docs: honesty/accuracy pass — phone-role disclosure, ICM provenance, dangling-citation fix

- Correct grid disclosure to match the sealed device-map: single-laptop
  isolated-docker host; the two phones are pinned consenting-node labels
  (can_host_engine=false / isolated_engine_available=false), never forwarders
  and carrying no measured traffic — across abstract, apparatus, scope, and
  limitations, plus the companion methods.
- Replace two dangling `PHONE-ROLE-AUDIT.md` citations (file never existed)
  with the real artifact that substantiates the claim: grid/device-map.json;
  vendor that artifact so the citation resolves in a clean clone.
- Drop the stale "(skeleton — quantitative claims held...)" abstract label now
  that the abstract is filled and RQ2 is ratified.
- Disclose that the study was staged, pre-registered, and executed under the
  Interpretable Context Methodology (ICM) [VanClief2026]; add the reference.
- Repoint the bibliography citation to the vendored docs/sor-consent-bibliography.md.
- Regenerate the paper site from the corrected markdown.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
leetcrypt
2026-07-23 10:30:54 -07:00
parent 8f30be186c
commit 07b64a2a9e
4 changed files with 102 additions and 21 deletions
+26 -11
View File
@@ -569,7 +569,7 @@ anonymity set rather than growing it (RQ2-P1, a Holm-significant <em>negative</e
plainly — nulls and negatives are results.</p>
</blockquote>
<hr />
<h2 id="abstract-skeleton-quantitative-claims-held-until-data-rq2-ratification">Abstract <em>(skeleton — quantitative claims held until data + RQ2 ratification)</em></h2>
<h2 id="abstract">Abstract</h2>
<p>Onion-routing systems typically admit any relay that meets a directory's technical criteria;
they do not model <strong>relay consent</strong> — a host's in-band, per-circuit choice to carry a given
flow. We build and measure a <strong>consent-gated, federated, nested-SSH relay data plane</strong> in which
@@ -577,7 +577,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
<strong>houses</strong> that federate either through a shared <strong>bridge</strong> or through a <strong>directory</strong>. Treating
this as a <em>measurement instrument</em> for a trust model's exposure (not a service that provides
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: <strong>(RQ1)</strong>
anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): <strong>(RQ1)</strong>
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
exit segments, and does cover padding remove it; <strong>(RQ2)</strong> does federating relays across houses
<strong>grow or shrink</strong> the anonymity set an adversary faces, and is any effect explained by
@@ -635,8 +635,7 @@ linkability (RQ1) and the anonymity-set effect of federation (RQ2) on a lab grid
when consent-gated federation helps or harms anonymity. <strong>On this instrument the answer is a
double null/negative: no bridge leak to close, and federation that measurably <em>reduces</em> the
anonymity set</strong> — reported here without spin as the paper's evidentiary core.</p>
<p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (two phones +
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
<p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
The paired <strong>churn-resilience</strong> question (RQ3) and a QUIC/<code>ssh3</code> transport arm [Michel2023] are
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.</p>
<hr />
@@ -700,7 +699,14 @@ by the freeze. Key mechanisms:</p>
<hr />
<h2 id="4-methods-pre-registered-frozen">4. Methods (pre-registered; frozen)</h2>
<p>This study is a <strong>confirmatory factorial controlled comparison</strong>; the design, variables, seeds,
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.</p>
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
It was designed, pre-registered, and executed under the <strong>Interpretable Context Methodology</strong>
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
frozen <code>output/</code> is the sole input to the next. ICM is the structural mechanism behind the
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
provenance chain (§4.4) is auditable by construction rather than by convention.</p>
<h3 id="41-design-matrix">4.1 Design matrix</h3>
<p>Cells are organised per RQ with the other factors held at their declared control:</p>
<ul>
@@ -744,7 +750,10 @@ completion — <strong>no optional stopping, no interim looks</strong>; an uninf
<strong>inconclusive</strong>, never extended to chase significance.</p>
<p><strong>Apparatus (disclosed).</strong> All relay hops ran as <strong>isolated Docker containers on a single engine
