{
 "schema": "cain42.l5.bypass-report.v1",
 "generated_at": "2026-09-28T07:03:12Z",
 "method": "classified from the repository's own enforcement surfaces; RAW = a process that does not route through CAIN/MCPGate is not seen by CAIN",
 "surfaces": [
  {
   "surface": "shell",
   "where": "cain45/confine.py",
   "control": "ZoD: bubblewrap namespaces, uid 65534, cgroup v2, seccomp-BPF",
   "classification": "GOVERNED_IN_ZOD",
   "note": "executing outside a ZoD is the RAW gap (unconfined process)"
  },
  {
   "surface": "filesystem",
   "where": "cain45/confine.py",
   "control": "read-only system, tmpfs; lab writes confined to lab_sessions/",
   "classification": "GOVERNED_IN_ZOD",
   "note": "an unconfined process has normal filesystem rights"
  },
  {
   "surface": "database",
   "where": "clawx/control_plane/resources.py",
   "control": "ResourceLedger / FinancialGate on granted resources",
   "classification": "GOVERNED_IN_ZOD",
   "note": "direct DB access outside the governed path is not intercepted"
  },
  {
   "surface": "network",
   "where": "cain45/confine.py",
   "control": "network namespace, egress deny-all",
   "classification": "GOVERNED_IN_ZOD",
   "note": "none in-ZoD; outside is the RAW gap"
  },
  {
   "surface": "mcp",
   "where": "cain/mcp_proxy.py",
   "control": "MCPGate verifies agent identity, authority, decision signature, action hash",
   "classification": "GOVERNED",
   "note": "the tool call boundary is enforced by default on the hosted path"
  },
  {
   "surface": "http",
   "where": "platform-gateway",
   "control": "tenant write gate + operator key; audited by authority_boundary_audit",
   "classification": "GOVERNED",
   "note": "0 unreviewed anonymous writes (see CAIN42_AUTHORITY_BOUNDARY_AUDIT.json)"
  },
  {
   "surface": "container",
   "where": "cain45/confine.py",
   "control": "cgroup v2 limits + freeze/kill in the ZoD",
   "classification": "GOVERNED_IN_ZOD",
   "note": "container runtime itself is host-operational, outside the agent boundary"
  },
  {
   "surface": "kubernetes",
   "where": "deploy/helm",
   "control": "Helm appliance (client clusters)",
   "classification": "OUTSIDE_BOUNDARY",
   "note": "not run on this host; no kubectl present"
  },
  {
   "surface": "cloud",
   "where": "deploy/multi-region",
   "control": "operator-held; not an agent action surface",
   "classification": "OUTSIDE_BOUNDARY",
   "note": "operator infrastructure, not exposed to agents"
  },
  {
   "surface": "deployment",
   "where": "cain45/hypervisor.py",
   "control": "DEPLOY_INFRASTRUCTURE capability is grant-gated",
   "classification": "GOVERNED_IN_ZOD",
   "note": "a deployment tool call without the capability is refused"
  },
  {
   "surface": "financial",
   "where": "clawx/control_plane/resources.py",
   "control": "CAPABILITY TRANSFER_FUNDS + two-person rule on irreversible",
   "classification": "GOVERNED_IN_ZOD",
   "note": "none in-ZoD"
  },
  {
   "surface": "messaging",
   "where": "\u2014",
   "control": "no first-party messaging/email capability is implemented",
   "classification": "NOT_IMPLEMENTED",
   "note": "not a governed surface because it does not exist yet"
  },
  {
   "surface": "email",
   "where": "\u2014",
   "control": "same",
   "classification": "NOT_IMPLEMENTED",
   "note": "same"
  },
  {
   "surface": "secrets",
   "where": "\u2014",
   "control": "no credential broker implemented; SECRET_ACCESS is a declared capability only",
   "classification": "NOT_IMPLEMENTED",
   "note": "secret access is not yet a mediated surface"
  }
 ],
 "known_raw_gap": "an agent that runs its own process outside a ZoD and does not call MCPGate is not governed (stated on the homepage and in CAIN45_BYPASS_AUDIT.json)",
 "bypass_audit_summary": {
  "PASS": 5,
  "INCONCLUSIVE": 3,
  "GAP": 1
 },
 "unreviewed_anonymous_writes": []
}
