CAIN-42 invariant · E24
NET-S-code-rollback: a rolled-back code is refused
Held · CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric
Last reviewed 2026-10-01
held niche Core guarantees
What this rule means
CAIN-42 must always satisfy: a rolled-back code is refused. It is one of 298 invariants checked for CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.
Recorded detail
[
"ARTIFACT_VERSION_ROLLBACK"
]Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Check it yourself
Browse the raw bundle · SHA-256 manifest
Related rules
- NET-I045: unknown execution state remains unknown
- NET-I054: a legitimately re-attested agent is restored with its history intact
- NET-I057: VERIFIED is not translated as HIGH
- NET-S-plugin-rollback: a rolled-back plugin is refused
- NET-S-skill-rollback: a rolled-back skill is refused
- NET-S-prompt-rollback: a rolled-back prompt is refused
- NET-S-agent-rollback: a rolled-back agent is refused
- NET-L05: NET-L05 EXECUTION IS NOT SUCCESS
← NET-S-code-tamper · all 298 · NET-S-agent-tamper →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem