docs: honesty/accuracy pass — phone-role disclosure, ICM provenance, dangling-citation fix
- Correct grid disclosure to match the sealed device-map: single-laptop isolated-docker host; the two phones are pinned consenting-node labels (can_host_engine=false / isolated_engine_available=false), never forwarders and carrying no measured traffic — across abstract, apparatus, scope, and limitations, plus the companion methods. - Replace two dangling `PHONE-ROLE-AUDIT.md` citations (file never existed) with the real artifact that substantiates the claim: grid/device-map.json; vendor that artifact so the citation resolves in a clean clone. - Drop the stale "(skeleton — quantitative claims held...)" abstract label now that the abstract is filled and RQ2 is ratified. - Disclose that the study was staged, pre-registered, and executed under the Interpretable Context Methodology (ICM) [VanClief2026]; add the reference. - Repoint the bibliography citation to the vendored docs/sor-consent-bibliography.md. - Regenerate the paper site from the corrected markdown. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
+26
-11
@@ -569,7 +569,7 @@ anonymity set rather than growing it (RQ2-P1, a Holm-significant <em>negative</e
|
|||||||
plainly — nulls and negatives are results.</p>
|
plainly — nulls and negatives are results.</p>
|
||||||
</blockquote>
|
</blockquote>
|
||||||
<hr />
|
<hr />
|
||||||
<h2 id="abstract-skeleton-quantitative-claims-held-until-data-rq2-ratification">Abstract <em>(skeleton — quantitative claims held until data + RQ2 ratification)</em></h2>
|
<h2 id="abstract">Abstract</h2>
|
||||||
<p>Onion-routing systems typically admit any relay that meets a directory's technical criteria;
|
<p>Onion-routing systems typically admit any relay that meets a directory's technical criteria;
|
||||||
they do not model <strong>relay consent</strong> — a host's in-band, per-circuit choice to carry a given
|
they do not model <strong>relay consent</strong> — a host's in-band, per-circuit choice to carry a given
|
||||||
flow. We build and measure a <strong>consent-gated, federated, nested-SSH relay data plane</strong> in which
|
flow. We build and measure a <strong>consent-gated, federated, nested-SSH relay data plane</strong> in which
|
||||||
@@ -577,7 +577,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
|
|||||||
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
|
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
|
||||||
<strong>houses</strong> that federate either through a shared <strong>bridge</strong> or through a <strong>directory</strong>. Treating
|
<strong>houses</strong> that federate either through a shared <strong>bridge</strong> or through a <strong>directory</strong>. Treating
|
||||||
this as a <em>measurement instrument</em> for a trust model's exposure (not a service that provides
|
this as a <em>measurement instrument</em> for a trust model's exposure (not a service that provides
|
||||||
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: <strong>(RQ1)</strong>
|
anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): <strong>(RQ1)</strong>
|
||||||
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
|
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
|
||||||
exit segments, and does cover padding remove it; <strong>(RQ2)</strong> does federating relays across houses
|
exit segments, and does cover padding remove it; <strong>(RQ2)</strong> does federating relays across houses
|
||||||
<strong>grow or shrink</strong> the anonymity set an adversary faces, and is any effect explained by
|
<strong>grow or shrink</strong> the anonymity set an adversary faces, and is any effect explained by
|
||||||
@@ -635,8 +635,7 @@ linkability (RQ1) and the anonymity-set effect of federation (RQ2) on a lab grid
|
|||||||
when consent-gated federation helps or harms anonymity. <strong>On this instrument the answer is a
|
when consent-gated federation helps or harms anonymity. <strong>On this instrument the answer is a
|
||||||
