{
  "baseline_pass": true,
  "per_node": [
    {
      "spec_version": "1.4.0",
      "agent_type": "hermes",
      "agent_id": "ai:alice",
      "node_index": "1",
      "framework_version": "Hermes Agent v0.11.0 (2026.4.23)",
      "ai_memory_version": "v0.6.2",
      "peer_urls": "https://10.11.2.2:9077,https://10.11.2.4:9077,https://10.11.2.3:9077",
      "config_file_sha256": "fa358f9a90597243fb96224babd541399bd7b1e972f364605308ab1e2d9dd2c7",
      "config_attestation": {
        "framework_is_authentic": true,
        "mcp_server_ai_memory_registered": true,
        "llm_backend_is_xai_grok": true,
        "llm_is_default_provider": true,
        "mcp_command_is_ai_memory": true,
        "agent_id_stamped": true,
        "federation_live": true,
        "ufw_disabled": true,
        "iptables_flushed": true,
        "dead_man_switch_scheduled": true
      },
      "negative_invariants": {
        "_description": "Alternative A2A channels must be OFF so a passing scenario is only passing via ai-memory shared memory. Any true here = thesis-preserving.",
        "a2a_protocol_off": true,
        "sub_agent_or_sessions_spawn_off": true,
        "alternative_channels_off": true,
        "tool_allowlist_is_memory_only": true,
        "a2a_gate_profile_locked": true
      },
      "functional_probes": {
        "xai_grok_chat_reachable": true,
        "xai_grok_sample_reply": "READY",
        "substrate_http_canary_f2a": true,
        "substrate_http_canary_uuid": "aef7750d-e290-460f-bdc3-37641910369c",
        "agent_mcp_canary_f2b": false,
        "agent_mcp_canary_uuid": "983cbb5e-7bd5-45e1-b94b-60d17ac6182f",
        "agent_canary_response_head": "Traceback (most recent call last):   File \"/usr/local/bin/hermes\", line 11, in <module>     main()   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 8956, in main     args.func(args)   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 1159, in cmd_chat     from cli import main as cli_main   File \"/root/.hermes/hermes-agent/cli.py\", line 43, in <module>     from prompt_toolkit.history import FileHistory ModuleNotFoundError: No module named 'prompt_toolkit' ",
        "_f2b_note": "F2b is LLM-dependent and non-blocking. F2a (deterministic HTTP substrate) gates baseline_pass.",
        "mesh_connectivity_f4": true,
        "mesh_edges_ok": 3,
        "mesh_edges_total": 3,
        "mesh_edges_detail": "10.11.2.2:9077:OK,10.11.2.4:9077:OK,10.11.2.3:9077:OK",
        "_f4_note": "F4 verifies this local nodes N-1 OUTBOUND mesh edges to every peer via both GET health and POST sync_push dry_run. Aggregator ANDs across N nodes to confirm full N*(N-1) bidirectional reachability. Gates baseline_pass.",
        "ai_memory_mcp_stdio_f5": true,
        "ai_memory_mcp_stdio_init_ok": true,
        "ai_memory_mcp_stdio_tools_ok": true,
        "ai_memory_mcp_stdio_tools_found": "memory_agent_list,memory_agent_register,memory_archive_list,memory_archive_purge,memory_archive_restore,memory_archive_stats,memory_auto_tag,memory_capabilities,memory_consolidate,memory_delete,memory_detect_contradiction,memory_expand_query,memory_forget,memory_gc,memory_get,memory_get_links,memory_inbox,memory_link,memory_list,memory_list_subscriptions,memory_namespace_clear_standard,memory_namespace_get_standard,memory_namespace_set_standard,memory_notify,memory_pending_approve,memory_pending_list,memory_pending_reject,memory_promote,memory_recall,memory_search,memory_session_start,memory_stats,memory_store,memory_subscribe,memory_unsubscribe,memory_update",
