{
  "title": "Livox SDK2 v1.3.1 Evidence: 221 Files, 6 Sample Targets, Zero Test Paths",
  "rciNumber": "RCI 035",
  "version": "0.1.0",
  "schemaVersion": 1,
  "released": "2026-08-10",
  "canonical": "https://robotcomponentindex.com/research/livox-sdk2-1-3-1-release-evidence-audit/",
  "scope": "Release-identity, source-distribution, Mid-360S support-surface, sample, test, firmware and rights audit of Livox SDK2 v1.3.1. RCI resolved the official GitHub release, lightweight tag, target commit and complete recursive tree; downloaded both GitHub-generated source archives; matched every extracted file to its fixed Git blob; inspected version, API, CMake, README, changelog, sample configuration and license files; checked the linked Livox protocol and Mid-360S product pages; and separated source-level support statements from missing release execution, exact firmware/hardware matrices, timing results, sensor benchmarks and robot integration evidence. RCI did not compile or execute Livox SDK2, download firmware, connect a LiDAR or run a robot workload.",
  "sources": {
    "releaseUrl": "https://github.com/Livox-SDK/Livox-SDK2/releases/tag/v1.3.1",
    "releaseApiUrl": "https://api.github.com/repos/Livox-SDK/Livox-SDK2/releases/tags/v1.3.1",
    "repositoryUrl": "https://github.com/Livox-SDK/Livox-SDK2",
    "readmeUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/README.md",
    "changelogUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/CHANGELOG.md",
    "apiHeaderUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/include/livox_lidar_api.h",
    "definitionHeaderUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/include/livox_lidar_def.h",
    "coreCmakeUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/sdk_core/CMakeLists.txt",
    "samplesCmakeUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/samples/CMakeLists.txt",
    "licenseUrl": "https://github.com/Livox-SDK/Livox-SDK2/blob/v1.3.1/LICENSE.txt",
    "mid360sProductUrl": "https://www.livoxtech.com/mid-360s/specs",
    "mid360ProtocolUrl": "https://livox-wiki-en.readthedocs.io/en/latest/tutorials/new_product/mid360/mid360.html",
    "tag": "v1.3.1",
    "tagType": "lightweight",
    "commitSha": "f5d9375f84efe2b15bc0a052d3e18482ed13adf4",
    "treeSha": "7daae4c235a14deae58d724141397da82097303e",
    "releaseCreatedAt": "2026-04-15T02:50:19Z",
    "publishedAt": "2026-04-15T03:02:57Z",
    "licenseName": "MIT License with bundled dependency notices",
    "verifiedDate": "2026-08-10"
  },
  "independentAudit": {
    "method": "RCI used the official GitHub release, ref, commit, recursive-tree, check-runs and combined-status APIs; fixed version, API, CMake, README, changelog, sample configuration and license files; and official Livox protocol and product pages. RCI downloaded GitHub's generated tar.gz and ZIP, computed audit-date SHA-256 identifiers, safely extracted both, compared normalized path and byte sets, and recomputed the Git blob SHA-1 for every extracted file against the fixed recursive tree. RCI mechanically counted version headings, changelog bullets, sample targets, JSON configurations, explicit test/benchmark/result paths, CI workflows, binary or firmware payloads and public GitHub checks. It did not compile source, execute samples, download firmware, connect a LiDAR or infer private validation from public code.",
    "githubReleaseAssetCount": 0,
    "githubGeneratedArchiveCount": 2,
    "githubGeneratedArchiveEntryCountEach": 258,
    "githubGeneratedArchiveFileCountEach": 221,
    "githubGeneratedArchiveDirectoryCountEach": 37,
    "githubGeneratedArchiveExpandedFileBytesEach": 1813622,
    "githubGeneratedArchivePathSetsIdentical": true,
    "githubGeneratedArchiveFileBytesIdentical": true,
    "tarArchiveGitBlobMatchCount": 221,
    "zipArchiveGitBlobMatchCount": 221,
    "sourceTreeEntryCount": 258,
    "sourceTreeBlobCount": 221,
    "sourceTreeDirectoryCount": 37,
    "sourceTreeDeclaredBlobBytes": 1813622,
    "sourceTreeTruncated": false,
    "annotatedTag": false,