double null/negative: no bridge leak to close, and federation that measurably <em>reduces</em> the
|
double null/negative: no bridge leak to close, and federation that measurably <em>reduces</em> the
|
||||||
anonymity set</strong> — reported here without spin as the paper's evidentiary core.</p>
|
anonymity set</strong> — reported here without spin as the paper's evidentiary core.</p>
|
||||||
<p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (two phones +
|
<p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
|
||||||
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
|
|
||||||
The paired <strong>churn-resilience</strong> question (RQ3) and a QUIC/<code>ssh3</code> transport arm [Michel2023] are
|
The paired <strong>churn-resilience</strong> question (RQ3) and a QUIC/<code>ssh3</code> transport arm [Michel2023] are
|
||||||
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.</p>
|
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.</p>
|
||||||
<hr />
|
<hr />
|
||||||
@@ -700,7 +699,14 @@ by the freeze. Key mechanisms:</p>
|
|||||||
<hr />
|
<hr />
|
||||||
<h2 id="4-methods-pre-registered-frozen">4. Methods (pre-registered; frozen)</h2>
|
<h2 id="4-methods-pre-registered-frozen">4. Methods (pre-registered; frozen)</h2>
|
||||||
<p>This study is a <strong>confirmatory factorial controlled comparison</strong>; the design, variables, seeds,
|
<p>This study is a <strong>confirmatory factorial controlled comparison</strong>; the design, variables, seeds,
|
||||||
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.</p>
|
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
|
||||||
|
It was designed, pre-registered, and executed under the <strong>Interpretable Context Methodology</strong>
|
||||||
|
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
|
||||||
|
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
|
||||||
|
frozen <code>output/</code> is the sole input to the next. ICM is the structural mechanism behind the
|
||||||
|
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
|
||||||
|
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
|
||||||
|
provenance chain (§4.4) is auditable by construction rather than by convention.</p>
|
||||||
<h3 id="41-design-matrix">4.1 Design matrix</h3>
|
<h3 id="41-design-matrix">4.1 Design matrix</h3>
|
||||||
<p>Cells are organised per RQ with the other factors held at their declared control:</p>
|
<p>Cells are organised per RQ with the other factors held at their declared control:</p>
|
||||||
<ul>
|
<ul>
|
||||||
@@ -744,7 +750,10 @@ completion — <strong>no optional stopping, no interim looks</strong>; an uninf
|
|||||||
<strong>inconclusive</strong>, never extended to chase significance.</p>
|
<strong>inconclusive</strong>, never extended to chase significance.</p>
|
||||||
<p><strong>Apparatus (disclosed).</strong> All relay hops ran as <strong>isolated Docker containers on a single engine
|
<p><strong>Apparatus (disclosed).</strong> All relay hops ran as <strong>isolated Docker containers on a single engine
|
||||||
host</strong> (the laptop; <code>grid/device-map.json</code>, <code>isolated_engine_host_count = 1</code>, Docker 27.5.1). The
|
host</strong> (the laptop; <code>grid/device-map.json</code>, <code>isolated_engine_host_count = 1</code>, Docker 27.5.1). The
|
||||||
two phones were <strong>consenting endpoints, not forwarders</strong>. Node distinctness is thus container-level
|
two phones were <strong>pinned consenting-node labels, not forwarders</strong> (probed reachable once at grid-pin;
|
||||||
|
carried no measured traffic — the device map records both phones with <code>can_host_engine = false</code> /
|
||||||
|
<code>isolated_engine_available = false</code>, i.e. structurally unable to run an isolated forwarder). Node
|
||||||
|
distinctness is thus container-level
|
||||||
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
|
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
|
||||||
per manifest; cross-machine effects are out of scope (§7).</p>
|
per manifest; cross-machine effects are out of scope (§7).</p>
|
