docs: honesty/accuracy pass — phone-role disclosure, ICM provenance, dangling-citation fix

- Correct grid disclosure to match the sealed device-map: single-laptop
  isolated-docker host; the two phones are pinned consenting-node labels
  (can_host_engine=false / isolated_engine_available=false), never forwarders
  and carrying no measured traffic — across abstract, apparatus, scope, and
  limitations, plus the companion methods.
- Replace two dangling `PHONE-ROLE-AUDIT.md` citations (file never existed)
  with the real artifact that substantiates the claim: grid/device-map.json;
  vendor that artifact so the citation resolves in a clean clone.
- Drop the stale "(skeleton — quantitative claims held...)" abstract label now
  that the abstract is filled and RQ2 is ratified.
- Disclose that the study was staged, pre-registered, and executed under the
  Interpretable Context Methodology (ICM) [VanClief2026]; add the reference.
- Repoint the bibliography citation to the vendored docs/sor-consent-bibliography.md.
- Regenerate the paper site from the corrected markdown.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
leetcrypt
2026-07-23 10:30:54 -07:00
parent 8f30be186c
commit 07b64a2a9e
4 changed files with 102 additions and 21 deletions
+26 -11
View File
@@ -569,7 +569,7 @@ anonymity set rather than growing it (RQ2-P1, a Holm-significant <em>negative</e
plainly — nulls and negatives are results.</p> plainly — nulls and negatives are results.</p>
</blockquote> </blockquote>
<hr /> <hr />
<h2 id="abstract-skeleton-quantitative-claims-held-until-data-rq2-ratification">Abstract <em>(skeleton — quantitative claims held until data + RQ2 ratification)</em></h2> <h2 id="abstract">Abstract</h2>
<p>Onion-routing systems typically admit any relay that meets a directory's technical criteria; <p>Onion-routing systems typically admit any relay that meets a directory's technical criteria;
they do not model <strong>relay consent</strong> — a host's in-band, per-circuit choice to carry a given they do not model <strong>relay consent</strong> — a host's in-band, per-circuit choice to carry a given
flow. We build and measure a <strong>consent-gated, federated, nested-SSH relay data plane</strong> in which flow. We build and measure a <strong>consent-gated, federated, nested-SSH relay data plane</strong> in which
@@ -577,7 +577,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into (Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
<strong>houses</strong> that federate either through a shared <strong>bridge</strong> or through a <strong>directory</strong>. Treating <strong>houses</strong> that federate either through a shared <strong>bridge</strong> or through a <strong>directory</strong>. Treating
this as a <em>measurement instrument</em> for a trust model's exposure (not a service that provides this as a <em>measurement instrument</em> for a trust model's exposure (not a service that provides
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: <strong>(RQ1)</strong> anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): <strong>(RQ1)</strong>
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
exit segments, and does cover padding remove it; <strong>(RQ2)</strong> does federating relays across houses exit segments, and does cover padding remove it; <strong>(RQ2)</strong> does federating relays across houses
<strong>grow or shrink</strong> the anonymity set an adversary faces, and is any effect explained by <strong>grow or shrink</strong> the anonymity set an adversary faces, and is any effect explained by
@@ -635,8 +635,7 @@ linkability (RQ1) and the anonymity-set effect of federation (RQ2) on a lab grid
when consent-gated federation helps or harms anonymity. <strong>On this instrument the answer is a when consent-gated federation helps or harms anonymity. <strong>On this instrument the answer is a
double null/negative: no bridge leak to close, and federation that measurably <em>reduces</em> the double null/negative: no bridge leak to close, and federation that measurably <em>reduces</em> the
anonymity set</strong> — reported here without spin as the paper's evidentiary core.</p> anonymity set</strong> — reported here without spin as the paper's evidentiary core.</p>
<p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (two phones + <p><strong>Scope.</strong> Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
The paired <strong>churn-resilience</strong> question (RQ3) and a QUIC/<code>ssh3</code> transport arm [Michel2023] are The paired <strong>churn-resilience</strong> question (RQ3) and a QUIC/<code>ssh3</code> transport arm [Michel2023] are
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.</p> pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.</p>
<hr /> <hr />
@@ -700,7 +699,14 @@ by the freeze. Key mechanisms:</p>
<hr /> <hr />
<h2 id="4-methods-pre-registered-frozen">4. Methods (pre-registered; frozen)</h2> <h2 id="4-methods-pre-registered-frozen">4. Methods (pre-registered; frozen)</h2>
<p>This study is a <strong>confirmatory factorial controlled comparison</strong>; the design, variables, seeds, <p>This study is a <strong>confirmatory factorial controlled comparison</strong>; the design, variables, seeds,
