{
  "schemaVersion": 1,
  "rciNumber": "RCI 039",
  "version": "0.1.0",
  "released": "2026-08-11",
  "title": "Orbbec SDK 2.9.3 Evidence: 12 Hash Matches, 0 Public Checks, One Unresolved License Boundary",
  "canonical": "https://robotcomponentindex.com/research/orbbec-sdk-2-9-3-release-evidence-audit/",
  "candidateId": "174264acba768fc5",
  "scope": "Independent release-integrity, provenance, rights-boundary and disclosure audit of the official Orbbec SDK v2.9.3 release. This is not a depth-quality, timing, compatibility, firmware, model or robot-system benchmark.",
  "sources": {
    "releaseUrl": "https://github.com/orbbec/OrbbecSDK_v2/releases/tag/v2.9.3",
    "releaseApiUrl": "https://api.github.com/repos/orbbec/OrbbecSDK_v2/releases/tags/v2.9.3",
    "tag": "v2.9.3",
    "tagType": "annotated",
    "tagSha": "ca69b53b11eda5c65909da7e016d07fc7537d6a9",
    "commitSha": "2f6561c28255d805b34aa00a690199ce40e96c81",
    "treeSha": "85c4ac366a36567cf697a8fb5fd3e35b6f6a70c4",
    "licenseUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/LICENSE.txt",
    "extensionLicenseUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/extensions/license.txt",
    "extensionReadmeUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/extensions/README.md",
    "eulaUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/End%20User%20License%20Agreement.txt",
    "enhancedFilterReadmeUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/examples/3.advanced.enhanced_depth_filter/README.md",
    "rootReadmeUrl": "https://github.com/orbbec/OrbbecSDK_v2/blob/v2.9.3/README.md",
    "atomUrl": "https://github.com/orbbec/OrbbecSDK_v2/releases.atom"
  },
  "independentAudit": {
    "method": "RCI queried the official GitHub release, Git tag, commit, tree, checks, workflows and status APIs; downloaded twelve uploaded assets and both generated source archives; recomputed byte sizes and SHA-256 digests; compared normalized archive paths and file bytes with a fixed tagged checkout; inspected fixed license, EULA, extension, example, test and benchmark surfaces; and did not execute, install or redistribute upstream artifacts.",
    "releaseCreatedAt": "2026-07-15T15:55:49Z",
    "releasePublishedAt": "2026-07-16T15:48:20Z",
    "releaseUpdatedAt": "2026-08-05T11:58:24Z",
    "atomEntryUpdatedAt": "2026-08-05T11:58:24Z",
    "githubDisplayedAssetCountIncludingGeneratedArchives": 14,
    "githubUploadedAssetCount": 12,
    "githubUploadedAssetTotalBytes": 649731276,
    "rciDownloadedUploadedAssetCount": 12,
    "publisherDigestMatchCount": 12,
    "publisherSizeMatchCount": 12,
    "modelAssetCount": 1,
    "modelAssetBytes": 252582062,
    "sdkDistributionAssetCount": 7,
    "viewerDistributionAssetCount": 4,
    "githubGeneratedArchiveCount": 2,
    "generatedTarBytes": 25666471,
    "generatedTarSha256": "8e983ba60b3ee9e14b79c6c8365f619470c636c7c79de6c7f72b592c3e48e7bd",
    "generatedZipBytes": 27675202,
    "generatedZipSha256": "84914d9626d86501928f9af049ac7c51d6976d0415b6d0f5effa34a22ec99892",
    "generatedArchivePathCountEach": 2995,
    "generatedArchiveRegularFileCountEach": 2993,
    "generatedArchiveSymlinkCountEach": 2,
    "generatedArchiveDirectoryCountIncludingRootEach": 373,
    "generatedArchivePathSetsIdentical": true,
    "generatedArchiveIncludedBytesIdentical": true,
    "generatedArchiveFixedCheckoutMatchCount": 2995,
    "generatedArchiveExportIgnoredPathCount": 2,
    "sourceTreeEntryCount": 3369,
    "sourceTreeBlobCount": 2997,
    "sourceTreeDirectoryCount": 372,
    "sourceTreeDeclaredBlobBytes": 60077681,
    "sourceTreeTruncated": false,
    "tagSignatureVerifiedByGitHub": false,
    "commitSignatureVerifiedByGitHub": false,
    "declaredProjectVersion": "2.9.3",
    "firstPartyTestFileCount": 13,
    "firstPartyTestSuiteCount": 5,
    "benchmarkSurfaceFileCount": 17,
    "publicCheckRunCount": 0,
    "publicWorkflowRunCountAtCommit": 0,
    "legacyCommitStatusCount": 0,