    "targetCommitSignatureVerifiedByGitHub": false,
    "apiHeaderVersion": "1.3.1",
    "coreCmakeVersionString": "0.0.2",
    "coreCmakeVersionAppliedToTarget": false,
    "changelogVersionHeadingCount": 10,
    "changelogTopLevelBulletCount": 17,
    "currentReleaseChangelogBulletCount": 2,
    "sampleTargetCount": 6,
    "sampleTreeFileCount": 40,
    "sampleJsonConfigCount": 24,
    "mid360sSampleConfigCount": 6,
    "readmeNamedSampleCount": 3,
    "explicitTestPathCount": 0,
    "explicitBenchmarkPathCount": 0,
    "publishedResultPathCount": 0,
    "ciWorkflowPathCount": 0,
    "publicCheckRunCount": 0,
    "publicCommitStatusContextCount": 0,
    "binaryOrFirmwarePayloadPathCount": 0,
    "firmwareNamedSourceFileCount": 2,
    "protocolAndProductLinkHttp200Count": 5,
    "softwareBuiltOrExecutedByRci": false,
    "physicalLidarTestPerformedByRci": false,
    "robotSystemTestPerformedByRci": false,
    "upstreamArtifactsRedistributedByRci": false
  },
  "distributionSurfaces": [
    {
      "name": "GitHub-generated source tar.gz for v1.3.1",
      "role": "generated repository snapshot",
      "bytes": 341259,
      "archiveEntryCount": 258,
      "fileCount": 221,
      "publisherSha256Available": false,
      "rciSha256": "dfd720eb586b1dbc88f8dedf51c03f6a605090501ba43ef9914669a920dfa379",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; all 221 files matched the fixed tree's declared size and Git blob identity. The SHA-256 identifies bytes retrieved by RCI on the audit date, not a publisher-supplied digest."
    },
    {
      "name": "GitHub-generated source ZIP for v1.3.1",
      "role": "generated repository snapshot",
      "bytes": 524254,
      "archiveEntryCount": 258,
      "fileCount": 221,
      "publisherSha256Available": false,
      "rciSha256": "faf85c99e52e53480c5eac42158396b957bcb37ad90f032e999c029e74517149",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; its 221 files, 37 directories and expanded bytes match the tar.gz and fixed tree. Source integrity does not establish a successful build or sensor behavior."
    },
    {
      "name": "Fixed v1.3.1 repository source",
      "role": "versioned source, API, examples and rights surface",
      "bytes": 1813622,
      "archiveEntryCount": 258,
      "fileCount": 221,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "The recursive tree is complete and the public API header declares 1.3.1. Source-level support and sample code are inspectable, but the tree contains no explicit test suite, result bundle, CI workflow or firmware payload."
    },
    {
      "name": "Livox protocol and Mid-360S product pages",
      "role": "living device and communication documentation",
      "bytes": null,
      "archiveEntryCount": null,
      "fileCount": null,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "Five links referenced or used by RCI returned HTTP 200 on the audit date. RCI inspected selected pages without mirroring them; living documentation and product specifications remain separate from the fixed SDK release and can change."
    }
  ],
  "releasePageClaims": [
    {
      "claim": "Support Mid-360S LiDAR",
      "evidenceRole": "issuer device-support statement",
      "rciBoundary": "The fixed tree adds a device type, handler, ports and six sample configurations. It does not publish an exact hardware-revision and firmware matrix or a device-run result."
    },
    {
      "claim": "Set Mid-360S ESC mode",
      "evidenceRole": "issuer API-feature statement",
      "rciBoundary": "The public header and implementation expose an ESC-mode API and two enum values; no command trace, timing, physical behavior or pass/fail result accompanies the release."
    },
    {
      "claim": "Set Mid-360S PPS synchronization mode",
      "evidenceRole": "issuer API-feature statement",
      "rciBoundary": "The public header and implementation expose a PPS-mode API and two enum values; no time-error distribution, reference clock, holdover test or multi-device synchronization result is published."