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.</p> detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
It was designed, pre-registered, and executed under the <strong>Interpretable Context Methodology</strong>
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
frozen <code>output/</code> is the sole input to the next. ICM is the structural mechanism behind the
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
provenance chain (§4.4) is auditable by construction rather than by convention.</p>
<h3 id="41-design-matrix">4.1 Design matrix</h3> <h3 id="41-design-matrix">4.1 Design matrix</h3>
<p>Cells are organised per RQ with the other factors held at their declared control:</p> <p>Cells are organised per RQ with the other factors held at their declared control:</p>
<ul> <ul>
@@ -744,7 +750,10 @@ completion — <strong>no optional stopping, no interim looks</strong>; an uninf
<strong>inconclusive</strong>, never extended to chase significance.</p> <strong>inconclusive</strong>, never extended to chase significance.</p>
<p><strong>Apparatus (disclosed).</strong> All relay hops ran as <strong>isolated Docker containers on a single engine <p><strong>Apparatus (disclosed).</strong> All relay hops ran as <strong>isolated Docker containers on a single engine
host</strong> (the laptop; <code>grid/device-map.json</code>, <code>isolated_engine_host_count = 1</code>, Docker 27.5.1). The host</strong> (the laptop; <code>grid/device-map.json</code>, <code>isolated_engine_host_count = 1</code>, Docker 27.5.1). The
two phones were <strong>consenting endpoints, not forwarders</strong>. Node distinctness is thus container-level two phones were <strong>pinned consenting-node labels, not forwarders</strong> (probed reachable once at grid-pin;
carried no measured traffic — the device map records both phones with <code>can_host_engine = false</code> /
<code>isolated_engine_available = false</code>, i.e. structurally unable to run an isolated forwarder). Node
distinctness is thus container-level
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count (≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
per manifest; cross-machine effects are out of scope (§7).</p> per manifest; cross-machine effects are out of scope (§7).</p>
<h3 id="44-frozen-detectors-and-the-instrument-validation-gate">4.4 Frozen detectors and the instrument-validation gate</h3> <h3 id="44-frozen-detectors-and-the-instrument-validation-gate">4.4 Frozen detectors and the instrument-validation gate</h3>
@@ -940,14 +949,17 @@ without being explained away.</p>
<hr /> <hr />
<h2 id="7-limitations-threats-to-validity">7. Limitations &amp; threats to validity</h2> <h2 id="7-limitations-threats-to-validity">7. Limitations &amp; threats to validity</h2>
<ul> <ul>
<li><strong>Scale / adversary model (External).</strong> The grid is two phones + a laptop and few houses; this <li><strong>Scale / adversary model (External).</strong> The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
is <strong>not</strong> internet-scale and <strong>not</strong> a global passive adversary. Claims are scoped to the is <strong>not</strong> internet-scale and <strong>not</strong> a global passive adversary. Claims are scoped to the
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
reported).</li> reported).</li>
<li><strong>Node distribution (External, disclosed).</strong> All relay hops executed as <strong>isolated Docker <li><strong>Node distribution (External, disclosed).</strong> All relay hops executed as <strong>isolated Docker
containers on a single engine host</strong> (the laptop; <code>isolated_engine_host_count = 1</code>, recorded in containers on a single engine host</strong> (the laptop; <code>isolated_engine_host_count = 1</code>, recorded in
<code>grid/device-map.json</code>). The two phones were <strong>consenting endpoints, not forwarders</strong> — they <code>grid/device-map.json</code>). The two phones were <strong>pinned consenting-node labels, not forwarders</strong> — they
cannot host an isolated engine. Node <em>distinctness</em> for RQ1/RQ2 is therefore container-level cannot host an isolated engine (<code>grid/device-map.json</code> records both phones with
<code>can_host_engine = false</code> / <code>isolated_engine_available = false</code>), were verified reachable only by a
single grid-pin probe, and carried no measured traffic. Node <em>distinctness</em> for RQ1/RQ2 is therefore
container-level
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the (≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
containerised node count per manifest. This satisfies the containment law (every forwarder runs containerised node count per manifest. This satisfies the containment law (every forwarder runs
in an isolated engine, <code>engine ≠ local</code>) but means cross-machine timing effects are <strong>out of in an isolated engine, <code>engine ≠ local</code>) but means cross-machine timing effects are <strong>out of
@@ -1032,8 +1044,11 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
<li><strong>[Mittal2012b]</strong> Mittal, P., Caesar, M., &amp; Borisov, N. (2012). X-Vine. <em>NDSS 2012</em>. <li><strong>[Mittal2012b]</strong> Mittal, P., Caesar, M., &amp; Borisov, N. (2012). X-Vine. <em>NDSS 2012</em>.
