# CAIN-42 E13 — quorum-governed, kernel-enforced execution

**Classification: IMPLEMENTED, TESTED (library + live kernel lifecycle on the build host); NOT DEPLOYED at MCPGate or the hosted gateway; enforcer fixes F13-1..4 ARE live**

## Verify this bundle

    # from this directory's parent, after downloading the bundle and the publisher attestation
    python3 verify_publisher.py e13-bpf-governance-execution-2026-10-05 e13-bpf-governance-execution-2026-10-05.attestation.json \
      && python3 e13-bpf-governance-execution-2026-10-05/verify_e13.py.txt e13-bpf-governance-execution-2026-10-05

`verify_publisher.py` proves the bytes are exactly what the pinned CAIN publisher key signed.
`verify_e13.py.txt` has zero CAIN imports (standard library + `cryptography`). It recomputes the published
artifacts and re-hashes every file. Both must pass.

## What it proves / does not prove

- Proves: the published artifacts are internally consistent under the rules in the bundle's spec, and were
  published by CAIN's key.
- Does NOT prove: independent (third-party) verification. The publisher key and the verifier are CAIN's own.