    },
    {
      "claim": "Update README communication-protocol links for Mid-360(S)",
      "evidenceRole": "issuer documentation-change statement",
      "rciBoundary": "The Chinese and English Mid-360(S) links resolved on the audit date. Living protocol pages are not frozen by the SDK tag."
    },
    {
      "claim": "Linux Ubuntu 18.04+ and Windows 10/11, C++11, CMake 3.0+, x86 and ARM prerequisites",
      "evidenceRole": "issuer build-support statement",
      "rciBoundary": "The README provides requirements and example commands but no compiler/OS matrix, build logs or release pass table. RCI did not build the source."
    },
    {
      "claim": "Livox SDK2 includes three named samples",
      "evidenceRole": "issuer README inventory statement",
      "rciBoundary": "The same fixed tree's samples/CMakeLists.txt adds six sample subdirectories. RCI preserves the concurrent documentation difference and does not silently select one count."
    }
  ],
  "observations": [
    {
      "id": "RCI035-O01",
      "field": "release_identity",
      "value": "Livox SDK2 v1.3.1",
      "unit": null,
      "sourceLocation": "GitHub release and fixed repository",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Identifies an SDK release, not a LiDAR firmware release, ROS-driver release, sensor calibration or robot integration."
    },
    {
      "id": "RCI035-O02",
      "field": "release_state_and_dates",
      "value": "non-draft; non-prerelease; immutable=false; created 2026-04-15T02:50:19Z; published 2026-04-15T03:02:57Z",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "GitHub state and dates do not establish support duration, production readiness or field validation."
    },
    {
      "id": "RCI035-O03",
      "field": "tag_and_commit_identity",
      "value": "lightweight tag v1.3.1 → commit f5d9375f84ef; commit reported unsigned by GitHub",
      "unit": null,
      "sourceLocation": "GitHub ref and commit APIs",
      "evidenceRole": "RCI-resolved version identity",
      "rciBoundary": "A lightweight tag has no separate tag-object signature; unsigned commit status remains separate from archive integrity and software correctness."
    },
    {
      "id": "RCI035-O04",
      "field": "version_surfaces",
      "value": "API header 1.3.1; sdk_core CMake variables 0.0.2; CMake variables not applied to target properties",
      "unit": null,
      "sourceLocation": "include/livox_lidar_def.h and sdk_core/CMakeLists.txt at v1.3.1",
      "evidenceRole": "RCI cross-file version check",
      "rciBoundary": "RCI does not infer that 0.0.2 is the public SDK release version; the relationship is undocumented and remains a fact-check question."
    },
    {
      "id": "RCI035-O05",
      "field": "github_release_assets",
      "value": "0 separately uploaded assets; 2 GitHub-generated source downloads",
      "unit": null,
      "sourceLocation": "GitHub release API and UI",
      "evidenceRole": "issuer distribution metadata",
      "rciBoundary": "The two UI downloads are generated repository snapshots, not publisher-uploaded binaries, firmware, test logs or sensor data."
    },
    {
      "id": "RCI035-O06",
      "field": "generated_archive_integrity",
      "value": "tar.gz 341,259 bytes; ZIP 524,254 bytes; 258 normalized entries, 221 files and 37 directories each; path and expanded-byte sets identical",
      "unit": null,
      "sourceLocation": "RCI downloads, SHA-256, safe extraction and archive comparison",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "GitHub publishes no digest for either generated archive; RCI hashes identify audit-date bytes and do not verify a build or runtime."
    },
    {
      "id": "RCI035-O07",
      "field": "fixed_tree_blob_verification",
      "value": "221/221 files in each archive matched fixed-tree size and recomputed Git blob SHA-1; tree 7daae4c235a1 not truncated",
      "unit": "files",
      "sourceLocation": "GitHub recursive tree API and RCI Git-blob recomputation",
      "evidenceRole": "RCI-derived fixed-source integrity result",
      "rciBoundary": "Byte identity with source control does not show successful compilation, dependency availability or device execution."
    },
    {
      "id": "RCI035-O08",
      "field": "release_note_scope",
      "value": "2 Added bullets: Mid-360S ESC mode and PPS sync mode support; README/protocol-link update",
      "unit": "release bullets",
      "sourceLocation": "GitHub v1.3.1 release body",
      "evidenceRole": "issuer feature and documentation statements",
      "rciBoundary": "The release body contains no test protocol, exact firmware floor, hardware revision, command output or numerical result."
