CAIN-42 IP hardening, batch 1 (2026-10-06)

WE ATTACKED OUR OWN TOP INVENTIONS, FOUND 12 REAL DEFECTS AND CLOSED EVERY ONE. EACH FIX IS PROVEN BY A TEST THAT FAILED BEFORE IT.

What was fixed

How it was proven

18 new tests (23 test cases) were written first; 22 of the 23 cases failed against the old code (the 23rd, an S3 public-read ACL, was already handled). All 23 pass now. Wider regression: 140 of 140 in the proof run in this bundle, plus 234 trust and trajectory tests, 150 decision-pipeline tests, the 40-attack mission lab and the mission race tests. A second held-out attack set, written after the trajectory change and run once without tuning, went from 4 of 5 attacks running unattended to 2 of 5. The 2 that remain are listed openly in limits_closed_2026-10-06.json.

Files: RESULTS.json · trajectory · snapshot race · mission budgets · junit.xml · manifest.json (SHA-256 of every file). Source code is not published; the bundle carries results and hashes only.

Limits. Same-project tests, not third-party assurance. Snapshot race verified against a scripted quorum, not the live clusters. Two trajectory attack variants remain open. PRE-PRODUCTION.