{
  "schema": "s2s-bench-v1",
  "kind": "data-kit-index",
  "exhibit": "onnx-runtime-telemetry-on-linux",
  "exhibit_title": "ONNX Runtime's telemetry on Linux, measured: on by default since 1.29, and the switch that stops it",
  "exhibit_url": "https://research.strata2signal.com/onnx-runtime-telemetry-on-linux/",
  "published_utc": "2026-09-28",
  "licence": "CC BY 4.0",
  "attribution": "strata→signal research, research.strata2signal.com",
  "contact": "hello@strata2signal.com",
  "run_id": "onnxruntime-telemetry-probe-2026-09-28",
  "run_window_utc": {
    "dry_run_utc": "2026-09-28T08:44Z",
    "prereg_frozen_utc": "2026-09-28T08:45Z",
    "probe_opened_utc": "2026-09-28T08:45:25Z",
    "probe_closed_utc": "2026-09-28T08:51:43Z",
    "audit_opened_utc": "2026-09-28T08:56Z",
    "audit_reruns_utc": "2026-09-28T09:01Z to 2026-09-28T09:12Z",
    "audit_closed_utc": "2026-09-28T09:16Z",
    "note": "The probe's window runs from the preflight to the end of round 3, as PROBE-RESULTS.md states it. The pre-registration's last write was issued at 08:45:13.5Z and landed at 08:45:16.67Z (the file's own mtime), and the first test program started at 08:45:31.51Z (PROBE-AUDIT.md, check 2). The audit's window is its own report's."
  },
  "card_class": "none: every run used the processor (onnxruntime's CPUExecutionProvider) of one x86-64 laptop on mains power, inside a Debian 12 Docker container with no network",
  "counting_rules": {
    "lookup": "A lookup is a query the stand-in name server logged. Every attempt was preceded by two, A and AAAA.",
    "attempt": "An attempt is a TLS connection the stand-in listener accepted with the server name mobile.events.data.microsoft.com, the collector. The listener read the first handshake message and hung up before any encrypted session began.",
    "network_system_call": "Any connect, sendto, sendmsg or sendmmsg by any process of the test program's tree to an AF_INET or AF_INET6 address, from strace's log. AF_UNIX is local and is counted apart.",
    "times": "Seconds after t_launch, the harness's clock just before it started the test program.",
    "verdicts": "A prediction holds only if it holds in every run of its row; one contrary run refutes it."
  },
  "not_a_standard": "One library at three versions, on one laptop's processor, in a Debian 12 container with no network, on 2026-09-28. It measures attempts, not delivery, for 120 seconds a run on mains power. It is a reading, not a rating.",
  "sanitisation": "Every file here was copied from the probe's and the audit's own record and rewritten only by the named mechanical rules in provenance.json, applied by one program (the hub repo's tools/kit_sanitise.py) in a fixed order. provenance.json names each rule, describes what it does, and gives its firing count on every file, and says of every file whether a rule touched it. The original's digest is given only for a file no rule touched: a digest of a redacted original would let anyone test guesses for what was replaced. NO FIGURE WAS TOUCHED: the tool's fence re-reads every numeric token on both sides and refuses on any difference, and the only digits a rule moves are inside the names, addresses and throwaway identifiers named in what_was_not_touched, and inside the pre-registration's recorded sha256, which is withheld (README.md). The literal private side of each rule is held off this kit.",
  "files_note": "Stamped from the files themselves rather than authored: every row is the name, the byte count and the sha256 as they are on disk. Two files were RECOVERED rather than copied, so they are listed here and not in provenance.json, which lists only what a rule produced: probe/as-run/inside.py and probe/as-run/summarize.py, the two scripts as they ran, rebuilt by replaying the probe agent's own recorded file writes. Each is proved by applying the one recorded later edit to it, which gives the copy in probe/ byte for byte, and no rule would fire in either.",
  "file_count": 272,
  "files": [
    {
      "file": "PREREG-probe.md",
      "bytes": 10416,
      "sha256": "1f0bf8906db75c680d68e4c156d5a89ed7886005f076821a66cbdbd8bc62cd65",
      "role": "The pre-registration, frozen at 08:45Z before the first run: the question, the instrument, the arms, the six predictions and the void rules, with Amendment 0 (why Docker and not unshare). This copy has three words replaced by rule (a machine's estate name twice, an account name once). The sha256 the runs recorded of the original is withheld (README.md, \"The pre-registration's fingerprint, withheld\")."
    },
    {
      "file": "PROBE-AUDIT.md",
      "bytes": 15322,
      "sha256": "882e23f8c8262321a445ad730f987546cf855c5fdde197fe57dad64ef50f2d0c",
      "role": "The independent audit (08:56Z to 09:16Z): the sandbox re-checked from inside and from the host, the pre-registration's timing, three positive controls, five rows re-run plus one exploratory 1.29.0 run with the switch set, every figure matched against the raw run files, and the kernel-counter witness. Its evidence is under audit/."
    },
    {
      "file": "PROBE-RESULTS.md",
      "bytes": 22299,
      "sha256": "21cd845c80a2fc7fbdae0e0ef57c6123b32c3a68e9284de6ce0290c78714d885",
      "role": "The measurement record, written by the agent that ran the probe and corrected by the audit: the verdict on each prediction, the table per arm and per run, the gaps between attempts, the secondary measures, the exact environment, the kit changes after the runs, and what the probe does not show."
    },
    {
      "file": "README.md",
      "bytes": 19762,
      "sha256": "8c19a7b610c837ac0c0a44b5ea6681f4e2e367df66a6559c8eb9275dee691ee0",
      "role": "What every file is, how to run the sealed test, what each rule did, the two scripts edited after the runs with both sha256, and the limits of the run."
    },
    {
      "file": "audit/audit_inside.py",
      "bytes": 6483,
      "sha256": "c057565bbd5eb6d445aaab379f7d5defdea5838f9c28df169b33798df00d8c5c",
      "role": "The audit's own in-container checks, with the probe's exact flags: is there any route out (interfaces, routes, and real connects to public and host-side addresses), then three positive controls through the probe's own listeners (HTTPS and HTTP to the collector's name, and a raw connect to one of its hard-coded addresses)."
    },
    {
      "file": "audit/ort-pybind-SHA256SUMS",
      "bytes": 366,
      "sha256": "20ffd489b59ce1d2644cd25485fc8db967e5fd2f2201677a42593e8148b53359",
      "role": "The sha256 of each compiled library in the audit's own virtual environments; they match the probe's."
