CAIN-42 Public Proof Fabric
===========================
Save verify_proof_fabric.py.txt as verify_proof_fabric.py (Python 3 + `cryptography`; it imports nothing from CAIN).

  python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric/            # this bundle, recomputed
  python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric/ --claims --text
        # plus every signed claim: registry signature, and each artifact's SHA-256 fetched from all 3 sites
  python3 verify_proof_fabric.py --pack https://clawx.click/evidence/proof-fabric/CAIN42_EVIDENCE_PACK.zip

What it recomputes: the artifact tree hash, deployment id and configuration hash; SBOM and test counts against
the published JUnit XML; every test vector with its own implementations; the provenance graph; the failure ledger.

What it cannot do: rebuild the gateway (its source is not public) or attest hardware (none exists). The tests
need the repository; the verifiers do not. Nothing here is a third-party review.