||||||
<h3 id="44-frozen-detectors-and-the-instrument-validation-gate">4.4 Frozen detectors and the instrument-validation gate</h3>
|
<h3 id="44-frozen-detectors-and-the-instrument-validation-gate">4.4 Frozen detectors and the instrument-validation gate</h3>
|
||||||
@@ -940,14 +949,17 @@ without being explained away.</p>
|
|||||||
<hr />
|
<hr />
|
||||||
<h2 id="7-limitations-threats-to-validity">7. Limitations & threats to validity</h2>
|
<h2 id="7-limitations-threats-to-validity">7. Limitations & threats to validity</h2>
|
||||||
<ul>
|
<ul>
|
||||||
<li><strong>Scale / adversary model (External).</strong> The grid is two phones + a laptop and few houses; this
|
<li><strong>Scale / adversary model (External).</strong> The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
|
||||||
is <strong>not</strong> internet-scale and <strong>not</strong> a global passive adversary. Claims are scoped to the
|
is <strong>not</strong> internet-scale and <strong>not</strong> a global passive adversary. Claims are scoped to the
|
||||||
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
|
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
|
||||||
reported).</li>
|
reported).</li>
|
||||||
<li><strong>Node distribution (External, disclosed).</strong> All relay hops executed as <strong>isolated Docker
|
<li><strong>Node distribution (External, disclosed).</strong> All relay hops executed as <strong>isolated Docker
|
||||||
containers on a single engine host</strong> (the laptop; <code>isolated_engine_host_count = 1</code>, recorded in
|
containers on a single engine host</strong> (the laptop; <code>isolated_engine_host_count = 1</code>, recorded in
|
||||||
<code>grid/device-map.json</code>). The two phones were <strong>consenting endpoints, not forwarders</strong> — they
|
<code>grid/device-map.json</code>). The two phones were <strong>pinned consenting-node labels, not forwarders</strong> — they
|
||||||
cannot host an isolated engine. Node <em>distinctness</em> for RQ1/RQ2 is therefore container-level
|
cannot host an isolated engine (<code>grid/device-map.json</code> records both phones with
|
||||||
|
<code>can_host_engine = false</code> / <code>isolated_engine_available = false</code>), were verified reachable only by a
|
||||||
|
single grid-pin probe, and carried no measured traffic. Node <em>distinctness</em> for RQ1/RQ2 is therefore
|
||||||
|
container-level
|
||||||
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
|
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
|
||||||
containerised node count per manifest. This satisfies the containment law (every forwarder runs
|
containerised node count per manifest. This satisfies the containment law (every forwarder runs
|
||||||
in an isolated engine, <code>engine ≠ local</code>) but means cross-machine timing effects are <strong>out of
|
in an isolated engine, <code>engine ≠ local</code>) but means cross-machine timing effects are <strong>out of
|
||||||
@@ -1032,8 +1044,11 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
|
|||||||
<li><strong>[Mittal2012b]</strong> Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. <em>NDSS 2012</em>.
|
<li><strong>[Mittal2012b]</strong> Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. <em>NDSS 2012</em>.
|
||||||
arXiv:1109.0971.</li>
|
arXiv:1109.0971.</li>
|
||||||
<li><strong>[Zhou2011]</strong> Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.</li>
|
<li><strong>[Zhou2011]</strong> Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.</li>
|
||||||
|
<li><strong>[VanClief2026]</strong> Van Clief, J., & McDermott, D. (2026). Interpretable Context Methodology:
|
||||||
|
Folder Structure as Agentic Architecture. arXiv:2603.16021. <em>(Methodology framework under which
|
||||||
|
this study was staged, pre-registered, and executed.)</em></li>
|
||||||
</ul>
|
</ul>
|
||||||
<p><em>(Full bibliography: <code>~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md</code>.
|
<p><em>(Full bibliography: <code>docs/sor-consent-bibliography.md</code> (vendored in-repo).