    },
    {
      "id": "RCI035-O09",
      "field": "changelog_structure",
      "value": "10 bracketed version headings and 17 top-level bullets; v1.3.1 has 2 bullets",
      "unit": "top-level bullets",
      "sourceLocation": "CHANGELOG.md at v1.3.1",
      "evidenceRole": "RCI mechanical count of issuer statements",
      "rciBoundary": "Changelog bullets are not tests collected, passed checks, affected devices or independent measurements."
    },
    {
      "id": "RCI035-O10",
      "field": "named_device_scope",
      "value": "README protocol scope names Mid-360(S) and HAP(TX/T1); source enum also contains legacy/family device types",
      "unit": null,
      "sourceLocation": "README.md and include/livox_lidar_def.h at v1.3.1",
      "evidenceRole": "issuer documentation and source inventory",
      "rciBoundary": "A device enum or protocol link is not an exact supported firmware, hardware revision or operating-system validation matrix."
    },
    {
      "id": "RCI035-O11",
      "field": "mid360s_command_surface",
      "value": "device type 35; SetLivoxLidarPpsSyncMode and SetLivoxLidarEscMode declarations and implementations; two values in each mode enum",
      "unit": null,
      "sourceLocation": "Fixed API/definition headers and sdk_core implementation",
      "evidenceRole": "RCI source-level feature check",
      "rciBoundary": "Code presence does not prove the commands succeed on every Mid-360S revision or firmware."
    },
    {
      "id": "RCI035-O12",
      "field": "mid360s_network_configuration",
      "value": "device ports 56100–56500; host ports 56101–56501; debug point-cloud port 60301",
      "unit": "UDP port identifiers",
      "sourceLocation": "sdk_core/comm/define.h and six fixed sample configurations",
      "evidenceRole": "issuer source/configuration statement",
      "rciBoundary": "Port constants are integration inputs, not evidence of packet delivery, latency, loss, synchronization or multi-LiDAR stability."
    },
    {
      "id": "RCI035-O13",
      "field": "sample_source_inventory",
      "value": "6 CMake sample targets; 40 files under samples/; 24 JSON configurations; all 6 targets include mid360s_config.json",
      "unit": null,
      "sourceLocation": "Fixed samples tree and samples/CMakeLists.txt",
      "evidenceRole": "RCI-derived source inventory",
      "rciBoundary": "Examples and configuration templates are not executed integration tests or supported-host results."
    },
    {
      "id": "RCI035-O14",
      "field": "readme_sample_inventory_difference",
      "value": "README says 3 named samples; fixed CMake source adds 6 sample subdirectories",
      "unit": "sample targets",
      "sourceLocation": "README.md and samples/CMakeLists.txt at the same commit",
      "evidenceRole": "RCI concurrent fixed-file difference",
      "rciBoundary": "The difference may be documentation lag or a narrower tutorial definition; RCI does not silently rewrite either surface."
    },
    {
      "id": "RCI035-O15",
      "field": "published_build_prerequisites",
      "value": "Ubuntu 18.04+; Windows 10/11; C++11 compiler; CMake 3.0+; x86 and ARM; Ubuntu example names gcc 4.8.1+; Windows example names Visual Studio 2019",
      "unit": null,
      "sourceLocation": "README.md at v1.3.1",
      "evidenceRole": "issuer build-support statement",
      "rciBoundary": "No complete OS/compiler/architecture matrix or frozen dependency lock and no release build log are published."
    },
    {
      "id": "RCI035-O16",
      "field": "public_test_and_result_tree",
      "value": "0 explicit test paths; 0 benchmark paths; 0 coverage/JUnit/result paths",
      "unit": "fixed-tree paths",
      "sourceLocation": "RCI explicit recursive-tree pattern audit",
      "evidenceRole": "RCI public-source disclosure result",
      "rciBoundary": "RCI does not infer that Livox ran no private or external tests; it records that no explicit suite or result bundle is present in the audited public tree."