    "extensionFileCount": 37,
    "extensionFileBytes": 13187269,
    "releaseSupportedDeviceRowCount": 19,
    "releaseSupportedPlatformFamilyCount": 4,
    "assetExecutedByRci": false,
    "modelInspectedOrExecutedByRci": false,
    "softwareBuiltOrInstalledByRci": false,
    "firmwareDownloadedOrUpdatedByRci": false,
    "physicalCameraTestPerformedByRci": false,
    "physicalLidarTestPerformedByRci": false,
    "robotSystemTestPerformedByRci": false
  },
  "releaseAssets": [
    {
      "name": "model.sm4",
      "role": "proprietary-or-undeclared-model-asset",
      "bytes": 252582062,
      "publisherSha256": "83c9143b494f6eb781e38efebd40af851d154ea002884b159a7edeece448cd23",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_202607151523_2f6561c_linux_arm64.tar.gz",
      "role": "sdk-distribution",
      "bytes": 10905176,
      "publisherSha256": "ce2c476c283b932181b04daf44debadff9e4a743344bd69eecf34f8c18009ac1",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_202607151523_2f6561c_linux_x86_64.tar.gz",
      "role": "sdk-distribution",
      "bytes": 9885452,
      "publisherSha256": "8516081b2201f841b1aa444dd203975e06891d73a2694dd2b3d864254f89ff0d",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_202607152322_2f6561c_win_x64.zip",
      "role": "sdk-distribution",
      "bytes": 61142460,
      "publisherSha256": "300c1961da269a58ead4351e66ae9071b65beac25d665a4bcfa59200f6b3e830",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_202607152323_2f6561c_macOS.tar.gz",
      "role": "sdk-distribution",
      "bytes": 12120512,
      "publisherSha256": "12b33a1bf07c6e38122a8fcee6d16360d8ef305af55d2eebeaf2304202b3f385",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_amd64.deb",
      "role": "sdk-distribution",
      "bytes": 39923970,
      "publisherSha256": "1c3c56bceafe6f0f562b09eb400750a911b5d02d529f776e76c29fc36371ae29",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_arm64.deb",
      "role": "sdk-distribution",
      "bytes": 65715970,
      "publisherSha256": "3d238ab1bf76ba768ce859e08991f8cbb40c17ef0895aae6d85e938683aab693",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecSDK_v2.9.3_win64.exe",
      "role": "sdk-distribution",
      "bytes": 36958959,
      "publisherSha256": "ed9d894b841714e60cd415a1ea5944d1d1fc41d2155a955f8c87beee2ca4f874",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecViewer_v2.9.3_202607160623_b7e38ef_linux_arm64.tar.gz",
      "role": "viewer-distribution-separate-build-token",
      "bytes": 56702023,
      "publisherSha256": "a555a0b7cdf694d76eb485a234a95c78f387c5335ae077bb19ea42afb1437fee",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecViewer_v2.9.3_202607160623_b7e38ef_linux_x86_64.tar.gz",
      "role": "viewer-distribution-separate-build-token",
      "bytes": 31732438,
      "publisherSha256": "8b667dd2d6f65bce82d1c273e51e6bdc4e8973b0fc1ba6a8d2ad2e7e61194f17",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecViewer_v2.9.3_202607161422_b7e38ef_win_x64.zip",
      "role": "viewer-distribution-separate-build-token",
      "bytes": 43899166,
      "publisherSha256": "b318be912bb6db821a09103d5874b50ba9fdb8d057123e92f66ccceb3d2a3715",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "OrbbecViewer_v2.9.3_202607161423_b7e38ef_macOS_arm64.tar.gz",
      "role": "viewer-distribution-separate-build-token",
      "bytes": 28163088,
      "publisherSha256": "ca3d8a319ad2a5f269d1960eb68356a8d83650c3bb29550642e59130241d1ec3",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    }
  ],
  "releasePageClaims": [
    {
      "claim": "LingBot Enhanced Depth Filter is available for Gemini 330 series on NVIDIA Jetson/Linux ARM64 and requires device-license activation plus model.sm4.",
      "evidenceRole": "issuer release statement plus fixed example documentation",
      "rciBoundary": "RCI matched the model bytes but did not inspect the model, activate a device license, run inference or measure depth quality."