    },
    {
      "file": "audit/run-arm-audit-arm.diff",
      "bytes": 134,
      "sha256": "2960d8d7c693634c7b10ca71aace913ef5837c1ebb7e7a1265fc078c72182da7",
      "role": "The one line the audit added to a scratch copy of run-arm.sh for its exploratory, not-pre-registered 1.29.0 run with the switch set."
    },
    {
      "file": "audit/runs/launch-ort130-apioff.txt",
      "bytes": 127,
      "sha256": "533d7e032955a5bcf59c23347a19af44b0c5786d847b384adb040d9b4f5818c3",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch-ort130-default.txt",
      "bytes": 129,
      "sha256": "359750c5faf723298a3d44b4338577d067da525819bde8e75aa56050a6a3938f",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch-ort130-envoff.txt",
      "bytes": 125,
      "sha256": "e1f616798df1b47191809a1c6a17524d76ac971d8a1d6a623c0b9bcd02975f38",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch-posctl.txt",
      "bytes": 111,
      "sha256": "4c892a4fe7e44c1183dc01df4acd4b8d3215c085085c9e18e6095db19d40bada",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch2-ort130-default.txt",
      "bytes": 129,
      "sha256": "83c31e0f3cc94da0ebb9f900da1c483770c0873692e58090f3a5474833a72bce",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch2-ort130-envoff.txt",
      "bytes": 125,
      "sha256": "882297398dd2fad6daf5c7e33b6d1cb414554fc272ced66a512eceb30e700293",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch3-ort129-default.txt",
      "bytes": 129,
      "sha256": "5169c3f1b2f456096a876c68cb5d61d8e7f5a7acb2e501c171d40d0f1339f2a7",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/launch3-ort129-envoff.txt",
      "bytes": 125,
      "sha256": "9ecb463f29b0b8a57da32f144503e0698dfb7571281d6cd36a5358d7964b9e64",
      "role": "run-arm.sh's one-line result for one audit run, as printed when it finished."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/deviceid",
      "bytes": 33,
      "sha256": "5de2468d3405a16b78644529e83d5a959ba893b331ae251b9ca0b07694a8077e",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/harness.log",
      "bytes": 98,
      "sha256": "c7025ee460724f30118b230d928f3c38c6ff71444920610c3961da8d7b0c1db5",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/machine-id",
      "bytes": 35,
      "sha256": "7fa91c362441d481e2390635e5eb53930eb76a23edd4b5c44ca2f1a094cd02e3",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/marks.json",
      "bytes": 280,
      "sha256": "b7d7863801046a64f81be5a18afc2d19a83856be4748a0e16948b9c3d1038711",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/queue/strings.txt",
      "bytes": 6546,
      "sha256": "518d4dbb7895a9db993efcdb74d38b938638a41dbfd583d6ab5854c0bee16dac",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/result.json",
      "bytes": 13403,
      "sha256": "adc26b40c03cacbdf4e08c7f392285a2cad7901e5854c78a4804bd26e7cadf9f",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/strace.log",
      "bytes": 19092,
      "sha256": "8bf43707bfff8a3ef0cf0abbd7d95fd505da8537987c689643cc5bb6762f25df",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort129-default-raudit3/tmp.ses",
      "bytes": 53,
      "sha256": "05daeb971af37eddbd53631c966afdfa3744364e271c8f3ddaee3930f763e568",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/harness.log",
      "bytes": 95,
      "sha256": "a7634c1d8b526a9e74ad7835f403063a093f9264e72240286da78c7b0b2aa01d",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/machine-id",
      "bytes": 34,
      "sha256": "3e99f0697a1e1f4ebbf98c0bd1548b544a26892cdc4edf6047bc9afe03473263",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/marks.json",
      "bytes": 279,
      "sha256": "2c0ddd317a2bb11a22bd798dfcb001161df5688b5f2b6e5373c60a9c7a6b1810",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/result.json",
      "bytes": 2490,
      "sha256": "bdf14b5b8cc8773849bbf41853cd4155d9fe0f5f3af77e97934f9d0bca939347",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/strace.log",
      "bytes": 2162,
      "sha256": "d26d28fefb06f3544040a69a43dd05a0398390735130c5551ab91a2d03afb260",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort129-envoff-raudit3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/deviceid",
      "bytes": 32,
      "sha256": "6b89c07cd3175cb0d7eab1e541d6833378dbbc8dc243d22efcf83bad4ce9fa63",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/harness.log",
      "bytes": 97,
      "sha256": "07d677bfc664d728bbf79f14968da8bba8aed217a9f2b7252d5e8694c0645757",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/machine-id",
      "bytes": 34,
      "sha256": "1c418a7f05a43ed4bbb55ed6df4e4344dfc565e9a4467c0d4a74f32e12b8e4f9",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/marks.json",
      "bytes": 314,
      "sha256": "735767acd47bfd95bbf0fbed2807160ffe855be4521cede2d8f7764835feafa6",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/queue/strings.txt",
      "bytes": 1572,
      "sha256": "b9b5aa3a8498daa5c6e2a4115a5089f9de04e6991b1cb8fffff8f349c68984e0",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/result.json",
      "bytes": 9823,
      "sha256": "9935b0699c7b45dce4c4d4f792ca743312ffc6bb0b24c41660060e8dd2ef0997",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/strace.log",
      "bytes": 19594,
      "sha256": "ec2297d167186c86593ddcae3dbd8518580173da46a2ffbc0f27dd8a55476c7b",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort130-apioff-raudit1/tmp.ses",
      "bytes": 52,
      "sha256": "cd69e25a475031873218006f756816bc2e0f90e4537ed1fb1d27c53d15e76aec",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/deviceid",
      "bytes": 33,
      "sha256": "3b2dbd515800e121b878e3e0675142b65913d60c130ac910f5ffaf8b801443b1",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/harness.log",
      "bytes": 98,
      "sha256": "77898658bf38866d8daa6608e01711e4bc1a4207bc70e105faeadaa865fd0efd",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/machine-id",
      "bytes": 35,
      "sha256": "e7e3c7dc3f0eade77c90e359c877f01092065ae89eb896eb729f5827b0b38f0e",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/marks.json",
      "bytes": 280,
      "sha256": "7fd3cbd23cff934a8350d19bdb4f14cb08322f563c9f2dafff536affc93c3dec",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/queue/strings.txt",
      "bytes": 6546,
      "sha256": "949a52f7f0f83258679e9cfca0958782463b62ac627f0bb9785d3aa381a2c0a4",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/result.json",