    },
    {
      "id": "RCI035-O17",
      "field": "public_github_automation",
      "value": "0 .github/workflows paths; 0 check runs; 0 commit status contexts",
      "unit": "public GitHub records",
      "sourceLocation": "Fixed tree, GitHub check-runs API and combined-status API",
      "evidenceRole": "public repository automation metadata",
      "rciBoundary": "Zero public records do not prove that no private, vendor or external validation occurred."
    },
    {
      "id": "RCI035-O18",
      "field": "firmware_distribution_boundary",
      "value": "0 binary/firmware payload paths; 2 firmware-named C++ source files; upgrade sample requires a separately supplied firmware file path",
      "unit": null,
      "sourceLocation": "Fixed recursive tree and README upgrade instructions",
      "evidenceRole": "RCI distribution-boundary result",
      "rciBoundary": "SDK v1.3.1 does not itself identify or distribute the exact firmware bytes required for each supported LiDAR."
    },
    {
      "id": "RCI035-O19",
      "field": "license_inventory",
      "value": "root MIT terms plus embedded RapidJSON, spdlog and FastCRC notices; separate bundled license files present",
      "unit": null,
      "sourceLocation": "LICENSE.txt and 3rdparty license files at v1.3.1",
      "evidenceRole": "fixed-file rights statement",
      "rciBoundary": "The root illustrative tree says sample/one quick-start example while the fixed repository uses samples/six targets; exact file-level scope and marks remain item-specific."
    },
    {
      "id": "RCI035-O20",
      "field": "physical_and_robot_validation",
      "value": "RCI built 0 binaries, ran 0 samples, connected 0 LiDARs and executed 0 robot workloads",
      "unit": null,
      "sourceLocation": "RCI audit execution boundary",
      "evidenceRole": "independent-method limitation",
      "rciBoundary": "No claim about range, precision, point rate, latency, packet loss, PPS accuracy, thermal behavior, power, mapping quality or robot integration is independently verified by this audit."
    }
  ],
  "disclosureAudit": [
    {
      "id": "RCI035-D01",
      "field": "release_identity_and_date",
      "status": "disclosed",
      "publicEvidence": "GitHub identifies v1.3.1, release state and timestamps.",
      "reproductionImpact": "A reader can cite a specific public release rather than a moving branch."
    },
    {
      "id": "RCI035-D02",
      "field": "tag_object_and_signature",
      "status": "disclosed-lightweight-unsigned",
      "publicEvidence": "The tag ref resolves directly to an unsigned commit; no annotated tag object exists.",
      "reproductionImpact": "The commit is fixed, while provenance does not include a verified tag or commit signature."
    },
    {
      "id": "RCI035-D03",
      "field": "recursive_tree_identity",
      "status": "disclosed-and-not-truncated",
      "publicEvidence": "GitHub returns tree 7daae4c235a1 with 258 entries and truncated=false.",
      "reproductionImpact": "The audited public source boundary can be enumerated completely."
    },
    {
      "id": "RCI035-D04",
      "field": "publisher_archive_digests",
      "status": "not-published",
      "publicEvidence": "The release has zero uploaded assets and GitHub supplies no publisher digest for generated source downloads.",
      "reproductionImpact": "RCI hashes identify audit-date downloads rather than matching an issuer checksum."
    },
    {
      "id": "RCI035-D05",
      "field": "archive_to_fixed_tree_bytes",
      "status": "disclosed-and-matched",
      "publicEvidence": "RCI matched 221/221 extracted files in each archive to fixed-tree byte sizes and recomputed Git blob identities.",
      "reproductionImpact": "The two downloaded snapshots are byte-consistent with the selected commit."
    },
    {
      "id": "RCI035-D06",
      "field": "public_api_version",
      "status": "disclosed",
      "publicEvidence": "include/livox_lidar_def.h defines 1, 3 and 1 version components.",
      "reproductionImpact": "The API-reported version agrees with the release tag."
    },
    {
      "id": "RCI035-D07",
      "field": "cmake_version_relationship",
      "status": "unresolved-concurrent-value",
      "publicEvidence": "sdk_core/CMakeLists.txt defines 0.0.2 variables that are not applied to a target; no fixed explanation relates them to API version 1.3.1.",
      "reproductionImpact": "Packagers should not infer binary ABI or SONAME version semantics without maintainer clarification."
