CAIN-42 multi-region PBFT cluster -- fault-injection evidence: multi-region-cluster-2026-09-26 ======================================================================== What: Every quorum certificate the live 4-replica CAIN-42 PBFT cluster cain-mr-01 produced during a fault-injection run across three Vultr regions (Atlanta, Los Angeles x2, Miami) connected by a WireGuard overlay: baseline, each remote region stopped in turn, the two-replica host stopped (must fail closed), the Atlanta region with the primary killed (view change), and full recovery. Classification: MEASURED on the live multi-region cluster cain-mr-01 (3 Vultr regions, 3 hosts, 4 replicas) Generated: 2026-09-26T18:27:22Z Source commitment: git e1cf69c9c394f685e16a9631f38683eef8ec1a05, image sha256:95d0ddfb2401806daac805c03f7d0b87e34be908252b65f8b4700377c9262525 (engine 33.4-production-hardened); source is not published. Topology: n=4 f=1 quorum=3; placement {"cain-mr-node-1": "atl", "cain-mr-node-2": "lax", "cain-mr-node-3": "lax", "cain-mr-node-4": "mia"} Tolerates: any 1 Byzantine replica; loss of the atl host; loss of the mia host Does not tolerate: loss of the lax host (2 replicas); loss of 2 replicas anywhere Fault schedule (real `docker stop` of replicas on their own hosts): A_baseline 20/20 committed, expected COMMIT PASS B_mia_down 6/6 committed, expected COMMIT PASS C_one_lax_replica_down 6/6 committed, expected COMMIT PASS D_lax_host_down 0/3 committed, expected NO_COMMIT (fail closed) PASS E_atl_region_and_primary_down 6/6 committed, expected COMMIT PASS F_all_back 3/3 committed, expected COMMIT PASS Baseline commit latency (client -> committed ALLOW, sequential, n=20): p50 501.74 ms, p95 796.63 ms, p99 1480.35 ms, max 1480.35 ms Method: client on the atl host (over WireGuard), HTTP POST /api/v1/cluster/pbft/request to the entry replica, wall time until the committed ALLOW response; sequential requests, concurrency 1; atl host is a 2 vCPU / 3.4 GB VM also running other workloads Verify in under a minute (Python 3.8+, `pip install cryptography`, no CAIN code): BASE=https://cainstudio.online/proof/bundle/multi-region-cluster-2026-09-26 # or https://mcpgate.online/proof/bundle/multi-region-cluster-2026-09-26 # or https://clawx.click/evidence/multi-region-cluster-2026-09-26 curl -so verify_pbft_qc_bundle.py "$BASE/verify_pbft_qc_bundle.py.txt" curl -so verify_multi_region_bundle.py "$BASE/verify_multi_region_bundle.py.txt" curl -so MULTI_REGION_BUNDLE.json "$BASE/PBFT_QC_BUNDLE.json" sha256sum MULTI_REGION_BUNDLE.json verify_pbft_qc_bundle.py verify_multi_region_bundle.py # expect 393d88099d4d62686abff3bf0da841808741717a0978626b04d34e678f35fd4b MULTI_REGION_BUNDLE.json # expect ba452ce42528f11f7f5235727a65cae25a34072bc52b4711fd72581615d06009 verify_pbft_qc_bundle.py # expect 7e5815cbf62c9cf7bbd3adfefefbbed8fb44ceb4b0cd149f8c7ac4f2cbf2b167 verify_multi_region_bundle.py python3 verify_multi_region_bundle.py MULTI_REGION_BUNDLE.json Or open $BASE/index.html -- your browser runs the certificate checks and the fault-schedule checks. The live cluster itself: /live-cluster.html on any of the three sites (read-only, verified in your browser). Not claimed: tolerance of losing the Los Angeles host: it holds 2 of 4 replicas, so losing it halts progress (safety kept); independent providers: all three hosts are Vultr, one account, same image; region placement is operator-attested (host facts below), not cryptographically proven; hardware attestation (no TPM/TEE on these VMs); third-party review; absence of bugs. Redacted: host public IP addresses (not needed for verification); overlay (private) addresses replaced by region labels.