    },
    {
      "claim": "Timestamp fitting, clock-source selection and DaBai hardware PPS behavior changed.",
      "evidenceRole": "issuer release statement and API surface",
      "rciBoundary": "No clock trace, PPS test protocol, synchronization result file or physical multi-device test was published or run by RCI."
    },
    {
      "claim": "Preset, color-preset, network-state and firmware-log APIs were added or expanded.",
      "evidenceRole": "issuer release statement and fixed source surface",
      "rciBoundary": "API presence is not evidence that every listed device/firmware combination behaves correctly."
    },
    {
      "claim": "The release lists 19 supported-device/firmware rows and four supported platform families.",
      "evidenceRole": "issuer compatibility matrix",
      "rciBoundary": "Rows are manufacturer support statements, not an RCI compatibility test or a blanket statement across every hardware revision."
    },
    {
      "claim": "Twelve uploaded assets expose publisher SHA-256 digests.",
      "evidenceRole": "publisher distribution metadata independently matched by RCI",
      "rciBoundary": "Digest equality proves byte identity at audit time, not security, safety, performance, license clearance or production readiness."
    },
    {
      "claim": "SDK artifact names include short commit 2f6561c while Viewer artifacts use b7e38ef.",
      "evidenceRole": "publisher filenames",
      "rciBoundary": "The release does not link b7e38ef to a fixed public Viewer source repository/commit, so Viewer build provenance remains incomplete."
    },
    {
      "claim": "The repository root says MIT, while extension files have separate restrictions and an EULA.",
      "evidenceRole": "fixed upstream rights documents",
      "rciBoundary": "RCI reports the public wording conflict and does not provide legal advice or infer permission for model, binary, firmware, media or documentation reuse."
    },
    {
      "claim": "The fixed tree contains tests and a benchmark tool but no public GitHub checks at the tagged commit.",
      "evidenceRole": "source-surface and GitHub API observation",
      "rciBoundary": "Test source is not execution evidence; zero public checks does not prove that Orbbec ran no private tests."
    }
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "Orbbec SDK v2.9.3 is a fixed public release with twelve byte-identifiable uploaded assets whose publisher sizes and SHA-256 digests all matched RCI downloads. Its source identity and distribution bytes are auditable; its performance, device behavior, model operation and complete rights boundary are not independently validated.",
    "distributionClaim": "The twelve uploaded assets total 649,731,276 bytes. RCI downloaded and hashed them without executing or redistributing them. GitHub's human page count of fourteen includes two generated source archives, which are not members of the uploaded-asset API array.",
    "provenanceClaim": "The annotated tag resolves to fixed commit 2f6561c and complete tree 85c4ac3, but both tag and commit are unsigned in GitHub's verification fields. SDK artifact filenames repeat 2f6561c; Viewer assets instead repeat b7e38ef without a fixed public source link in this release.",
    "sourceClaim": "Both generated archives expose identical 2,995-path sets and identical included bytes, matching the fixed checkout for every included path. They omit two libusb dotfiles through archive export behavior; this is a bounded archive difference, not a source corruption finding.",
    "ciClaim": "The fixed tree contains thirteen first-party test files across five suites and seventeen benchmark-tool files. GitHub exposes zero check runs, zero workflow runs at the tagged commit and zero legacy statuses. Source presence cannot be rewritten as successful execution, and absence of public checks cannot be rewritten as absence of private testing.",
    "rightsClaim": "The root declares MIT for the repository, while extension binaries are separately restricted by extensions/license.txt and the EULA. extensions/README.md also says the non-open-source extensions are under MIT, creating unresolved upstream wording. model.sm4 has no item-specific license identified by RCI. RCI therefore extracts facts and links upstream but does not republish source, model, binaries, firmware, documentation or release prose.",
    "deviceClaim": "The release's device, firmware and platform tables are issuer support statements with model- and version-specific qualifiers. RCI connected no Orbbec camera or LiDAR, installed no SDK, activated no license and downloaded or updated no firmware."
  },
  "observations": [
    {
      "id": "obs-01",
      "field": "release_tag",
      "value": "v2.9.3",
      "unit": null,
      "sourceLocation": "official GitHub release and tag API",
      "evidenceRole": "publisher identity",
      "rciBoundary": "Fixed identifier only."