    },
    {
      "id": "RCI035-D08",
      "field": "publisher_binaries_or_install_packages",
      "status": "not-published",
      "publicEvidence": "The release has no uploaded asset; the public tree contains no .so, .dll, .a, .lib, .exe, .deb or .rpm payload.",
      "reproductionImpact": "Users must build source and cannot match a publisher binary digest from this release."
    },
    {
      "id": "RCI035-D09",
      "field": "mid360s_source_support",
      "status": "disclosed",
      "publicEvidence": "Device type, handler, configuration parser, ports, API calls and six sample configurations are fixed in source.",
      "reproductionImpact": "The implementation surface is inspectable, but execution remains unverified."
    },
    {
      "id": "RCI035-D10",
      "field": "minimum_device_firmware",
      "status": "not-published",
      "publicEvidence": "Neither the release body nor fixed README supplies exact Mid-360S firmware bytes, version floor or digest for ESC/PPS support.",
      "reproductionImpact": "An exact software–firmware pair cannot be reconstructed from the release alone."
    },
    {
      "id": "RCI035-D11",
      "field": "hardware_revision_matrix",
      "status": "not-published",
      "publicEvidence": "No serial range, board revision or exact product revision matrix accompanies v1.3.1.",
      "reproductionImpact": "Support cannot be generalized to every physical Mid-360S unit."
    },
    {
      "id": "RCI035-D12",
      "field": "host_build_matrix",
      "status": "partially-disclosed",
      "publicEvidence": "README gives broad OS, architecture and tool prerequisites plus one Ubuntu and one Visual Studio example, but no matrix or build logs.",
      "reproductionImpact": "Declared prerequisites guide setup without proving every supported combination."
    },
    {
      "id": "RCI035-D13",
      "field": "sample_inventory",
      "status": "concurrent-fixed-file-difference",
      "publicEvidence": "README names three samples while samples/CMakeLists.txt builds six at the same commit.",
      "reproductionImpact": "Documentation coverage and the full example surface should be clarified before making completeness claims."
    },
    {
      "id": "RCI035-D14",
      "field": "public_test_suite",
      "status": "not-published",
      "publicEvidence": "The complete public tree contains zero explicit test or benchmark paths.",
      "reproductionImpact": "There is no fixed public suite from which to reproduce release validation."
    },
    {
      "id": "RCI035-D15",
      "field": "release_test_commands_and_results",
      "status": "not-published",
      "publicEvidence": "No release test manifest, command list, pass/fail table, coverage output, JUnit record or execution log is included.",
      "reproductionImpact": "Source availability cannot be converted into a passed-release claim."
    },
    {
      "id": "RCI035-D16",
      "field": "public_ci_at_tag_commit",
      "status": "not-published",
      "publicEvidence": "The tree has no workflow path and GitHub exposes zero checks and zero status contexts at the tagged commit.",
      "reproductionImpact": "Public GitHub metadata supplies no independent build or test outcome."
    },
    {
      "id": "RCI035-D17",
      "field": "sensor_performance_protocol_and_results",
      "status": "not-published-in-release",
      "publicEvidence": "The SDK release contains no fixed range, precision, point-rate, latency, packet-loss, thermal or power test protocol and result bundle.",
      "reproductionImpact": "Product-page specifications remain issuer claims outside this software-release audit."
    },
    {
      "id": "RCI035-D18",
      "field": "pps_and_esc_physical_results",
      "status": "not-published",
      "publicEvidence": "API declarations and implementation paths exist, but no clock identity, trace, timing error, mode-transition measurement or physical device log accompanies them.",
      "reproductionImpact": "PPS and ESC functionality cannot be quantified or independently reproduced from the release package."
    },
    {
      "id": "RCI035-D19",
      "field": "file_level_rights_inventory",
      "status": "partially-disclosed",
      "publicEvidence": "Root and bundled dependency license texts are present, but the root illustrative scope tree is stale relative to current samples and does not map every file individually.",
      "reproductionImpact": "MIT coverage is strong for named portions, while exact file scope, marks and living external documents remain item-specific."