|
||||||
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
|
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
|
||||||
preprint — neither is load-bearing in this lead paper.)</em></p></article>
|
preprint — neither is load-bearing in this lead paper.)</em></p></article>
|
||||||
</details>
|
</details>
|
||||||
@@ -1383,7 +1398,7 @@ confirmatory battery and have both passed on a <strong>dry, synthetic, offline</
|
|||||||
companion's frozen-detector method both <em>caught</em> the unique-bridge artifact and <em>promotes</em> the
|
companion's frozen-detector method both <em>caught</em> the unique-bridge artifact and <em>promotes</em> the
|
||||||
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.</li>
|
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.</li>
|
||||||
<li><strong>Scope & limitations.</strong> Both findings are scoped to the lab grid (1-house / bridge-off control,
|
<li><strong>Scope & limitations.</strong> Both findings are scoped to the lab grid (1-house / bridge-off control,
|
||||||
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity
|
single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
|
||||||
caveats. Specific to this companion: (i) the RQ2-P3 mix is an <strong>as-instrumented</strong> concentration
|
caveats. Specific to this companion: (i) the RQ2-P3 mix is an <strong>as-instrumented</strong> concentration
|
||||||
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
|
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
|
||||||
are <strong>grid-bound</strong> — the perf null follows from a baseline retention ceiling under the pinned
|
are <strong>grid-bound</strong> — the perf null follows from a baseline retention ceiling under the pinned
|
||||||
|
|||||||
@@ -343,7 +343,7 @@ confirmatory battery and have both passed on a **dry, synthetic, offline** pass:
|
|||||||
companion's frozen-detector method both *caught* the unique-bridge artifact and *promotes* the
|
companion's frozen-detector method both *caught* the unique-bridge artifact and *promotes* the
|
||||||
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.
|
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.
|
||||||
- **Scope & limitations.** Both findings are scoped to the lab grid (1-house / bridge-off control,
|
- **Scope & limitations.** Both findings are scoped to the lab grid (1-house / bridge-off control,
|
||||||
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity
|
single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
|
||||||
caveats. Specific to this companion: (i) the RQ2-P3 mix is an **as-instrumented** concentration
|
caveats. Specific to this companion: (i) the RQ2-P3 mix is an **as-instrumented** concentration
|
||||||
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
|
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
|
||||||
are **grid-bound** — the perf null follows from a baseline retention ceiling under the pinned
|
are **grid-bound** — the perf null follows from a baseline retention ceiling under the pinned
|
||||||
|
|||||||
@@ -26,7 +26,7 @@
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Abstract *(skeleton — quantitative claims held until data + RQ2 ratification)*
|
## Abstract
|
||||||
|
|
||||||
Onion-routing systems typically admit any relay that meets a directory's technical criteria;
|
Onion-routing systems typically admit any relay that meets a directory's technical criteria;
|
||||||
they do not model **relay consent** — a host's in-band, per-circuit choice to carry a given
|
they do not model **relay consent** — a host's in-band, per-circuit choice to carry a given
|
||||||
@@ -35,7 +35,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
|
|||||||
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
|
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
|
||||||
**houses** that federate either through a shared **bridge** or through a **directory**. Treating
|
**houses** that federate either through a shared **bridge** or through a **directory**. Treating
|
||||||
this as a *measurement instrument* for a trust model's exposure (not a service that provides
|
this as a *measurement instrument* for a trust model's exposure (not a service that provides
|
||||||
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: **(RQ1)**
|
anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): **(RQ1)**
|
||||||
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
|
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
|
||||||
exit segments, and does cover padding remove it; **(RQ2)** does federating relays across houses
|
exit segments, and does cover padding remove it; **(RQ2)** does federating relays across houses
|
||||||
**grow or shrink** the anonymity set an adversary faces, and is any effect explained by
|
**grow or shrink** the anonymity set an adversary faces, and is any effect explained by
|
||||||
@@ -95,8 +95,7 @@ when consent-gated federation helps or harms anonymity. **On this instrument the
|
|||||||
double null/negative: no bridge leak to close, and federation that measurably *reduces* the
|
double null/negative: no bridge leak to close, and federation that measurably *reduces* the
|
||||||
anonymity set** — reported here without spin as the paper's evidentiary core.
|
anonymity set** — reported here without spin as the paper's evidentiary core.