    },
    {
      "id": "obs-02",
      "field": "tag_type",
      "value": "annotated",
      "unit": null,
      "sourceLocation": "Git tag object ca69b53b11ed",
      "evidenceRole": "publisher repository metadata",
      "rciBoundary": "Annotated does not mean cryptographically signed."
    },
    {
      "id": "obs-03",
      "field": "tag_signature",
      "value": "unsigned",
      "unit": null,
      "sourceLocation": "GitHub tag verification field",
      "evidenceRole": "public provenance limitation",
      "rciBoundary": "No verified signature is claimed."
    },
    {
      "id": "obs-04",
      "field": "target_commit",
      "value": "2f6561c28255d805b34aa00a690199ce40e96c81",
      "unit": null,
      "sourceLocation": "annotated tag target",
      "evidenceRole": "fixed source identity",
      "rciBoundary": "Commit identity is not runtime behavior."
    },
    {
      "id": "obs-05",
      "field": "commit_signature",
      "value": "unsigned",
      "unit": null,
      "sourceLocation": "GitHub commit verification field",
      "evidenceRole": "public provenance limitation",
      "rciBoundary": "No verified commit signature is claimed."
    },
    {
      "id": "obs-06",
      "field": "release_published_at",
      "value": "2026-07-16T15:48:20Z",
      "unit": null,
      "sourceLocation": "release API published_at",
      "evidenceRole": "publisher timestamp",
      "rciBoundary": "Separate from later editing."
    },
    {
      "id": "obs-07",
      "field": "release_updated_at",
      "value": "2026-08-05T11:58:24Z",
      "unit": null,
      "sourceLocation": "release API updated_at and Atom updated",
      "evidenceRole": "publisher edit timestamp",
      "rciBoundary": "The radar discovered an edited release; this is not a new August publication."
    },
    {
      "id": "obs-08",
      "field": "displayed_asset_count",
      "value": "14",
      "unit": "items",
      "sourceLocation": "human-facing release page",
      "evidenceRole": "publisher interface count",
      "rciBoundary": "Includes two generated source archives."
    },
    {
      "id": "obs-09",
      "field": "uploaded_asset_count",
      "value": "12",
      "unit": "items",
      "sourceLocation": "release API assets array",
      "evidenceRole": "publisher machine manifest",
      "rciBoundary": "Excludes generated archives."
    },
    {
      "id": "obs-10",
      "field": "uploaded_asset_total_bytes",
      "value": "649731276",
      "unit": "bytes",
      "sourceLocation": "sum of publisher size fields matched locally",
      "evidenceRole": "RCI independent distribution check",
      "rciBoundary": "Bytes do not prove function or rights."
    },
    {
      "id": "obs-11",
      "field": "publisher_digest_matches",
      "value": "12",
      "unit": "assets",
      "sourceLocation": "publisher SHA-256 versus RCI SHA-256",
      "evidenceRole": "RCI independent integrity check",
      "rciBoundary": "Matched, not executed."
    },
    {
      "id": "obs-12",
      "field": "model_asset",
      "value": "model.sm4 / 252582062",
      "unit": "bytes",
      "sourceLocation": "release asset API and RCI hash",
      "evidenceRole": "distribution fact",
      "rciBoundary": "No item-specific model license or model inspection is claimed."
    },
    {
      "id": "obs-13",
      "field": "sdk_build_token",
      "value": "2f6561c",
      "unit": null,
      "sourceLocation": "seven SDK artifact filenames",
      "evidenceRole": "publisher filename provenance",
      "rciBoundary": "Token agrees with tag commit but is not a reproducible build attestation."
    },
    {
      "id": "obs-14",
      "field": "viewer_build_token",
      "value": "b7e38ef",
      "unit": null,
      "sourceLocation": "four Viewer artifact filenames",
      "evidenceRole": "publisher filename provenance",
      "rciBoundary": "No fixed public source mapping was supplied in the release."
    },
    {
      "id": "obs-15",
      "field": "generated_archive_count",
      "value": "2",
      "unit": "archives",
      "sourceLocation": "GitHub tag archive endpoints",
      "evidenceRole": "RCI independent source check",
      "rciBoundary": "Generated archive digests are RCI observations, not publisher digests."
    },
    {
      "id": "obs-16",
      "field": "generated_archive_path_count_each",
      "value": "2995",
      "unit": "paths",
      "sourceLocation": "RCI archive inventories",
      "evidenceRole": "RCI independent source check",
      "rciBoundary": "Includes 2 symlinks and excludes 2 export-ignored dotfiles."