arXiv:1109.0971.</li> arXiv:1109.0971.</li>
<li><strong>[Zhou2011]</strong> Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.</li> <li><strong>[Zhou2011]</strong> Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.</li>
<li><strong>[VanClief2026]</strong> Van Clief, J., &amp; McDermott, D. (2026). Interpretable Context Methodology:
Folder Structure as Agentic Architecture. arXiv:2603.16021. <em>(Methodology framework under which
this study was staged, pre-registered, and executed.)</em></li>
</ul> </ul>
<p><em>(Full bibliography: <code>~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md</code>. <p><em>(Full bibliography: <code>docs/sor-consent-bibliography.md</code> (vendored in-repo).
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
preprint — neither is load-bearing in this lead paper.)</em></p></article> preprint — neither is load-bearing in this lead paper.)</em></p></article>
</details> </details>
@@ -1383,7 +1398,7 @@ confirmatory battery and have both passed on a <strong>dry, synthetic, offline</
companion's frozen-detector method both <em>caught</em> the unique-bridge artifact and <em>promotes</em> the companion's frozen-detector method both <em>caught</em> the unique-bridge artifact and <em>promotes</em> the
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.</li> corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.</li>
<li><strong>Scope &amp; limitations.</strong> Both findings are scoped to the lab grid (1-house / bridge-off control, <li><strong>Scope &amp; limitations.</strong> Both findings are scoped to the lab grid (1-house / bridge-off control,
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
caveats. Specific to this companion: (i) the RQ2-P3 mix is an <strong>as-instrumented</strong> concentration caveats. Specific to this companion: (i) the RQ2-P3 mix is an <strong>as-instrumented</strong> concentration
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
are <strong>grid-bound</strong> — the perf null follows from a baseline retention ceiling under the pinned are <strong>grid-bound</strong> — the perf null follows from a baseline retention ceiling under the pinned
+1 -1
View File
@@ -343,7 +343,7 @@ confirmatory battery and have both passed on a **dry, synthetic, offline** pass:
companion's frozen-detector method both *caught* the unique-bridge artifact and *promotes* the companion's frozen-detector method both *caught* the unique-bridge artifact and *promotes* the
corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless. corrected mechanism finding into the surviving family. Lead RQ1-P1 and RQ2-P1 survive regardless.