|
||||||
|
|
||||||
**Scope.** Claims are deliberately restricted to the tested lab topology and scale (two phones +
|
**Scope.** Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
|
||||||
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
|
|
||||||
The paired **churn-resilience** question (RQ3) and a QUIC/`ssh3` transport arm [Michel2023] are
|
The paired **churn-resilience** question (RQ3) and a QUIC/`ssh3` transport arm [Michel2023] are
|
||||||
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.
|
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.
|
||||||
|
|
||||||
@@ -172,6 +171,13 @@ by the freeze. Key mechanisms:
|
|||||||
|
|
||||||
This study is a **confirmatory factorial controlled comparison**; the design, variables, seeds,
|
This study is a **confirmatory factorial controlled comparison**; the design, variables, seeds,
|
||||||
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
|
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
|
||||||
|
It was designed, pre-registered, and executed under the **Interpretable Context Methodology**
|
||||||
|
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
|
||||||
|
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
|
||||||
|
frozen `output/` is the sole input to the next. ICM is the structural mechanism behind the
|
||||||
|
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
|
||||||
|
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
|
||||||
|
provenance chain (§4.4) is auditable by construction rather than by convention.
|
||||||
|
|
||||||
### 4.1 Design matrix
|
### 4.1 Design matrix
|
||||||
|
|
||||||
@@ -218,7 +224,10 @@ completion — **no optional stopping, no interim looks**; an uninformative cell
|
|||||||
|
|
||||||
**Apparatus (disclosed).** All relay hops ran as **isolated Docker containers on a single engine
|
**Apparatus (disclosed).** All relay hops ran as **isolated Docker containers on a single engine
|
||||||
host** (the laptop; `grid/device-map.json`, `isolated_engine_host_count = 1`, Docker 27.5.1). The
|
host** (the laptop; `grid/device-map.json`, `isolated_engine_host_count = 1`, Docker 27.5.1). The
|
||||||
two phones were **consenting endpoints, not forwarders**. Node distinctness is thus container-level
|
two phones were **pinned consenting-node labels, not forwarders** (probed reachable once at grid-pin;
|
||||||
|
carried no measured traffic — the device map records both phones with `can_host_engine = false` /
|
||||||
|
`isolated_engine_available = false`, i.e. structurally unable to run an isolated forwarder). Node
|
||||||
|
distinctness is thus container-level
|
||||||
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
|
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
|
||||||
per manifest; cross-machine effects are out of scope (§7).
|
per manifest; cross-machine effects are out of scope (§7).
|
||||||
|
|
||||||
@@ -391,14 +400,17 @@ without being explained away.
|
|||||||
|
|
||||||
## 7. Limitations & threats to validity
|
## 7. Limitations & threats to validity
|
||||||
|
|
||||||
- **Scale / adversary model (External).** The grid is two phones + a laptop and few houses; this
|
- **Scale / adversary model (External).** The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
|
||||||
is **not** internet-scale and **not** a global passive adversary. Claims are scoped to the
|
is **not** internet-scale and **not** a global passive adversary. Claims are scoped to the
|
||||||
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
|
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
|
||||||
reported).
|
reported).
|
||||||
- **Node distribution (External, disclosed).** All relay hops executed as **isolated Docker
|
- **Node distribution (External, disclosed).** All relay hops executed as **isolated Docker
|
||||||
containers on a single engine host** (the laptop; `isolated_engine_host_count = 1`, recorded in
|
containers on a single engine host** (the laptop; `isolated_engine_host_count = 1`, recorded in
|
||||||
`grid/device-map.json`). The two phones were **consenting endpoints, not forwarders** — they
|
`grid/device-map.json`). The two phones were **pinned consenting-node labels, not forwarders** — they
|
||||||
cannot host an isolated engine. Node *distinctness* for RQ1/RQ2 is therefore container-level
|
cannot host an isolated engine (`grid/device-map.json` records both phones with
|
||||||
|
`can_host_engine = false` / `isolated_engine_available = false`), were verified reachable only by a
|
||||||
|
single grid-pin probe, and carried no measured traffic. Node *distinctness* for RQ1/RQ2 is therefore
|
||||||
|
container-level
|
||||||
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
|
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
|
||||||
containerised node count per manifest. This satisfies the containment law (every forwarder runs
|
containerised node count per manifest. This satisfies the containment law (every forwarder runs
|
||||||
in an isolated engine, `engine ≠ local`) but means cross-machine timing effects are **out of
|
in an isolated engine, `engine ≠ local`) but means cross-machine timing effects are **out of
|
||||||
@@ -487,7 +499,10 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
|
|||||||
- **[Mittal2012b]** Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. *NDSS 2012*.