        "_f5_note": "F5 spawns the ai-memory stdio MCP subprocess using the framework-configured invocation and verifies initialize + tools/list return memory_store, memory_recall, memory_list. Deterministic (no LLM). Gates baseline_pass.",
        "tls_mode": "mtls",
        "tls_handshake_f6": true,
        "tls_handshake_f6_reason": "",
        "mtls_enforcement_f7": true,
        "mtls_enforcement_f7_reason": "",
        "_f6_f7_note": "F6 verifies the TLS 1.3 handshake against the local serve + CA chain. F7 verifies mTLS enforcement — anonymous client rejected, whitelisted client accepted. Both gate baseline_pass when tls_mode != off / mtls respectively.",
        "embedder_loaded_f8": true,
        "embedder_loaded_f8_reason": "",
        "_f8_note": "F8 verifies /api/v1/capabilities reports features.embedder_loaded=true — i.e. the MiniLM embedder initialised at serve startup. Gates baseline_pass unconditionally. Without this, scenario-18 silently black-holes (semantic recall returns 0 rows).",
        "agent_mcp_ai_memory_canary": true,
        "canary_uuid": "aef7750d-e290-460f-bdc3-37641910369c",
        "canary_namespace": "_baseline_canary_f2a"
      },
      "baseline_pass": true
    },
    {
      "spec_version": "1.4.0",
      "agent_type": "hermes",
      "agent_id": "ai:bob",
      "node_index": "2",
      "framework_version": "Hermes Agent v0.11.0 (2026.4.23)",
      "ai_memory_version": "v0.6.2",
      "peer_urls": "https://10.11.2.5:9077,https://10.11.2.4:9077,https://10.11.2.3:9077",
      "config_file_sha256": "21635cf6364057fd2a004d28aac89abf8438671d85f9fd2ed1e654d812d23ff1",
      "config_attestation": {
        "framework_is_authentic": true,
        "mcp_server_ai_memory_registered": true,
        "llm_backend_is_xai_grok": true,
        "llm_is_default_provider": true,
        "mcp_command_is_ai_memory": true,
        "agent_id_stamped": true,
        "federation_live": true,
        "ufw_disabled": true,
        "iptables_flushed": true,
        "dead_man_switch_scheduled": true
      },
      "negative_invariants": {
        "_description": "Alternative A2A channels must be OFF so a passing scenario is only passing via ai-memory shared memory. Any true here = thesis-preserving.",
        "a2a_protocol_off": true,
        "sub_agent_or_sessions_spawn_off": true,
        "alternative_channels_off": true,
        "tool_allowlist_is_memory_only": true,
        "a2a_gate_profile_locked": true
      },
      "functional_probes": {
        "xai_grok_chat_reachable": true,
        "xai_grok_sample_reply": "READY",
        "substrate_http_canary_f2a": true,
        "substrate_http_canary_uuid": "8bb3ab53-a80c-4939-a179-9b61e5825d4b",
        "agent_mcp_canary_f2b": false,
        "agent_mcp_canary_uuid": "03aa604f-4980-46eb-8a38-8ad16deaec0a",
        "agent_canary_response_head": "Traceback (most recent call last):   File \"/usr/local/bin/hermes\", line 11, in <module>     main()   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 8956, in main     args.func(args)   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 1159, in cmd_chat     from cli import main as cli_main   File \"/root/.hermes/hermes-agent/cli.py\", line 43, in <module>     from prompt_toolkit.history import FileHistory ModuleNotFoundError: No module named 'prompt_toolkit' ",
        "_f2b_note": "F2b is LLM-dependent and non-blocking. F2a (deterministic HTTP substrate) gates baseline_pass.",
        "mesh_connectivity_f4": true,
        "mesh_edges_ok": 3,
        "mesh_edges_total": 3,