- **Scope & limitations.** Both findings are scoped to the lab grid (1-house / bridge-off control, - **Scope & limitations.** Both findings are scoped to the lab grid (1-house / bridge-off control,
2 phones + laptop, self-generated fixture traffic) and inherit the lead paper's external-validity single-laptop isolated-docker, two non-forwarding phones, self-generated fixture traffic) and inherit the lead paper's external-validity
caveats. Specific to this companion: (i) the RQ2-P3 mix is an **as-instrumented** concentration caveats. Specific to this companion: (i) the RQ2-P3 mix is an **as-instrumented** concentration
effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls effect on the ratified exit-signature posterior, not an internet-scale claim; (ii) the RQ3 nulls
are **grid-bound** — the perf null follows from a baseline retention ceiling under the pinned are **grid-bound** — the perf null follows from a baseline retention ceiling under the pinned
+24 -9
View File
@@ -26,7 +26,7 @@
--- ---
## Abstract *(skeleton — quantitative claims held until data + RQ2 ratification)* ## Abstract
Onion-routing systems typically admit any relay that meets a directory's technical criteria; Onion-routing systems typically admit any relay that meets a directory's technical criteria;
they do not model **relay consent** — a host's in-band, per-circuit choice to carry a given they do not model **relay consent** — a host's in-band, per-circuit choice to carry a given
@@ -35,7 +35,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band
(Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into (Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into
**houses** that federate either through a shared **bridge** or through a **directory**. Treating **houses** that federate either through a shared **bridge** or through a **directory**. Treating
this as a *measurement instrument* for a trust model's exposure (not a service that provides this as a *measurement instrument* for a trust model's exposure (not a service that provides
anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: **(RQ1)** anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): **(RQ1)**
does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and
exit segments, and does cover padding remove it; **(RQ2)** does federating relays across houses exit segments, and does cover padding remove it; **(RQ2)** does federating relays across houses
**grow or shrink** the anonymity set an adversary faces, and is any effect explained by **grow or shrink** the anonymity set an adversary faces, and is any effect explained by
@@ -95,8 +95,7 @@ when consent-gated federation helps or harms anonymity. **On this instrument the
double null/negative: no bridge leak to close, and federation that measurably *reduces* the double null/negative: no bridge leak to close, and federation that measurably *reduces* the
anonymity set** — reported here without spin as the paper's evidentiary core. anonymity set** — reported here without spin as the paper's evidentiary core.
**Scope.** Claims are deliberately restricted to the tested lab topology and scale (two phones + **Scope.** Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7).
laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7).
The paired **churn-resilience** question (RQ3) and a QUIC/`ssh3` transport arm [Michel2023] are The paired **churn-resilience** question (RQ3) and a QUIC/`ssh3` transport arm [Michel2023] are
pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only. pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.
@@ -172,6 +171,13 @@ by the freeze. Key mechanisms:
This study is a **confirmatory factorial controlled comparison**; the design, variables, seeds, This study is a **confirmatory factorial controlled comparison**; the design, variables, seeds,
detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran. detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.
It was designed, pre-registered, and executed under the **Interpretable Context Methodology**
(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis,
design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose
frozen `output/` is the sole input to the next. ICM is the structural mechanism behind the
freeze-before-data discipline used throughout this section: the pre-registration was frozen and
SHA-256-sealed in the design stage before the build and execution stages could consume it, so the
provenance chain (§4.4) is auditable by construction rather than by convention.
### 4.1 Design matrix ### 4.1 Design matrix
@@ -218,7 +224,10 @@ completion — **no optional stopping, no interim looks**; an uninformative cell
**Apparatus (disclosed).** All relay hops ran as **isolated Docker containers on a single engine **Apparatus (disclosed).** All relay hops ran as **isolated Docker containers on a single engine
host** (the laptop; `grid/device-map.json`, `isolated_engine_host_count = 1`, Docker 27.5.1). The host** (the laptop; `grid/device-map.json`, `isolated_engine_host_count = 1`, Docker 27.5.1). The
two phones were **consenting endpoints, not forwarders**. Node distinctness is thus container-level two phones were **pinned consenting-node labels, not forwarders** (probed reachable once at grid-pin;
carried no measured traffic — the device map records both phones with `can_host_engine = false` /
`isolated_engine_available = false`, i.e. structurally unable to run an isolated forwarder). Node
distinctness is thus container-level
(≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count (≥ 3 distinct containers per circuit), and matched-N is pinned from the containerised node count
per manifest; cross-machine effects are out of scope (§7). per manifest; cross-machine effects are out of scope (§7).
@@ -391,14 +400,17 @@ without being explained away.
## 7. Limitations & threats to validity ## 7. Limitations & threats to validity
- **Scale / adversary model (External).** The grid is two phones + a laptop and few houses; this - **Scale / adversary model (External).** The grid is a single laptop (isolated-docker) with two non-forwarding phones pinned, and few houses; this
is **not** internet-scale and **not** a global passive adversary. Claims are scoped to the is **not** internet-scale and **not** a global passive adversary. Claims are scoped to the
tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts tested topology/scale; entropy CIs are wide at small node counts (accepted, node counts
reported). reported).