      "bytes": 13425,
      "sha256": "405a9bbdb1632c3fe37de1a329511d9d5c9de508b02f8b2b61699d82bd529da0",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/strace.log",
      "bytes": 19850,
      "sha256": "0ccee2db7443b0ac8c13870085894abbacadbf695097eef10764ddea37ec7024",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort130-default-raudit1/tmp.ses",
      "bytes": 53,
      "sha256": "71653e1bb3db7535d60c19a73942817202b906303ae25baf7dfcf4133caaa21d",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/deviceid",
      "bytes": 33,
      "sha256": "3dbeee21de240bc3b363de953ac671dd93d5841f11425c47fb47c857345b4759",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/harness.log",
      "bytes": 98,
      "sha256": "7f132aa27a259abb4ddca796b1bfaf5c0ba14387dd98a79ca1bf62a51b264a62",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/machine-id",
      "bytes": 35,
      "sha256": "332a1e23087dcb74c5b02dc1d91635d1e6f07fea312c4c1a4348f88e41071ee5",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/marks.json",
      "bytes": 278,
      "sha256": "9d81805edcb6bc19ceca1a055143970592b54c576a6e34ed2ca3295da9579339",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/queue/strings.txt",
      "bytes": 6548,
      "sha256": "d4b106e19e819f2c6b28248dccfe045c8e42ebd702d5f3a623e6897f33fbe894",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/result.json",
      "bytes": 13416,
      "sha256": "b6abd980873a0339ad112dee3b6f3c5d7e5593ac692c6c49e3f7353225afd8ad",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/strace.log",
      "bytes": 19524,
      "sha256": "e70e0485eba38befc91ede9d04bff69824bf93d1c11f7d883ea0f31b8c4f4458",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort130-default-raudit2/tmp.ses",
      "bytes": 53,
      "sha256": "04755768c7a6b4a7e8625b7ea822040c7253c1183d9452ae0c2b1b9e0c4a40f9",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/harness.log",
      "bytes": 95,
      "sha256": "a2318ebb4b0ebfb9e335b7960387f246488f5de369649ea2219fae40ca330a73",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/machine-id",
      "bytes": 34,
      "sha256": "5408038a8371c66a22e176cbc9b783965cdcc30e586bfd9e86d6654fb88edbd0",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/marks.json",
      "bytes": 278,
      "sha256": "8974902e67dca3dd788b326abd50afb8c10dbab69ede6283e4d8c5205d75d8ce",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/result.json",
      "bytes": 2486,
      "sha256": "6ddaaad6caeac1fffa09190ed34a63fba48e71385d26224728177a250d27dcc7",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/strace.log",
      "bytes": 2162,
      "sha256": "6281ff3d39111d2689c2b69414a4140269a8b249aedff64a73e9b03f61772ea1",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/harness.log",
      "bytes": 95,
      "sha256": "b0382f287c1eaa2095b49a59b67d88756197ccaa6b6e46534be10869f6d5bbb7",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/machine-id",
      "bytes": 34,
      "sha256": "c64990875d7b268c0374edaa36da607ed54c87efec132a85d3249f54965f3fe9",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/marks.json",
      "bytes": 277,
      "sha256": "ed1052a7bf66edb4f5b6c0fd320d35ebffc017a236db6620b8b038b77cc4e73c",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/result.json",
      "bytes": 2487,
      "sha256": "22e8e23599fa008a665fa1a5d84fc24965e1774ab8f12a58cc7e03058f4c6a77",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/strace.log",
      "bytes": 2162,
      "sha256": "beed42b7c8d9b3350a633e8f28bbdef9bd661e42d91b642671ed90fb26960202",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/ort130-envoff-raudit2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/runs/posctl-raudit1/harness.log",
      "bytes": 88,
      "sha256": "2377f6ce7a42d1ddee577ba6c474a0795a834e3c02e3e0c14397d5831c5cc21e",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "audit/runs/posctl-raudit1/machine-id",
      "bytes": 27,
      "sha256": "ee4ca07b2acc693c6d952267997c5a1ef2922c84ce6a4b37c22a2feaeac179ad",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "audit/runs/posctl-raudit1/marks.json",
      "bytes": 268,
      "sha256": "cf4769e876decb74f0a12c58b1951a20c9f085626143b9d02fb70fe131da941d",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "audit/runs/posctl-raudit1/result.json",
      "bytes": 3609,
      "sha256": "da2faec82b503ed705535c5d4767f0f6cf1521122c2d839f4b2d4867d777dd95",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "audit/runs/posctl-raudit1/strace.log",
      "bytes": 2366,
      "sha256": "0d9a33f15abb25cb7dbf209146239c16cf65788aa3ab58ec915733b209a68533",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "audit/runs/posctl-raudit1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "audit/runs/posctl-raudit1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "audit/verify-audit.txt",
      "bytes": 6915,
      "sha256": "a1c666f16963e108bbfe92264330a510884831539966fa480e5e07dbe078cb1d",
      "role": "verify.py's output over the audit's own 8 re-runs, as the audit recorded it."
    },
    {
      "file": "audit/verify-orig.txt",
      "bytes": 14968,
      "sha256": "0b015a6e5f2e69374b6942fd1b25d85ed0e290d6ba96e798f39e7c28de0cbfe9",
      "role": "verify.py's output over the probe's 18 runs, as the audit recorded it (queue lines included)."
    },
    {
      "file": "audit/verify.py",
      "bytes": 7710,
      "sha256": "c2ec1b44f72c5cda87f663741c494fecdd779f1f8ac6ab9d3ca244d884515b38",
      "role": "The audit's independent re-derivation of every figure from the raw run files: it reads strace.log directly rather than result.json's parsed copy. Its queue lines need the queue database copies, which this kit does not carry (see omitted in provenance.json)."
    },
    {
      "file": "audit/wheels-SHA256SUMS",
      "bytes": 2152,
      "sha256": "b7bc9c4749c0662512b97cf8fac4e042171a61bebf1c5f04a0e6edaebc7fda89",
      "role": "The sha256 of the wheels the audit downloaded fresh from PyPI; they match the probe's."
    },
    {
      "file": "audit/witness/audit-sandbox.json",
      "bytes": 4461,
      "sha256": "47473f1b3ffc696a353d1254b80d143f14ba34934655eaed4e22fce74b58d838",
      "role": "audit_inside.py's output: the no-route check and the three positive controls. Three of the connect targets were the dev laptop's own addresses (its LAN address, its private-network address and its second Docker bridge); each is replaced by a placeholder naming what it was."