    },
    {
      "id": "RCI035-D20",
      "field": "independent_lidar_or_robot_reproduction",
      "status": "not-performed",
      "publicEvidence": "RCI audited metadata, archives, source structure, links and rights only; it built no binary and accessed no LiDAR or robot hardware.",
      "reproductionImpact": "All device, timing, performance, stability and robot-integration conclusions remain outside independent RCI verification."
    }
  ],
  "limitations": [
    "RCI downloaded only the two GitHub-generated source archives; GitHub publishes no digest for either, so their SHA-256 values are audit-date identifiers rather than publisher matches.",
    "RCI recomputed and matched every extracted Git blob, but source-control integrity does not prove compilation, runtime correctness, device support or safety.",
    "RCI did not compile Livox SDK2 on Ubuntu or Windows, install dependencies, execute any of the six samples or inspect private/external CI.",
    "The fixed public tree contains no explicit test suite, benchmark path or structured result bundle; RCI does not infer that Livox performed no private validation.",
    "RCI did not download any LiDAR firmware; v1.3.1 does not publish an exact Mid-360S firmware version/digest or hardware revision matrix for ESC/PPS support.",
    "RCI did not connect a Mid-360S, Mid-360, HAP, clock source, Ethernet host, robot computer or robot platform.",
    "The README's three-sample statement and the fixed CMake six-target inventory are preserved as a concurrent documentation difference, not silently resolved.",
    "The API header's 1.3.1 and unused sdk_core CMake 0.0.2 variables have different apparent roles; the fixed project does not explain that relationship.",
    "Living Livox protocol and product pages returned HTTP 200 on the audit date but can change independently of the fixed SDK tag.",
    "Root and third-party license texts are public; RCI does not relicense upstream code, external documentation, product specifications or Livox marks."
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "Livox SDK2 v1.3.1 is a fixed non-prerelease GitHub release whose lightweight tag resolves to an unsigned commit and complete 221-file public tree. Both generated archives matched every fixed Git blob, the API header declares 1.3.1, and the source adds explicit Mid-360S handling, six sample configurations, ESC mode and PPS synchronization calls. The same release publishes no uploaded binary or firmware asset, explicit test suite, CI workflow, public GitHub check, exact firmware/hardware matrix, execution log or device-result bundle. These surfaces support a source-level release-evidence claim, not a LiDAR performance, timing, stability, compatibility or robot-integration validation claim.",
    "distributionClaim": "The tar.gz and ZIP each expose 258 normalized entries, 221 files, 37 directories and 1,813,622 expanded file bytes. RCI matched all 221 files in each archive to the fixed tree's byte size and Git blob identity. Their SHA-256 values identify audit-date downloads; neither is a publisher-uploaded artifact or digest match.",
    "changeClaim": "The v1.3.1 release body and changelog contain two current bullets for Mid-360S ESC/PPS support, while the fixed changelog contains 17 top-level bullets across ten version headings. These are issuer change statements, not executed tests or device results.",
    "sampleAndTestClaim": "The fixed CMake source builds six sample targets with 40 sample-tree files and 24 JSON configurations, including six Mid360s configs. README names only three samples. The complete tree has zero explicit test/benchmark/result paths and zero public CI workflows, checks or status contexts; examples remain separate from release validation.",
    "firmwareAndHardwareClaim": "v1.3.1 exposes source support and an upgrade sample but no firmware payload, exact firmware floor/digest, serial or hardware-revision matrix. A device-support statement therefore cannot be rewritten as every-unit compatibility or a successful physical test.",
    "rightsClaim": "The fixed repository includes Livox MIT terms and embedded RapidJSON, spdlog and FastCRC notices. The root illustrative file tree is stale relative to the six current sample targets, and external protocol/product pages and trademarks remain item-specific; RCI republishes only original facts, hashes and analysis."
  },
  "suggestedCitation": "Robot Component Index. “Livox SDK2 v1.3.1 Evidence: 221 Files, 6 Sample Targets, Zero Test Paths.” RCI 035, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/livox-sdk2-1-3-1-release-evidence-audit/"
}