host</strong> (the laptop; <code>grid/device-map.json</code>, <code>isolated_engine_host_count = 1</code>, Docker 27.5.1). The
two phones were <strong>consenting endpoints, not forwarders</strong>. Node distinctness is thus container-level
two phones were <strong>pinned consenting-node labels, not forwarders</strong> (probed reachable once at grid-pin;
carried no measured traffic — the device map records both phones with <code>can_host_engine = false</code> /
<code>isolated_engine_available = false</code>, i.e. structurally unable to run an isolated forwarder). Node
distinctness is thus container-level
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
per manifest; cross-machine effects are out of scope (§7).</p>
<h3 id="44-frozen-detectors-and-the-instrument-validation-gate">4.4 Frozen detectors and the instrument-validation gate</h3>
@@ -940,14 +949,17 @@ without being explained away.</p>
<hr />
<h2 id="7-limitations-threats-to-validity">7. Limitations &amp; threats to validity</h2>
<ul>
<li><strong>Scale / adversary model (External).</strong> The grid is two phones + a laptop and few houses; this
<li><strong>Scale / adversary model (External).</strong> The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
is <strong>not</strong> internet-scale and <strong>not</strong> a global passive adversary. Claims are scoped to the
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
reported).</li>
<li><strong>Node distribution (External, disclosed).</strong> All relay hops executed as <strong>isolated Docker
containers on a single engine host</strong> (the laptop; <code>isolated_engine_host_count = 1</code>, recorded in
<code>grid/device-map.json</code>). The two phones were <strong>consenting endpoints, not forwarders</strong> — they
cannot host an isolated engine. Node <em>distinctness</em> for RQ1/RQ2 is therefore container-level
<code>grid/device-map.json</code>). The two phones were <strong>pinned consenting-node labels, not forwarders</strong> — they
cannot host an isolated engine (<code>grid/device-map.json</code> records both phones with
<code>can_host_engine = false</code> / <code>isolated_engine_available = false</code>), were verified reachable only by a
single grid-pin probe, and carried no measured traffic. Node <em>distinctness</em> for RQ1/RQ2 is therefore
container-level
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
containerised node count per manifest. This satisfies the containment law (every forwarder runs
in an isolated engine, <code>engine ≠ local</code>) but means cross-machine timing effects are <strong>out of
@@ -1032,8 +1044,11 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
<li><strong>[Mittal2012b]</strong> Mittal, P., Caesar, M., &amp; Borisov, N. (2012). X-Vine. <em>NDSS 2012</em>.
arXiv:1109.0971.</li>
<li><strong>[Zhou2011]</strong> Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.</li>
<li><strong>[VanClief2026]</strong> Van Clief, J., &amp; McDermott, D. (2026). Interpretable Context Methodology:
Folder Structure as Agentic Architecture. arXiv:2603.16021. <em>(Methodology framework under which
this study was staged, pre-registered, and executed.)</em></li>
</ul>
<p><em>(Full bibliography: <code>~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md</code>.
<p><em>(Full bibliography: <code>docs/sor-consent-bibliography.md</code> (vendored in-repo).
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
preprint — neither is load-bearing in this lead paper.)</em></p></article>
</details>
@@ -1383,7 +1398,7 @@ confirmatory battery and have both passed on a <strong>dry, synthetic, offline</
companion's frozen-detector method both <em>caught</em> the unique-bridge artifact and <em>promotes</em> the
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.</li>
<li><strong>Scope &amp; limitations.</strong> Both findings are scoped to the lab grid (1-house / bridge-off control,
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity
single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
caveats. Specific to this companion: (i) the RQ2-P3 mix is an <strong>as-instrumented</strong> concentration
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
are <strong>grid-bound</strong> — the perf null follows from a baseline retention ceiling under the pinned
+1 -1
View File
@@ -343,7 +343,7 @@ confirmatory battery and have both passed on a **dry, synthetic, offline** pass:
companion's frozen-detector method both *caught* the unique-bridge artifact and *promotes* the
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.
