },
 "deploy": "scripts/ops/rolling_deploy.py, tag deploy/20261006T230837Z, both gateway instances",
 "live_after_deploy": {
  "at": "2026-10-06T23:14:42+00:00",
  "forged_unsigned_a2a_card": {
   "cainstudio.online": {
    "allowed": false,
    "capability_provenance": "SELF_ASSERTED"
   },
   "mcpgate.online": {
    "allowed": false,
    "capability_provenance": "SELF_ASSERTED"
   },
   "clawx.click": {
    "allowed": false,
    "capability_provenance": "SELF_ASSERTED"
   }
  },
  "public_demo_decision_safe_read": {
   "cainstudio.online": "REQUIRE_APPROVAL",
   "mcpgate.online": "REQUIRE_APPROVAL",
   "clawx.click": "REQUIRE_APPROVAL"
  }
 },
 "fixes": [
  {
   "commits": "896848d6",
   "area": "MCPGate",
   "what": "The proxy forwarded CAIN's own authorization envelope (_cain_* arguments) and the caller's Authorization, X-API-Key and cookies to the downstream tool server. The tool server now receives only the call and an allow-list of protocol headers; a requested kernel sandbox that cannot be built stops the tool server from starting instead of running it unconfined.",
   "tests": "tests/test_mcpgate_forwarding_hygiene.py"
  },
  {
   "commits": "5ce2d7f9",
   "area": "Shipped package",
   "what": "The installable package carried stale copies of eight security modules, including identity defects already fixed in the gateway (sub-agents inheriting every parent capability, revocation not cascading, a nonce race). The package now carries the fixed modules.",
   "tests": "tests/test_substrate_gateway_parity.py"
  },
  {
   "commits": "01731e4a",
   "area": "Agent passports on the hosted path",
   "what": "Signed agent passports were checked only by an opt-in MCPGate gate. The hosted decision path now runs the passport check, and the agent-signed request must describe the exact call being decided (tenant, tool, arguments, calling agent); a tenant can require a passport on every call.",
   "tests": "tests/test_fabric_passport_stage.py"
  },
  {
   "commits": "50adc064, 9f2ffcaa",
   "area": "Tamper-evident identity log",
   "what": "The identity and passport audit log was append-only by convention. It is now hash-chained per tenant, the issuer signs checkpoints, and a standalone verifier with no CAIN imports detects edited, deleted, reordered and truncated history.",
   "tests": "tests/test_identity_audit_chain.py"
  },
  {
   "commits": "1d632b0f, 2ea07272, 509c5f25",
   "area": "Trajectory governance",
   "what": "Trust earned on cheap reads no longer unlocks high-risk actions, and sequences of individually allowed calls go to a human: a sensitive read followed by an outbound call (also when two keys of one tenant split it), a privilege raised step by step, split payments, a look-alike tool, and the same consequential call repeated in a tight loop.",
   "tests": "tests/test_mission3_trajectory_governance.py"
  },
  {
   "commits": "c9e3557d, 81bf32ab",
   "area": "Emergency controls",
   "what": "The operator's cluster emergency halt and agent quarantines did not stop hosted decisions. They now halt every tenant (or the quarantined agent) in enforce and shadow mode alike, and an unreadable halt store fails closed.",
   "tests": "tests/test_fabric_global_freeze.py"
  },
  {
   "commits": "993a8cb0",
   "area": "Physical safety envelope",
   "what": "A tenant-owned envelope per device (geofence, speed, payload, battery, sensor freshness and agreement) refuses out-of-envelope physical actions deterministically, even in shadow mode. Device state is self-reported and not hardware-attested.",
   "tests": "tests/test_fabric_physical_stage.py"
  },
  {
   "commits": "34d69e8b, bf2c39d0",
   "area": "Agent-to-agent (A2A)",
   "what": "The public delegation verifier answered 'cryptographically verified' without checking any signature, and the guard accepted a forged card for a registered agent signed with the caller's own key. Card and delegation signatures are now verified, a registered agent's card is checked only against the issuer key, and capabilities are labelled self-asserted.",
   "tests": "tests/test_cain42_phase3_frontier.py, tests/test_guard_a2a_cards.py"
  },
  {
   "commits": "13d2d291, 2adb8c56",
   "area": "Agents cannot raise their own authority",
   "what": "An agent key could promote its own memory (stored as if from a human) to TRUSTED, create or loosen policies, switch off the kill switch and resume itself after being paused. Agent keys can now only lower trust and cannot operate the controls that govern them.",
   "tests": "tests/test_memory_authority_laundering.py, platform-gateway/tests/test_agent_cannot_operate_controls.py"
  }
 ],
 "independence": "same-project, self-verified; not third-party",
 "source_published": false
}