        "mesh_edges_detail": "10.11.2.5:9077:OK,10.11.2.4:9077:OK,10.11.2.3:9077:OK",
        "_f4_note": "F4 verifies this local nodes N-1 OUTBOUND mesh edges to every peer via both GET health and POST sync_push dry_run. Aggregator ANDs across N nodes to confirm full N*(N-1) bidirectional reachability. Gates baseline_pass.",
        "ai_memory_mcp_stdio_f5": true,
        "ai_memory_mcp_stdio_init_ok": true,
        "ai_memory_mcp_stdio_tools_ok": true,
        "ai_memory_mcp_stdio_tools_found": "memory_agent_list,memory_agent_register,memory_archive_list,memory_archive_purge,memory_archive_restore,memory_archive_stats,memory_auto_tag,memory_capabilities,memory_consolidate,memory_delete,memory_detect_contradiction,memory_expand_query,memory_forget,memory_gc,memory_get,memory_get_links,memory_inbox,memory_link,memory_list,memory_list_subscriptions,memory_namespace_clear_standard,memory_namespace_get_standard,memory_namespace_set_standard,memory_notify,memory_pending_approve,memory_pending_list,memory_pending_reject,memory_promote,memory_recall,memory_search,memory_session_start,memory_stats,memory_store,memory_subscribe,memory_unsubscribe,memory_update",
        "_f5_note": "F5 spawns the ai-memory stdio MCP subprocess using the framework-configured invocation and verifies initialize + tools/list return memory_store, memory_recall, memory_list. Deterministic (no LLM). Gates baseline_pass.",
        "tls_mode": "mtls",
        "tls_handshake_f6": true,
        "tls_handshake_f6_reason": "",
        "mtls_enforcement_f7": true,
        "mtls_enforcement_f7_reason": "",
        "_f6_f7_note": "F6 verifies the TLS 1.3 handshake against the local serve + CA chain. F7 verifies mTLS enforcement — anonymous client rejected, whitelisted client accepted. Both gate baseline_pass when tls_mode != off / mtls respectively.",
        "embedder_loaded_f8": true,
        "embedder_loaded_f8_reason": "",
        "_f8_note": "F8 verifies /api/v1/capabilities reports features.embedder_loaded=true — i.e. the MiniLM embedder initialised at serve startup. Gates baseline_pass unconditionally. Without this, scenario-18 silently black-holes (semantic recall returns 0 rows).",
        "agent_mcp_ai_memory_canary": true,
        "canary_uuid": "8bb3ab53-a80c-4939-a179-9b61e5825d4b",
        "canary_namespace": "_baseline_canary_f2a"
      },
      "baseline_pass": true
    },
    {
      "spec_version": "1.4.0",
      "agent_type": "hermes",
      "agent_id": "ai:charlie",
      "node_index": "3",
      "framework_version": "Hermes Agent v0.11.0 (2026.4.23)",
      "ai_memory_version": "v0.6.2",
      "peer_urls": "https://10.11.2.5:9077,https://10.11.2.2:9077,https://10.11.2.3:9077",
      "config_file_sha256": "ce52d772ef5a00968db29fb80eea7a14206b0a258a00ff2165db725405474618",
      "config_attestation": {
        "framework_is_authentic": true,
        "mcp_server_ai_memory_registered": true,
        "llm_backend_is_xai_grok": true,
        "llm_is_default_provider": true,
        "mcp_command_is_ai_memory": true,
        "agent_id_stamped": true,
        "federation_live": true,
        "ufw_disabled": true,
        "iptables_flushed": true,
        "dead_man_switch_scheduled": true
      },
      "negative_invariants": {
        "_description": "Alternative A2A channels must be OFF so a passing scenario is only passing via ai-memory shared memory. Any true here = thesis-preserving.",
        "a2a_protocol_off": true,
        "sub_agent_or_sessions_spawn_off": true,
        "alternative_channels_off": true,