    },
    {
      "file": "audit/witness/audit-sandbox.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "audit_inside.py's error stream: empty."
    },
    {
      "file": "audit/witness/ort129-default.txt",
      "bytes": 10053,
      "sha256": "8e38795771ba51497b521e68f33ebd3a417e70540d5a2dc58580dfa9d94cd7d9",
      "role": "The kernel's own network counters (/proc/<pid>/net/snmp) of the ort129-default audit run's container network namespace, read from the host about once a second from after the self-test to after exit: epoch time, OutRequests, OutNoRoutes, TcpActiveOpens, UdpOutDatagrams."
    },
    {
      "file": "audit/witness/ort129-envoff.txt",
      "bytes": 9945,
      "sha256": "23dfa60167ec30ad669b87456a22ce0ec661f0d8ea2a485a494d5ba487124119",
      "role": "The kernel's own network counters (/proc/<pid>/net/snmp) of the ort129-envoff audit run's container network namespace, read from the host about once a second from after the self-test to after exit: epoch time, OutRequests, OutNoRoutes, TcpActiveOpens, UdpOutDatagrams."
    },
    {
      "file": "audit/witness/ort130-default.txt",
      "bytes": 10053,
      "sha256": "d334e46b0560a6f49a530b75ad0c5a80464fc4205ce4157d49c06a23c3bc24e9",
      "role": "The kernel's own network counters (/proc/<pid>/net/snmp) of the ort130-default audit run's container network namespace, read from the host about once a second from after the self-test to after exit: epoch time, OutRequests, OutNoRoutes, TcpActiveOpens, UdpOutDatagrams."
    },
    {
      "file": "audit/witness/ort130-envoff.txt",
      "bytes": 9945,
      "sha256": "3d841d3ac72d57678c06b02b6077a58ea065dc1e729bce268b2fb5862e05b59e",
      "role": "The kernel's own network counters (/proc/<pid>/net/snmp) of the ort130-envoff audit run's container network namespace, read from the host about once a second from after the self-test to after exit: epoch time, OutRequests, OutNoRoutes, TcpActiveOpens, UdpOutDatagrams."
    },
    {
      "file": "probe/as-run/inside.py",
      "bytes": 18954,
      "sha256": "b67df717833dbb78242f602110f8f60e64eb6584f9c8d012a56abe2937ad4ba4",
      "role": "The in-container harness exactly as it ran all 18 runs (sha256 b67df717…), recovered by replaying the probe agent's own recorded file writes; applying the one recorded 08:53:08Z edit to it gives probe/inside.py byte for byte."
    },
    {
      "file": "probe/as-run/summarize.py",
      "bytes": 4887,
      "sha256": "e864ea6e5b23c6fd46d99968b23170756fb49ae965225e0dfda7e30c8dec3776",
      "role": "The summariser exactly as it printed the live table at the end of round 3 (sha256 e864ea6e…), recovered from the probe agent's own recorded file write; applying the one recorded 08:52:14Z edit to it gives probe/summarize.py byte for byte. Run over probe/runs it prints the table in probe/runs/run-all.log byte for byte."
    },
    {
      "file": "probe/inside.py",
      "bytes": 18962,
      "sha256": "346aeef9843fae720ca2022eab6edf86a161f16b0d465c75d854a2fe66babfa4",
      "role": "The in-container harness: the logging stand-in name server and TLS and HTTP listeners, the self-test that voids a run on any failure, the test program under strace, and the after-run reading of files and the queue. EDITED AFTER THE RUNS (08:53:08Z, one line: how container_os strips its quote and newline); the bytes that ran are probe/as-run/inside.py."
    },
    {
      "file": "probe/preflight.sh",
      "bytes": 959,
      "sha256": "bf91412fb4d13ccf8a8c68f16e02d77212981f75b9ac66449baed5ef46c7a4a9",
      "role": "Proves the container network mode reaches nothing before any test runs: a real curl in a --network none container must fail against three public addresses."
    },
    {
      "file": "probe/prepare.sh",
      "bytes": 2628,
      "sha256": "f2eca818e5630d59df8affd9a819e1ddc7b7ed953758fceb52771ec5feee4d67",
      "role": "Step 1, the only step that uses the network: pip-downloads the three onnxruntime versions and the same onnx and numpy pins, bundles the host's strace with its libraries, and builds one virtual environment per version inside a --network none container, offline."
    },
    {
      "file": "probe/resolv.conf",
      "bytes": 133,
      "sha256": "800e198a4e06f053b6d3dbc0976cf0bda667a0cd7d6699d36d7e8d2fb82a7f5a",
      "role": "Mounted over /etc/resolv.conf inside every container: the only resolver is the logging stand-in on 127.0.0.1."
    },
    {
      "file": "probe/run-all.sh",
      "bytes": 658,
      "sha256": "a84f2a760b837c3b0ee618a0f636e902ccba416fa6f2aff61f61572425e1eea5",
      "role": "The preflight, then three rounds of all six rows (one container per row, a round's rows at once), then the summariser."
    },
    {
      "file": "probe/run-arm.sh",
      "bytes": 2587,
      "sha256": "dfe556bdb9771264dccd57903eded68564af99cdbafa675c3681f5ef952abf0f",
      "role": "One run of one row: starts the sealed container (no network, not root, every capability dropped, read-only root, a fresh random machine ID) and runs inside.py in it."
    },
    {
      "file": "probe/runs/SUMMARY.md",
      "bytes": 7883,
      "sha256": "db40e6480bffc4a73c8b2a4538b62ab31d03903e5d7c2daa6dd49503c43d98a3",
      "role": "probe/summarize.py's output over the 18 runs: the per-run table, the verdict on each prediction and the secondary table. `python3 probe/summarize.py probe/runs` over this kit reprints it byte for byte."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/harness.log",
      "bytes": 83,
      "sha256": "9ac42573c925fb22397094c5a232463f88b6efa333992e6e5bc256aa1de89b5b",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/machine-id",
      "bytes": 22,
      "sha256": "65fd1c0e4451b46745225be8b408aedc183445142e4dc7a2d9935a4161756042",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/marks.json",
      "bytes": 268,
      "sha256": "e442149ad043ca4c14d6161060bf68ffbbb8533f7772ffd3bdbe791eef3b0642",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/result.json",
      "bytes": 3611,
      "sha256": "961ddd4ce4a53c4b09ff1c42c2219877693c4c2cde9589a2591c36637d646e79",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/strace.log",
      "bytes": 2378,
      "sha256": "3bda64d445abc0f6e02df064a6077bf4af4798d816da2ea9e669da45fb2331a3",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/dryrun/posctl-r0/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/dryrun/preflight.txt",
      "bytes": 467,
      "sha256": "00f47d0786f8052b4eeceb33b36d3a042d7e05b9679e2c7f4addc7aa8ac9b106",
      "role": "The preflight of the instrument dry run at 08:44Z, before the pre-registration was frozen."