- **Scope & limitations.** Both findings are scoped to the lab grid (1-house / bridge-off control,
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity
single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
caveats. Specific to this companion: (i) the RQ2-P3 mix is an **as-instrumented** concentration
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
are **grid-bound** — the perf null follows from a baseline retention ceiling under the pinned
+24 -9
View File
@@ -26,7 +26,7 @@
---
## Abstract *(skeleton — quantitative claims held until data + RQ2 ratification)*
## Abstract
Onion-routing systems typically admit any relay that meets a directory's technical criteria;
they do not model **relay consent** — a host's in-band, per-circuit choice to carry a given
@@ -35,7 +35,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
**houses** that federate either through a shared **bridge** or through a **directory**. Treating
this as a *measurement instrument* for a trust model's exposure (not a service that provides
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: **(RQ1)**
anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): **(RQ1)**
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
exit segments, and does cover padding remove it; **(RQ2)** does federating relays across houses
**grow or shrink** the anonymity set an adversary faces, and is any effect explained by
@@ -95,8 +95,7 @@ when consent-gated federation helps or harms anonymity. **On this instrument the
double null/negative: no bridge leak to close, and federation that measurably *reduces* the
anonymity set** — reported here without spin as the paper's evidentiary core.
**Scope.** Claims are deliberately restricted to the tested lab topology and scale (two phones +
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
**Scope.** Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
The paired **churn-resilience** question (RQ3) and a QUIC/`ssh3` transport arm [Michel2023] are
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.
@@ -172,6 +171,13 @@ by the freeze. Key mechanisms:
This study is a **confirmatory factorial controlled comparison**; the design, variables, seeds,
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
It was designed, pre-registered, and executed under the **Interpretable Context Methodology**
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
frozen `output/` is the sole input to the next. ICM is the structural mechanism behind the
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
provenance chain (§4.4) is auditable by construction rather than by convention.
### 4.1 Design matrix
@@ -218,7 +224,10 @@ completion — **no optional stopping, no interim looks**; an uninformative cell
**Apparatus (disclosed).** All relay hops ran as **isolated Docker containers on a single engine
host** (the laptop; `grid/device-map.json`, `isolated_engine_host_count = 1`, Docker 27.5.1). The
two phones were **consenting endpoints, not forwarders**. Node distinctness is thus container-level
two phones were **pinned consenting-node labels, not forwarders** (probed reachable once at grid-pin;
carried no measured traffic — the device map records both phones with `can_host_engine = false` /
`isolated_engine_available = false`, i.e. structurally unable to run an isolated forwarder). Node
distinctness is thus container-level
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
per manifest; cross-machine effects are out of scope (§7).
@@ -391,14 +400,17 @@ without being explained away.
## 7. Limitations & threats to validity
- **Scale / adversary model (External).** The grid is two phones + a laptop and few houses; this
- **Scale / adversary model (External).** The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
is **not** internet-scale and **not** a global passive adversary. Claims are scoped to the
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
reported).
- **Node distribution (External, disclosed).** All relay hops executed as **isolated Docker
containers on a single engine host** (the laptop; `isolated_engine_host_count = 1`, recorded in
`grid/device-map.json`). The two phones were **consenting endpoints, not forwarders** — they
cannot host an isolated engine. Node *distinctness* for RQ1/RQ2 is therefore container-level
`grid/device-map.json`). The two phones were **pinned consenting-node labels, not forwarders** — they
cannot host an isolated engine (`grid/device-map.json` records both phones with
`can_host_engine = false` / `isolated_engine_available = false`), were verified reachable only by a
single grid-pin probe, and carried no measured traffic. Node *distinctness* for RQ1/RQ2 is therefore
container-level
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
containerised node count per manifest. This satisfies the containment law (every forwarder runs
in an isolated engine, `engine ≠ local`) but means cross-machine timing effects are **out of
@@ -487,7 +499,10 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
- **[Mittal2012b]** Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. *NDSS 2012*.
arXiv:1109.0971.
- **[Zhou2011]** Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.
- **[VanClief2026]** Van Clief, J., & McDermott, D. (2026). Interpretable Context Methodology:
Folder Structure as Agentic Architecture. arXiv:2603.16021. *(Methodology framework under which
this study was staged, pre-registered, and executed.)*
*(Full bibliography: `~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md`.
*(Full bibliography: `docs/sor-consent-bibliography.md` (vendored in-repo).
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
preprint — neither is load-bearing in this lead paper.)*