CAIN-42 cluster fault-test bundle (2026-09-21) - what this is and is not. Verify (needs only python3 + `cryptography`; the verifier imports nothing from CAIN): curl -O https://cainstudio.online/proof/bundle/cluster-fault-test-2026-09-21/bundle.json curl -o verify_cluster_evidence.py https://cainstudio.online/proof/bundle/cluster-fault-test-2026-09-21/verify_cluster_evidence.py.txt python3 verify_cluster_evidence.py bundle.json Expected: "VERIFIED: 31/31 checks". It re-checks Ed25519 node state proofs, quorum-certificate signers (distinct valid signers >= quorum 3 of 4), cross-node agreement of state roots, and that QC membership keys equal the keys the nodes reported. Scenarios recorded (disposable 4-node twin cluster, PBFT n=4, f=1, quorum 3): baseline 4/4; commit with 4; crash 1 -> commit with 3; restart -> sampled ~12s after the node was reachable: NOT yet converged (node-4 was at sequence 1, the others at 2; see run2 for a 121s observation); crash 2 (beyond f) -> commit must not succeed; restart -> recovery. NOT PROVEN (also listed in bundle.json "not_claimed"): independent failure domains (one host, one image, one Docker daemon), network partitions, a malicious equivocating validator on the live wire, long-duration behaviour, fault injection on the live cluster (only a disposable twin), any third-party review. Status: CORRECTION 2026-09-21: the earlier wording 'convergence observed' was inaccurate for this run. See ../cluster-fault-test-2026-09-21-run2/REPRODUCE.txt.