    },
    {
      "file": "probe/runs/ort-pybind-SHA256SUMS",
      "bytes": 549,
      "sha256": "d51a1465d146bc22d5179022387fd6ef335af3739e76f0b1a8986031529ab1c9",
      "role": "The sha256 of each version's compiled onnxruntime library as installed in the three virtual environments."
    },
    {
      "file": "probe/runs/ort128-default-r1/harness.log",
      "bytes": 91,
      "sha256": "5b83522981b548cc96dd4c11c01ad9f02b2ac67ea6e30b94cb1e4d22cd07b65f",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort128-default-r1/machine-id",
      "bytes": 30,
      "sha256": "c7504efa786560987f0400d8b6f01b8a1969ca88e512f3c9dbff9c3a0c9c0900",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort128-default-r1/marks.json",
      "bytes": 279,
      "sha256": "c426a1db8260e42aadc4dd2e86ec867b54b8b574b6b218ccb46d6f9bfd1399bf",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort128-default-r1/result.json",
      "bytes": 2456,
      "sha256": "85f519354dae9068894767922a464fd783084766c8c28d683a641da5f4e3ac8b",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort128-default-r1/strace.log",
      "bytes": 2162,
      "sha256": "d0180696758c8fe5aed03de52b00e181df31c0b7f233779df5aefab207370e6c",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort128-default-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort128-default-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort128-default-r2/harness.log",
      "bytes": 91,
      "sha256": "94f6bd93ca829dcd6c5be96d34a42fb3429e0572dee5ed7a3eb0699d300b41f1",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort128-default-r2/machine-id",
      "bytes": 30,
      "sha256": "928b9cc00758ecadfd4cd7b6d55bc0ca29c490cdaf5efa06fcfdef4b4903598e",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort128-default-r2/marks.json",
      "bytes": 278,
      "sha256": "3d6eca9c999116796cad05376897d36b1ab7f605aae9d1a777db1d07ad3e7f14",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort128-default-r2/result.json",
      "bytes": 2456,
      "sha256": "c6cf9f172d608cf867fda7890a17c32c59efa3473b5c60237d6727cde9eaa041",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort128-default-r2/strace.log",
      "bytes": 2162,
      "sha256": "bf29a0900bc2af6d694f98461e7f63db162edd545381b5e599751d6230fffe2b",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort128-default-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort128-default-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort128-default-r3/harness.log",
      "bytes": 91,
      "sha256": "8f89574675bd5a7949dac9ceeda6a06f4626b32c74b00f72436e6db367b893c1",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort128-default-r3/machine-id",
      "bytes": 30,
      "sha256": "803641e9c2fd1440886c74817d82fe72f603009efbca9ecebc84495e916693d6",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort128-default-r3/marks.json",
      "bytes": 279,
      "sha256": "740d92d9a987917d9c88d240dee5feb9d5fed4a85f53b9784f6648e7c9314c34",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort128-default-r3/result.json",
      "bytes": 2455,
      "sha256": "1f4d9e6862729ead0458fba0974d3f042fcba8771f85b94e538ba745400cb534",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort128-default-r3/strace.log",
      "bytes": 2162,
      "sha256": "235f69ba412e198c9dc1b3bb793c4210fc74b4901f43d89a1fc5e6bd0813d551",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort128-default-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort128-default-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort129-default-r1/deviceid",
      "bytes": 28,
      "sha256": "e7286ebf805699513b5a0f2b85277961ecd754bb9c9c02d45aaf5497308104aa",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r1/harness.log",
      "bytes": 93,
      "sha256": "0f76a3294d080a1a4cb38738863b5e43dcc43a8db78ff7851bd9fc2419cb6ee6",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort129-default-r1/machine-id",
      "bytes": 30,
      "sha256": "05968ea90738c01ea8e92e5b4e2933afbaa7b38561f41da2d0c52b63953242be",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r1/marks.json",
      "bytes": 279,
      "sha256": "1a453e8e40cdd2fb9e47c79286b4c533aed52184b22bf3bf5a7fd0ad8d0ad94d",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort129-default-r1/queue/strings.txt",
      "bytes": 6426,
      "sha256": "d0827a2a6ee1015c4ee2bcfd439ec079de99a5fc9c60bf0b53fa6238619800c5",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort129-default-r1/result.json",
      "bytes": 13426,
      "sha256": "73cf8636ed3a6a318d0ff036a8c18a1771955a0c88a39d8f357d20cd6a3ac236",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort129-default-r1/strace.log",
      "bytes": 20322,
      "sha256": "c52f0771a90ae233f093d5fd99238d0ba715a05f02b9c1e5eac9c895edc2645a",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort129-default-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort129-default-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort129-default-r1/tmp.ses",
      "bytes": 48,
      "sha256": "7f7b8a610d9f84364a58c1e50c7fe4194d92303e8cb1466b5651617675eb12cf",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r2/deviceid",
      "bytes": 28,
      "sha256": "cfcc78cceac01982d70c8d268029a7b4d089639a32fec847e160cdd78b982356",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r2/harness.log",
      "bytes": 93,
      "sha256": "0d99e1a26f81e6fd72dafb82ef826a10b0171eef5f436ece9f7c85a166bc93c6",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort129-default-r2/machine-id",
      "bytes": 30,
      "sha256": "f58c809c3fd01d94471206a367691922ebb25ce705e6f54c8853afe94a88932b",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r2/marks.json",
      "bytes": 279,
      "sha256": "487ed89600110e3fa9bcd2ee933a3fec17157606c988f5373f722acc701ee986",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort129-default-r2/queue/strings.txt",
      "bytes": 6426,
      "sha256": "1ad3c06ca5de7acee9e2d43a19f41f555e24c5201fa8c591b15b48aa24fbe418",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort129-default-r2/result.json",
      "bytes": 13430,
      "sha256": "955f8599be635bb3a340d2807e9948e4afb7db4f312034139d1a9962d1834bce",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort129-default-r2/strace.log",
      "bytes": 20312,
      "sha256": "63ad2544d6803932c06a411be4496d54de9e42b2bbf5f9c41653e178787429f1",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort129-default-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort129-default-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort129-default-r2/tmp.ses",