|
- **[Mittal2012b]** Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. *NDSS 2012*.
|
||||||
arXiv:1109.0971.
|
arXiv:1109.0971.
|
||||||
- **[Zhou2011]** Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.
|
- **[Zhou2011]** Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.
|
||||||
|
- **[VanClief2026]** Van Clief, J., & McDermott, D. (2026). Interpretable Context Methodology:
|
||||||
|
Folder Structure as Agentic Architecture. arXiv:2603.16021. *(Methodology framework under which
|
||||||
|
this study was staged, pre-registered, and executed.)*
|
||||||
|
|
||||||
*(Full bibliography: `~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md`.
|
*(Full bibliography: `docs/sor-consent-bibliography.md` (vendored in-repo).
|
||||||
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
|
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
|
||||||
preprint — neither is load-bearing in this lead paper.)*
|
preprint — neither is load-bearing in this lead paper.)*
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
{
|
||||||
|
"assessment": "GO on isolated docker host",
|
||||||
|
"containment": {
|
||||||
|
"external_target": "none",
|
||||||
|
"hops_run_in": "isolated docker containers only (never a phone/host forwarder)",
|
||||||
|
"live_vm_churn_on_rq1_rq2": "none (RQ1/RQ2 use no churn; churn_schedule_id=none)",
|
||||||
|
"self_traffic_only": true
|
||||||
|
},
|
||||||
|
"degraded": false,
|
||||||
|
"devices": [
|
||||||
|
{
|
||||||
|
"arch": "x86_64",
|
||||||
|
"can_host_engine": true,
|
||||||
|
"engine_version": "27.5.1",
|
||||||
|
"house_role": "house-A docker host + hop pool",
|
||||||
|
"isolated_engine_available": true,
|
||||||
|
"kind": "laptop",
|
||||||
|
"name": "laptop",
|
||||||
|
"ssh_reachable": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"arch": "aarch64",
|
||||||
|
"can_host_engine": false,
|
||||||
|
"engine_version": null,
|
||||||
|
"house_role": "house-B consenting node (phone)",
|
||||||
|
"isolated_engine_available": false,
|
||||||
|
"kind": "phone",
|
||||||
|
"name": "fp6",
|
||||||
|
"ssh_reachable": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"arch": "aarch64",
|
||||||
|
"can_host_engine": false,
|
||||||
|
"engine_version": null,
|
||||||
|
"house_role": "house-C consenting node (Termux, no docker)",
|
||||||
|
"isolated_engine_available": false,
|
||||||
|
"kind": "phone",
|
||||||
|
"name": "tril",
|
||||||
|
"ssh_reachable": true
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"devices_down": [],
|
||||||
|
"generated_utc": "2026-07-20T06:01:52Z",
|
||||||
|
"isolated_engine_host_count": 1,
|
||||||
|
"local_docker_version": "27.5.1",
|
||||||
|
"matched_N_note": "RQ1/RQ2 isolated hops are containerised on the docker host (>=3 distinct containers = distinct nodes). Physical-phone distribution is optional; the confirmatory matched-N (single-house N = federated total consenting nodes) is pinned from the containerised node count at run time and recorded per manifest.",
|
||||||
|
"reachable_count": 3,
|
||||||
|
"schema": "sor-device-map/1",
|
||||||
|
"scope": "RQ1+RQ2 lead-paper grid pin (CLAUDE.md \u00a7Containment)",
|
||||||
|
"topology_matchedN_honourable": true
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user