    },
    {
      "id": "obs-17",
      "field": "source_tree",
      "value": "2997 blobs / 372 directories / not truncated",
      "unit": null,
      "sourceLocation": "GitHub recursive tree API",
      "evidenceRole": "publisher repository structure",
      "rciBoundary": "Tree visibility is not test execution."
    },
    {
      "id": "obs-18",
      "field": "public_checks",
      "value": "0",
      "unit": "check runs",
      "sourceLocation": "GitHub Checks, Actions and Status APIs at target commit",
      "evidenceRole": "public CI observation",
      "rciBoundary": "Does not assert that no private CI exists."
    },
    {
      "id": "obs-19",
      "field": "first_party_test_surface",
      "value": "13 files / 5 suites",
      "unit": null,
      "sourceLocation": "fixed tests/ tree",
      "evidenceRole": "source-surface observation",
      "rciBoundary": "No result bundle or RCI execution."
    },
    {
      "id": "obs-20",
      "field": "extension_surface",
      "value": "37 files / 13187269 bytes",
      "unit": null,
      "sourceLocation": "fixed extensions/ tree",
      "evidenceRole": "proprietary-binary surface observation",
      "rciBoundary": "Not reverse engineered, executed or treated as MIT-covered by default."
    }
  ],
  "disclosureAudit": [
    {
      "id": "disc-01",
      "field": "release_identity",
      "status": "disclosed",
      "publicEvidence": "Official release, annotated tag, target commit and tree are fixed.",
      "reproductionImpact": "The source event can be cited precisely."
    },
    {
      "id": "disc-02",
      "field": "tag_signature",
      "status": "disclosed-unsigned",
      "publicEvidence": "GitHub verification reason is unsigned.",
      "reproductionImpact": "Do not claim signed-tag provenance."
    },
    {
      "id": "disc-03",
      "field": "commit_signature",
      "status": "disclosed-unsigned",
      "publicEvidence": "GitHub verification reason is unsigned.",
      "reproductionImpact": "Do not claim signed-commit provenance."
    },
    {
      "id": "disc-04",
      "field": "publication_and_edit_dates",
      "status": "disclosed",
      "publicEvidence": "API exposes created, published and updated timestamps; Atom exposes updated.",
      "reproductionImpact": "The August radar event must be labeled an edit, not a new release publication."
    },
    {
      "id": "disc-05",
      "field": "uploaded_asset_manifest",
      "status": "disclosed-and-matched",
      "publicEvidence": "Twelve assets expose names, bytes and SHA-256; all matched RCI downloads.",
      "reproductionImpact": "Exact release bytes can be identified without redistribution."
    },
    {
      "id": "disc-06",
      "field": "generated_archive_digests",
      "status": "rci-observed",
      "publicEvidence": "RCI computed SHA-256 for the generated tar and zip.",
      "reproductionImpact": "GitHub does not publish those digests in the release asset array."
    },
    {
      "id": "disc-07",
      "field": "archive_checkout_match",
      "status": "disclosed-and-matched",
      "publicEvidence": "Both archive path sets and included bytes matched the fixed checkout.",
      "reproductionImpact": "Included source bytes are independently anchored."
    },
    {
      "id": "disc-08",
      "field": "archive_omissions",
      "status": "disclosed-and-matched",
      "publicEvidence": "Two libusb dotfiles are present in checkout but absent from both generated archives.",
      "reproductionImpact": "The bounded export difference must remain attached."
    },
    {
      "id": "disc-09",
      "field": "sdk_build_provenance",
      "status": "partial",
      "publicEvidence": "Seven filenames include target short commit 2f6561c; no SLSA or equivalent attestation is published.",
      "reproductionImpact": "Filename agreement is weaker than a reproducible build chain."
    },
    {
      "id": "disc-10",
      "field": "viewer_build_provenance",
      "status": "unresolved",
      "publicEvidence": "Four filenames include b7e38ef, not the SDK target commit, without a fixed public source mapping in the release.",
      "reproductionImpact": "Viewer bytes are identifiable but source-to-binary provenance is incomplete."
    },
    {
      "id": "disc-11",
      "field": "model_license",
      "status": "unresolved",
      "publicEvidence": "model.sm4 is a standalone 252,582,062-byte asset; no item-specific license was identified.",
      "reproductionImpact": "Do not redistribute, inspect or generalize rights for the model."