      "bytes": 48,
      "sha256": "8418fe7e79037e0e301e90b50fa3437be8439cc9f70099715b14d12c2d593a6c",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r3/deviceid",
      "bytes": 28,
      "sha256": "b52f7f8caddeb1c04b7a52e61ca12cb6eccc4d42f55847c0cbf3b70c5dda108d",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r3/harness.log",
      "bytes": 93,
      "sha256": "f58cd339dcc1666a72971781cb8c616d41ab7015cdfe9cb6aca06080cb6e6077",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort129-default-r3/machine-id",
      "bytes": 30,
      "sha256": "00bd577d5b4f265f6aeb8c2f8291539b980b06112b783a1d71599865e1326f47",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort129-default-r3/marks.json",
      "bytes": 278,
      "sha256": "99a18f8d8328d2f273a8abc1cb578d401d43dcf5961b222ddf504ddaa305b4b9",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort129-default-r3/queue/strings.txt",
      "bytes": 6426,
      "sha256": "426172ffdea390816de51d9da37017476236f3840019b788c8962f053a4a5c96",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort129-default-r3/result.json",
      "bytes": 13405,
      "sha256": "74ef5631bcedfeb51d06c32ba1a825acf5c315dfb26c330c9c436b831e42b188",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort129-default-r3/strace.log",
      "bytes": 19263,
      "sha256": "11801d8603048e8e421a70037817169303abc6914ce106eebd19654a8d09065f",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort129-default-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort129-default-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort129-default-r3/tmp.ses",
      "bytes": 48,
      "sha256": "3a9f831ff47dcff8c13a5b7248097fc5db3682a32f22232fbec488da6f3893bb",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/deviceid",
      "bytes": 27,
      "sha256": "b329e78f36ebfc6834dad71ee8b777ee737be8308b63155add6677b82338cb29",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/harness.log",
      "bytes": 92,
      "sha256": "877833628200c29d395e231335bc09452e0db7c15c65bb5e1c1e113958eca609",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/machine-id",
      "bytes": 29,
      "sha256": "8a8b561d5cb9f19d6fa4586421ae5dbf2774a43880fe1f6c1e2f99d4dc351c18",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/marks.json",
      "bytes": 314,
      "sha256": "d79897ffbb8369d1f72691fad9e42fd39bd839b3473bc268089aadf64f8ce0cc",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/queue/strings.txt",
      "bytes": 1542,
      "sha256": "8141056df86cf5d5f59f089d5d68a8485d5c0cd1f898cf68d3104a0590e57b00",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/result.json",
      "bytes": 9827,
      "sha256": "f282b440ef36f2463e6f869d452a6dda0c21b64ee8831653e21c0672e66bd50d",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/strace.log",
      "bytes": 20269,
      "sha256": "56ce8d51892f8746243da11f274c8aed3bf259da886b2721a17563c3dd2b4e17",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r1/tmp.ses",
      "bytes": 47,
      "sha256": "fc93dda11f96eb1055cbe8dba0a618f6c228d4d6c1e5f2258ae5761335150733",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/deviceid",
      "bytes": 27,
      "sha256": "3bd9433b9b42be0b8c6bb93ea5afe247a4e6f830a064a1bc1c2807c547efd67d",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/harness.log",
      "bytes": 92,
      "sha256": "26c986eb35c2bf558d761aa1b4b938f8ac4bafc758bb17de58e7e93bb2ac72c5",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/machine-id",
      "bytes": 29,
      "sha256": "e4cd2cc1c3e172b4de449be4e27722ef418c42cf35150669766f5d9b318cf62d",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/marks.json",
      "bytes": 314,
      "sha256": "90c07598d69c7a63660718c07a01db7eb888377488d04c10bde76ae665c4af97",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/queue/strings.txt",
      "bytes": 1542,
      "sha256": "df52dc8f968b381cca42f4e313a8c26eada9f78370bc87e3af6535a465dd94b8",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/result.json",
      "bytes": 9789,
      "sha256": "f810e428c877fa1c239d4e0e68ac147d6b6faab0aea897ba258240898b5bdbbf",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/strace.log",
      "bytes": 18784,
      "sha256": "e3fc6357462fe812f1bd0ff623b116635ca04f84e2102f8d96872b419b0650c4",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r2/tmp.ses",
      "bytes": 47,
      "sha256": "e7a059bea8a99b61833df9f1792617b224b51a74a3e54a1f4fd86da78419adb7",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/deviceid",
      "bytes": 27,
      "sha256": "7c6c512201e393e6258ac5e33103d9e7806f5067a591589b39878269d0cd2034",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/harness.log",
      "bytes": 92,
      "sha256": "2db894d063bd44988be527c6139e324bd036db00d021f291d4bc2b60064e33b2",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/machine-id",
      "bytes": 29,
      "sha256": "88b589b0ef16668436df7ce369714fb8e55c01ac789623204d83a5debbe8ccac",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/marks.json",
      "bytes": 314,
      "sha256": "b72046b03609f6d246e44aad8a7f53778b9a0d9f896ca79a2ae02b2dc94e7bbb",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/queue/strings.txt",
      "bytes": 1542,
      "sha256": "f3d61aad04023fb3869bf2e76831d21ce034d82a5908b27d76a7a3895cfa1010",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/result.json",
      "bytes": 9824,
      "sha256": "d328ccc1df9c27cbe92ce5fde288e6f287b661708227a5bf131a35f05e1eb600",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/strace.log",
      "bytes": 19851,
      "sha256": "25333ee309a3184d1a915fbebc9eaec62a6e6c45e41e9208110feb9139cbd89a",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-apioff-r3/tmp.ses",
      "bytes": 47,
      "sha256": "23f7a482c209caa5234701acf5cdc162390b59af0dee85802107b463e5b72883",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r1/deviceid",
      "bytes": 28,
      "sha256": "edeebc47cdda84afc8b7055122e27d3a27906b83fd7fbd0399e86dce431e1009",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r1/harness.log",
      "bytes": 93,
      "sha256": "8d8d9ddca1a23172fe4e3ebd8d946ba716082049b367d7e0454414a6ba39a04e",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-default-r1/machine-id",
      "bytes": 30,
      "sha256": "5561cca9ce1176756474cc436dff964b24d00c782c1bf7ddef724c4b626e28b4",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r1/marks.json",
      "bytes": 278,