- **Node distribution (External, disclosed).** All relay hops executed as **isolated Docker - **Node distribution (External, disclosed).** All relay hops executed as **isolated Docker
containers on a single engine host** (the laptop; `isolated_engine_host_count = 1`, recorded in containers on a single engine host** (the laptop; `isolated_engine_host_count = 1`, recorded in
`grid/device-map.json`). The two phones were **consenting endpoints, not forwarders** — they `grid/device-map.json`). The two phones were **pinned consenting-node labels, not forwarders** — they
cannot host an isolated engine. Node *distinctness* for RQ1/RQ2 is therefore container-level cannot host an isolated engine (`grid/device-map.json` records both phones with
`can_host_engine = false` / `isolated_engine_available = false`), were verified reachable only by a
single grid-pin probe, and carried no measured traffic. Node *distinctness* for RQ1/RQ2 is therefore
container-level
(≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the (≥ 3 distinct containers per circuit), not physical-machine-level; matched-N is pinned from the
containerised node count per manifest. This satisfies the containment law (every forwarder runs containerised node count per manifest. This satisfies the containment law (every forwarder runs
in an isolated engine, `engine ≠ local`) but means cross-machine timing effects are **out of in an isolated engine, `engine ≠ local`) but means cross-machine timing effects are **out of
@@ -487,7 +499,10 @@ estimate, CI gate, or decision is substituted. The frozen prereg SHA is unchange
- **[Mittal2012b]** Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. *NDSS 2012*. - **[Mittal2012b]** Mittal, P., Caesar, M., & Borisov, N. (2012). X-Vine. *NDSS 2012*.
arXiv:1109.0971. arXiv:1109.0971.
- **[Zhou2011]** Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794. - **[Zhou2011]** Zhou, P., et al. (2011/2013). STor. arXiv:1110.5794.
- **[VanClief2026]** Van Clief, J., & McDermott, D. (2026). Interpretable Context Methodology:
Folder Structure as Agentic Architecture. arXiv:2603.16021. *(Methodology framework under which
this study was staged, pre-registered, and executed.)*
*(Full bibliography: `~/coding/sci-method/stages/01-literature/output/sor-consent-bibliography.md`. *(Full bibliography: `docs/sor-consent-bibliography.md` (vendored in-repo).
Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent Integrity flags carried forward: [Stutzbach2006] secondary-sourced; [Constantinides2026] recent
preprint — neither is load-bearing in this lead paper.)* preprint — neither is load-bearing in this lead paper.)*
@@ -0,0 +1,51 @@
{
"assessment": "GO on isolated docker host",
"containment": {
"external_target": "none",
"hops_run_in": "isolated docker containers only (never a phone/host forwarder)",
"live_vm_churn_on_rq1_rq2": "none (RQ1/RQ2 use no churn; churn_schedule_id=none)",
"self_traffic_only": true
},
"degraded": false,
"devices": [
{
"arch": "x86_64",
"can_host_engine": true,
"engine_version": "27.5.1",
"house_role": "house-A docker host + hop pool",
"isolated_engine_available": true,
"kind": "laptop",
"name": "laptop",
"ssh_reachable": true
},
{
"arch": "aarch64",
"can_host_engine": false,
"engine_version": null,
"house_role": "house-B consenting node (phone)",
"isolated_engine_available": false,
"kind": "phone",
"name": "fp6",
"ssh_reachable": true
},
{
"arch": "aarch64",
"can_host_engine": false,
"engine_version": null,
"house_role": "house-C consenting node (Termux, no docker)",
"isolated_engine_available": false,
"kind": "phone",
"name": "tril",
"ssh_reachable": true
}
],
"devices_down": [],
"generated_utc": "2026-07-20T06:01:52Z",
"isolated_engine_host_count": 1,
"local_docker_version": "27.5.1",
"matched_N_note": "RQ1/RQ2 isolated hops are containerised on the docker host (>=3 distinct containers = distinct nodes). Physical-phone distribution is optional; the confirmatory matched-N (single-house N = federated total consenting nodes) is pinned from the containerised node count at run time and recorded per manifest.",
"reachable_count": 3,
"schema": "sor-device-map/1",
"scope": "RQ1+RQ2 lead-paper grid pin (CLAUDE.md \u00a7Containment)",
"topology_matchedN_honourable": true
}