    },
    {
      "id": "disc-12",
      "field": "extension_license_wording",
      "status": "conflicting-public-wording",
      "publicEvidence": "extensions/README.md says MIT while LICENSE.txt, extensions/license.txt and EULA impose separate extension restrictions.",
      "reproductionImpact": "Treat extension rights as unresolved and file-specific; seek publisher clarification."
    },
    {
      "id": "disc-13",
      "field": "eula_in_distribution_packages",
      "status": "not-confirmed",
      "publicEvidence": "RCI found license surfaces in listed archives but did not identify the separately named EULA in inspected SDK/Viewer archive listings.",
      "reproductionImpact": "Do not infer package-level notice completeness from the repository alone."
    },
    {
      "id": "disc-14",
      "field": "firmware_bytes",
      "status": "not-in-uploaded-assets",
      "publicEvidence": "The release links firmware versions and external firmware pages; no firmware image is one of the twelve uploaded assets.",
      "reproductionImpact": "Firmware identity and update behavior remain outside this byte audit."
    },
    {
      "id": "disc-15",
      "field": "first_party_test_source",
      "status": "disclosed",
      "publicEvidence": "Thirteen files across five first-party tests are present in the fixed tree.",
      "reproductionImpact": "Test source is inspectable but does not prove execution."
    },
    {
      "id": "disc-16",
      "field": "public_ci_results",
      "status": "not-published-at-tag",
      "publicEvidence": "Checks, Actions runs and legacy statuses each return zero at the target commit.",
      "reproductionImpact": "No public pass/fail manifest can be attached to this release."
    },
    {
      "id": "disc-17",
      "field": "device_firmware_matrix",
      "status": "issuer-disclosed",
      "publicEvidence": "Nineteen release rows name devices or series and recommended firmware.",
      "reproductionImpact": "Manufacturer support evidence is not independent compatibility validation."
    },
    {
      "id": "disc-18",
      "field": "platform_matrix",
      "status": "issuer-disclosed",
      "publicEvidence": "Four platform families are named with selected versions/hardware.",
      "reproductionImpact": "No public per-platform raw result package is supplied."
    },
    {
      "id": "disc-19",
      "field": "physical_device_validation_by_rci",
      "status": "not-performed",
      "publicEvidence": "RCI installed nothing and connected no camera, LiDAR or robot.",
      "reproductionImpact": "No RCI performance, stability, timing or compatibility conclusion is allowed."
    },
    {
      "id": "disc-20",
      "field": "release_performance_dataset",
      "status": "not-published",
      "publicEvidence": "No retained raw depth, timing, PPS, frame-loss, thermal or long-run dataset was identified in release assets.",
      "reproductionImpact": "Feature and fix statements remain issuer-reported."
    }
  ],
  "limitations": [
    "RCI did not execute model.sm4, inspect its internal format or infer its training data, architecture, safety or license.",
    "RCI did not install an SDK or Viewer asset, build the source, run tests, activate a device license or access Orbbec hardware.",
    "Publisher SHA-256 equality proves byte identity at audit time only; it does not establish security, non-maliciousness, compatibility or fitness.",
    "No public check run exists at the tagged commit; RCI cannot infer whether private CI, hardware-in-loop or release qualification occurred.",
    "The release's living documentation links may change after v2.9.3; this audit prefers fixed tag paths and records the release-page claims separately.",
    "Rights observations are factual comparisons of public documents, not legal advice. The conflicting extension wording requires publisher clarification.",
    "The Viewer build token b7e38ef was not mapped to a fixed public source commit by this release.",
    "No cross-camera or cross-LiDAR performance ranking is supported."
  ],
  "rights": {
    "rciWork": "RCI original directory structure, independent calculations, observations, boundaries and prose.",
    "upstream": "Orbbec repository source, extension binaries, model, release assets, firmware, documentation, logos and release prose retain their applicable upstream and third-party rights.",
    "reuseDecision": "Facts plus original commentary only. Link upstream; do not mirror model, binaries, firmware, documentation, source archives, tables, images or substantial release text without an item-specific rights basis."
  },
  "suggestedCitation": "Robot Component Index. “Orbbec SDK 2.9.3 Evidence: 12 Hash Matches, 0 Public Checks, One Unresolved License Boundary.” RCI 039, version 0.1.0, 2026-08-11. https://robotcomponentindex.com/research/orbbec-sdk-2-9-3-release-evidence-audit/"
}