      "sha256": "770f53de5a0cd76bfcb7b8bccbf3e04ea92158a527ff942c436427afcf87cff6",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-default-r1/queue/strings.txt",
      "bytes": 6426,
      "sha256": "2abca6f91fffb2c79b99039b9c392ba3beaeb001e565138befc5e95198c3a0fc",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-default-r1/result.json",
      "bytes": 13395,
      "sha256": "4ba588c711906f16724a8b9dae4d1b01f150ca5625a6703f7113ee8f8d12ebd4",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-default-r1/strace.log",
      "bytes": 19218,
      "sha256": "3c05a269c055817b2b79d138e9831e733b94301e9b0bce5a71d062e8736e3514",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-default-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-default-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-default-r1/tmp.ses",
      "bytes": 48,
      "sha256": "0138497b363ce64903616dd38043d1453d76de80ccec821c999323b929d3eada",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r2/deviceid",
      "bytes": 28,
      "sha256": "5bd6971e56e85941725cddc21770f35a96d2a8fc7f9c6727deaa9f4cd4f59e54",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r2/harness.log",
      "bytes": 93,
      "sha256": "d9c81cb21a242a0c170c4eff39f30c43e8322af49992063ea8a6d9c2e4a1727d",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-default-r2/machine-id",
      "bytes": 30,
      "sha256": "34e9de7371cd8cb4a636f93ae87c56f8198ed6a8b08ce9360ffaf524bb0d2ffb",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r2/marks.json",
      "bytes": 279,
      "sha256": "6ed508eb9d13e9ae9eea4654a5bff41fb437e671fb4923300b0a7efc9dc7ab0f",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-default-r2/queue/strings.txt",
      "bytes": 6426,
      "sha256": "ff147d05eba0a0ca12f04419e84b59c1c1885fce8e7955a9c5c8f221881895df",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-default-r2/result.json",
      "bytes": 13406,
      "sha256": "38b434557b2e663bc7fed7f45380c2bbf4f7429ee26ca70ca3da2659e4a35dda",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-default-r2/strace.log",
      "bytes": 19219,
      "sha256": "6243a0e6629f00f5226b6f8d4d8e3e99c0e59170fc02ed0d3e75a31ec924e16f",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-default-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-default-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-default-r2/tmp.ses",
      "bytes": 48,
      "sha256": "82a00397102fb4ae1f5ec7ccb4c0d3a076cf91b5c69da78b749a5d4080632bc1",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r3/deviceid",
      "bytes": 28,
      "sha256": "cddc95f2d04f4ea09bfc51b64cc1bf8f059055996bc8b40aadf7d2abc3bb377d",
      "role": "The device ID file the library created in the container's throwaway home folder, its ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r3/harness.log",
      "bytes": 93,
      "sha256": "a5282c6a39e19dff1344a64fbbe684a48095dbd3a051aaf1fb20c34eb9cf6069",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-default-r3/machine-id",
      "bytes": 30,
      "sha256": "00d81feb4665928ed142797e03ee80eb018367031afe8e26bb185549f6779b7b",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-default-r3/marks.json",
      "bytes": 278,
      "sha256": "d6779c1bafea295d0d08dfecd1fcab70d5493979f8e30d1bbf36818596c42365",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-default-r3/queue/strings.txt",
      "bytes": 6426,
      "sha256": "899290670b45eae92caac00f699286ebaf2502a3593c3b630ae245ae63486e76",
      "role": "The printable strings of every queued event's payload, record by record, read from a copy of the container's queue database after the run. The device-ID hash and the install ID in them are placeholders naming the run; everything else is as read."
    },
    {
      "file": "probe/runs/ort130-default-r3/result.json",
      "bytes": 13389,
      "sha256": "b1b3a32d6d10f249b991ceb3bd29f93404643a6afec5510896005668158e0c13",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-default-r3/strace.log",
      "bytes": 18834,
      "sha256": "29b060eaf249de780d573905053bca18f0e7399aa8a9484ad451cbce5d916e60",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-default-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-default-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-default-r3/tmp.ses",
      "bytes": 48,
      "sha256": "dd8ce026b4b414671f05057fca14c20d42edac5115e33110cf6ab0c6a5db5a15",
      "role": "The telemetry library's /tmp/.ses from the container: its first-launch time in epoch milliseconds, then its install ID, the ID replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/harness.log",
      "bytes": 90,
      "sha256": "29296ea3a3e3b1b8bf7341fc458f39fc9e6a87a71f19a44a7242e941f1756a98",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/machine-id",
      "bytes": 29,
      "sha256": "4ada5125acf95f5dbb6067851b5939146ed256f8833934310bd8021f4b71834a",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/marks.json",
      "bytes": 277,
      "sha256": "e774a1f12068d0faaab6c807644f50d587dd144419251f1ff0db56c418ee3a90",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/result.json",
      "bytes": 2486,
      "sha256": "d9992b7a504a76de9a82925ea81a59c504a0c0e9998c4ec497ef5e8f382377bb",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/strace.log",
      "bytes": 2162,
      "sha256": "4ddd5fb991ead3d25c3eea74f544f297d0219afc1859de331d287a75b23c6aa0",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-envoff-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/harness.log",
      "bytes": 90,
      "sha256": "e8e01e2fc324542932c2ffa51838de32199a58b825caeab0aa07a218a7f6b2cc",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/machine-id",
      "bytes": 29,
      "sha256": "9f18cf86a9d50b407bfc65b81f932a8a198743697f859016c01f770b6b565f42",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/marks.json",
      "bytes": 279,
      "sha256": "313a5552411d5bae7f53e6cc8225e4f7967e810b35a9ef8d2ec5be1cf4184fbc",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/result.json",
      "bytes": 2487,
      "sha256": "4d5bf99a5a0365fce0bced71192a58be36341bac127150bfbe1dbaef65ac3021",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/strace.log",
      "bytes": 2162,
      "sha256": "f565538af55136c2bd4eae73ad0785a12a4824f5030fb5fd98eb91e9b4ed51e7",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-envoff-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/harness.log",
      "bytes": 90,
      "sha256": "ff8fe55c6e15e08b35a7ee50008498347ebd6dd9f9d3d4dc62d2fc38d9a540dc",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/machine-id",
