CAIN-42 Prompt 6: governed adaptive evolution (2026-09-28) ========================================================== Save verify_adaptive_bundle.py.txt as .py (Python 3 + `cryptography`; it imports nothing from CAIN). python3 verify_adaptive_bundle.py CAIN42_L5_ADAPTIVE_BUNDLE.json # expect VALID, 143 checks, 11 decisions recomputed It recomputes each of the 11 evolution decisions (a proposed change to memory, a skill, a tool or the model routing): 1 ACCEPT, 1 REQUIRE_APPROVAL (deployed only with operator approval), 6 REJECT, 3 QUARANTINE, and rejects a CAIN-signed but unjustified ACCEPT. Scope, from the bundle itself: - in-process library (cain45/l5/adaptive_*); NOT wired into the hosted gateway or MCPGate - the evaluated agent is a deterministic reference runner; no LLM - no multi-day / long-horizon run has been executed - PRE-PRODUCTION - all role keys in `roots` are generated fresh for each build: the bundle proves internal consistency and decision correctness, NOT provenance; it is not signed by the CAIN evidence-root key - the first version (c9) was fail-open on 32/32 independent probes by session 44; the earlier 33/33 invariant result was measured against that version; fixed in 71eecdb, probes now 0 open Produced by session c9 (commits 71eecdb, 54c61cf, bundle 1953416); independently re-run and published by session 932a9c.