CAIN-42 IP hardening, batch 1 (2026-10-06)
WE ATTACKED OUR OWN TOP INVENTIONS, FOUND 12 REAL DEFECTS AND CLOSED EVERY ONE. EACH FIX IS PROVEN BY A TEST THAT FAILED BEFORE IT.
What was fixed
- Quorum-committed authorization snapshots (patent packet PP-01). A grant revoked while the reconciler was committing an earlier snapshot could still be published, and other gateway workers then authorized the revoked agent on the fast path until the snapshot expired. Now the grant must still be active, at the same generation, when a snapshot is built, published, adopted or reloaded.
- Mission goal-attenuation lattice (patent packet PP-02). Four budget defects: a negative spend refilled the mission budget; a goal's budget was checked per request, not cumulatively; a negative sibling budget inflated the allocation sum; malformed amounts crashed instead of being denied. Spending now counts against the goal and every ancestor.
- Trajectory governance (salami-attack defense). Three limits closed: calls in flight together now see each other (read+send, split payments and parallel retry storms were judged against an empty history); a read from a CRM, HR, billing or health system, or addressed to a person, is a sensitive read; making data public counts as data leaving.
- SLO endpoint. Callers without a key and any customer key received absolute decision counts across all tenants, and completeness was a hard-coded 100%. Counts are now operator-only, and an unmeasured figure is reported as not measured.
How it was proven
18 new tests (23 test cases) were written first; 22 of the 23 cases failed against the old code (the 23rd, an S3 public-read ACL, was already handled). All 23 pass now. Wider regression: 140 of 140 in the proof run in this bundle, plus 234 trust and trajectory tests, 150 decision-pipeline tests, the 40-attack mission lab and the mission race tests. A second held-out attack set, written after the trajectory change and run once without tuning, went from 4 of 5 attacks running unattended to 2 of 5. The 2 that remain are listed openly in limits_closed_2026-10-06.json.
Files: RESULTS.json · trajectory · snapshot race · mission budgets · junit.xml · manifest.json (SHA-256 of every file). Source code is not published; the bundle carries results and hashes only.
Limits. Same-project tests, not third-party assurance. Snapshot race verified against a scripted quorum, not the live clusters. Two trajectory attack variants remain open. PRE-PRODUCTION.