      "bytes": 29,
      "sha256": "67bf04e91829cb616450dfbb91115402a425c54b5ca04086f3a8e0ebb5faa6b6",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/marks.json",
      "bytes": 278,
      "sha256": "004d9033cdfe2ae8f4043c86305ebd31aee7dc616981c09ad6ba995dc1189ae5",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/result.json",
      "bytes": 2486,
      "sha256": "fa50fa745463ea245d6a6e4509744d459ef9a2022af0cadb51e9e931a861dd02",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/strace.log",
      "bytes": 2162,
      "sha256": "c5192f86f08dcd9a3aac341613f2c13a314eff07fe1feb7066156d0b077af467",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/ort130-envoff-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/posctl-r1/harness.log",
      "bytes": 83,
      "sha256": "8572a662626b2a95e2dcb177c33167d4422ff63c8e73f25e6f96c513954c0d82",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/posctl-r1/machine-id",
      "bytes": 22,
      "sha256": "55aa3a0bd69c2428732d0546918b68b6887b9778fe158d6a00bb16a05e29b7de",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/posctl-r1/marks.json",
      "bytes": 268,
      "sha256": "52363d631ed4fa219c7ff12c976a6848fc30c6207d6917a69f9d7ce94fbfd59f",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/posctl-r1/result.json",
      "bytes": 3611,
      "sha256": "546d32acf556dc1551ab4db391267e79d593aaad311852e920e03fe1f884f5fa",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/posctl-r1/strace.log",
      "bytes": 2372,
      "sha256": "69ccca039a0e009adf06a59664edfe1025c5f34b8ff1ac6c5182245f245836b5",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/posctl-r1/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/posctl-r1/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/posctl-r2/harness.log",
      "bytes": 83,
      "sha256": "426f6d214adcf8a9edbeacbbf3f01e0205242355a35c115f91c7b6734890cab5",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/posctl-r2/machine-id",
      "bytes": 22,
      "sha256": "066a4dfdfb20831e9794f7fc3928064c271a1e2a399ec641e9df5650b4dbd5ea",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/posctl-r2/marks.json",
      "bytes": 268,
      "sha256": "82e6610d06fbb9497848f3e967e8038cbbdac353c1124e55815cde6a6538fae5",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/posctl-r2/result.json",
      "bytes": 3613,
      "sha256": "87ea8c268ece3303851a53e5149fca140ca0bc573f807a85db8a4e8674df2e47",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/posctl-r2/strace.log",
      "bytes": 2372,
      "sha256": "45ba934ca9aa7b075e6fbd75cbb4d41aea78e3c16103f0a06484db382ad86338",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/posctl-r2/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/posctl-r2/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/posctl-r3/harness.log",
      "bytes": 83,
      "sha256": "5ebe47e55a58f288314a260393efac0a8bd9971b0a1a35368209ae2ce1e89931",
      "role": "inside.py's one-line summary of the run, as run-arm.sh captured it."
    },
    {
      "file": "probe/runs/posctl-r3/machine-id",
      "bytes": 22,
      "sha256": "a356d11c2134e9ff5d8f8a97de32ff623669d8bd024b9c2db1cb3dc879b4b685",
      "role": "The fresh random /etc/machine-id this run's container was given (never the host's), replaced by a placeholder naming the run."
    },
    {
      "file": "probe/runs/posctl-r3/marks.json",
      "bytes": 266,
      "sha256": "16a6cae3ebbac1de0855d5c7ff7246b12bd92cb8514a6a6b7dee7faa46c26b69",
      "role": "The test program's own timestamps: start, import done, session created, run done, exit."
    },
    {
      "file": "probe/runs/posctl-r3/result.json",
      "bytes": 3610,
      "sha256": "c17284f0c21fd92cea68fdef26f4e5e965c0e2f26c037c20e3e62c2741c153c1",
      "role": "One run's whole record as inside.py wrote it: the self-test, every lookup, every TLS attempt, every network system call, the files created, the queue's rows read after exit, and the packages installed. Where the run recorded the pre-registration's sha256, prereg_sha256 reads null: withheld (README.md says why)."
    },
    {
      "file": "probe/runs/posctl-r3/strace.log",
      "bytes": 2360,
      "sha256": "e594f4c2d83362e6f46744829a5caf7cb51e956964d165f51dde4f17030d9611",
      "role": "strace's own log of every network system call by the test program's whole process tree, epoch timestamps, one line per call."
    },
    {
      "file": "probe/runs/posctl-r3/subject.stderr",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard error: empty."
    },
    {
      "file": "probe/runs/posctl-r3/subject.stdout",
      "bytes": 0,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "role": "The test program's standard output: empty."
    },
    {
      "file": "probe/runs/preflight.txt",
      "bytes": 467,
      "sha256": "c68006790204145e463a0a932539b3242f46b580768e2d6aa1f2a349ab46f98d",
      "role": "The preflight's record at 08:45:25Z: curl in a --network none container failing to reach 1.1.1.1, 20.184.175.9 and the collector's name."
    },
    {
      "file": "probe/runs/run-all.log",
      "bytes": 7522,
      "sha256": "fbc706171e9c3bdc5ab6d0d1a83ce57a5390df580f06fccbc79818c994d1f682",
      "role": "run-all.sh's own log: the preflight, each round's start, each run's one-line result, and the summariser's table as it printed live at 08:51Z."
    },
    {
      "file": "probe/runs/wheels-SHA256SUMS",
      "bytes": 3250,
      "sha256": "998d9205f917692b6ce1e79a914ef945c12ace68274916489577a048b5cb76b6",
      "role": "The sha256 of every wheel prepare.sh downloaded from PyPI, per onnxruntime version."
    },
    {
      "file": "probe/subject.py",
      "bytes": 3484,
      "sha256": "2e5200647f8dd85720c0f43956155f141b3cb3bec5af9e9512a278bf381fb838",
      "role": "The test program: imports onnxruntime, builds a one-addition model in memory carrying four planted marker strings in three places (the graph name, the producer name, and one metadata key and its value), runs it once, and stays alive for the hold time."
    },
    {
      "file": "probe/summarize.py",
      "bytes": 7446,
      "sha256": "20300506248af87bd135a80cb56c6915c1f338c87bd60ec9eff03fbd4321b52c",
      "role": "The summariser: one table row per run, the verdict per pre-registered prediction, then the secondary table. EDITED AFTER THE RUNS (08:52:14Z: the secondary table was appended; the verdict code was not touched); the bytes that ran at the end of round 3 are probe/as-run/summarize.py."
    }
  ]
}