        "tool_allowlist_is_memory_only": true,
        "a2a_gate_profile_locked": true
      },
      "functional_probes": {
        "xai_grok_chat_reachable": true,
        "xai_grok_sample_reply": "READY",
        "substrate_http_canary_f2a": true,
        "substrate_http_canary_uuid": "de05346b-3807-4276-988c-0be8fbd946ef",
        "agent_mcp_canary_f2b": false,
        "agent_mcp_canary_uuid": "a0d2a354-d60d-4af9-8d51-6fa29367c137",
        "agent_canary_response_head": "Traceback (most recent call last):   File \"/usr/local/bin/hermes\", line 11, in <module>     main()   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 8956, in main     args.func(args)   File \"/root/.hermes/hermes-agent/hermes_cli/main.py\", line 1159, in cmd_chat     from cli import main as cli_main   File \"/root/.hermes/hermes-agent/cli.py\", line 43, in <module>     from prompt_toolkit.history import FileHistory ModuleNotFoundError: No module named 'prompt_toolkit' ",
        "_f2b_note": "F2b is LLM-dependent and non-blocking. F2a (deterministic HTTP substrate) gates baseline_pass.",
        "mesh_connectivity_f4": true,
        "mesh_edges_ok": 3,
        "mesh_edges_total": 3,
        "mesh_edges_detail": "10.11.2.5:9077:OK,10.11.2.2:9077:OK,10.11.2.3:9077:OK",
        "_f4_note": "F4 verifies this local nodes N-1 OUTBOUND mesh edges to every peer via both GET health and POST sync_push dry_run. Aggregator ANDs across N nodes to confirm full N*(N-1) bidirectional reachability. Gates baseline_pass.",
        "ai_memory_mcp_stdio_f5": true,
        "ai_memory_mcp_stdio_init_ok": true,
        "ai_memory_mcp_stdio_tools_ok": true,
        "ai_memory_mcp_stdio_tools_found": "memory_agent_list,memory_agent_register,memory_archive_list,memory_archive_purge,memory_archive_restore,memory_archive_stats,memory_auto_tag,memory_capabilities,memory_consolidate,memory_delete,memory_detect_contradiction,memory_expand_query,memory_forget,memory_gc,memory_get,memory_get_links,memory_inbox,memory_link,memory_list,memory_list_subscriptions,memory_namespace_clear_standard,memory_namespace_get_standard,memory_namespace_set_standard,memory_notify,memory_pending_approve,memory_pending_list,memory_pending_reject,memory_promote,memory_recall,memory_search,memory_session_start,memory_stats,memory_store,memory_subscribe,memory_unsubscribe,memory_update",
        "_f5_note": "F5 spawns the ai-memory stdio MCP subprocess using the framework-configured invocation and verifies initialize + tools/list return memory_store, memory_recall, memory_list. Deterministic (no LLM). Gates baseline_pass.",
        "tls_mode": "mtls",
        "tls_handshake_f6": true,
        "tls_handshake_f6_reason": "",
        "mtls_enforcement_f7": true,
        "mtls_enforcement_f7_reason": "",
        "_f6_f7_note": "F6 verifies the TLS 1.3 handshake against the local serve + CA chain. F7 verifies mTLS enforcement — anonymous client rejected, whitelisted client accepted. Both gate baseline_pass when tls_mode != off / mtls respectively.",
        "embedder_loaded_f8": true,
        "embedder_loaded_f8_reason": "",
        "_f8_note": "F8 verifies /api/v1/capabilities reports features.embedder_loaded=true — i.e. the MiniLM embedder initialised at serve startup. Gates baseline_pass unconditionally. Without this, scenario-18 silently black-holes (semantic recall returns 0 rows).",
        "agent_mcp_ai_memory_canary": true,
        "canary_uuid": "de05346b-3807-4276-988c-0be8fbd946ef",
        "canary_namespace": "_baseline_canary_f2a"
      },
      "baseline_pass": true
    }
  ]
}
