Skip to the content.

Public evidence and provenance

Home · Findings · Methods

This directory contains derived, publication-safe evidence only. The measurement file records build identity, counts, selected hashes and bounded validation results from the existing audit. Publication provenance records SHA-256 values of the retained source documents used to construct this repository. The finding ledger holds observations and scoped limits; the source crosswalk maps all 100 IDs to a retained document and source line, distinguishing explicit ID mentions from earlier section context. The EFI converter branch register and firmware-helper census are related derived datasets, not whole-object evidence. The external-link check records HTTP results for reference URLs. The checksums.sha256 file hashes the public data and diagrams.

Evidence class Public representation Original retained privately
Original versus copy Counts and comparison conclusion Full path inventory, hashes, original metadata, exceptions
Exact Apple reference Matched counts and source-document hashes Acquired package, distribution records, archive member records and extraction logs
Disk images and firmware Sizes, digests, format/signature conclusions Apple binaries, reconstructed images, firmware payloads, full parser output
Reverse engineering Bounded addresses, branch tables, call relationships and limitations Original-byte checks, decoded instructions, symbol/fixup dumps and intermediate analysis
Services and transport Configuration/path findings and negative limits Full launch inventories, protected files, logs and host metadata
Coverage Counts, status and exact next step 147,253-row path register, private validation/manifests and unresolved queue

Public files do not contain Apple binaries, raw disassembly dumps, secrets, credentials, personal identifiers, machine serials, local usernames, raw NVRAM values, private certificates/keys, or runtime traffic. Static certificate/public-key fingerprints and artifact hashes appear where they support a concrete comparison; they are not host secrets. A private evidence file name in a research page is a provenance pointer for the original audit, not a broken promised download.

The manifest here verifies this public draft’s files, not the Apple originals, historical custody, or a future GitHub release. The retained source-document digests allow a holder of the private audit workspace to verify which report versions informed this draft; readers without those documents cannot independently reproduce the crosswalk. Use the reproduction guide and limitations before treating a result as independently repeatable. No original material was changed to create this repository.