RCI 039 · depth-camera and LiDAR software evidence audit

12 assets matched. Zero public checks. One unresolved license boundary.

The release bytes are unusually easy to identify. The performance evidence and rights surface are not: a large licensed model, proprietary extension binaries, unsigned source identity and conflicting upstream license wording remain attached.

Published 2026-08-1116 min readResearch dataset v0.1.0
12publisher hashes matched
649,731,276uploaded bytes checked
0public checks at tag
0camera tests by RCI

The direct answer

Is v2.9.3 a fixed public release? Yes. The official release resolves through annotated tag ca69b53b11ed to commit 2f6561c28255 and a complete recursive tree. GitHub reports both tag and commit as unsigned.

Can the uploaded bytes be identified? Yes. RCI downloaded all twelve uploaded assets—649,731,276 bytes—and matched every publisher size and SHA-256 without executing any file.

Does this validate Orbbec camera, LiDAR or model performance? No. RCI installed nothing, activated no device license, updated no firmware and connected no device or robot.

Can the whole release be called MIT? No such blanket conclusion is supported. The repository root says MIT for the repository, but separately restricts extension binaries; the EULA calls them proprietary, while extensions/README.md also calls the non-open-source extensions MIT. The standalone model.sm4 has no item-specific license identified by RCI.

Strongest supported conclusion

Orbbec SDK v2.9.3 is a fixed public release with twelve byte-identifiable uploaded assets whose publisher sizes and SHA-256 digests all matched RCI downloads. Its source identity and distribution bytes are auditable; its performance, device behavior, model operation and complete rights boundary are not independently validated.

A July release edited in August

The release API separates published_at on 2026-07-16 from updated_at on 2026-08-05. GitHub's Atom entry exposes the August edit timestamp. The source radar therefore rediscovered an edited July release; RCI does not relabel it as a new August publication.

This distinction matters for an evidence database: discovery time, source edit time and original publication time are different fields.

Twelve uploaded assets, fourteen displayed entries

The twelve uploaded assets total 649,731,276 bytes. RCI downloaded and hashed them without executing or redistributing them. GitHub's human page count of fourteen includes two generated source archives, which are not members of the uploaded-asset API array.

AssetRoleBytesRCI check
model.sm4proprietary-or-undeclared-model-asset252,582,062size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_202607151523_2f6561c_linux_arm64.tar.gzsdk-distribution10,905,176size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_202607151523_2f6561c_linux_x86_64.tar.gzsdk-distribution9,885,452size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_202607152322_2f6561c_win_x64.zipsdk-distribution61,142,460size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_202607152323_2f6561c_macOS.tar.gzsdk-distribution12,120,512size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_amd64.debsdk-distribution39,923,970size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_arm64.debsdk-distribution65,715,970size + SHA-256 matched; not executed
OrbbecSDK_v2.9.3_win64.exesdk-distribution36,958,959size + SHA-256 matched; not executed
OrbbecViewer_v2.9.3_202607160623_b7e38ef_linux_arm64.tar.gzviewer-distribution-separate-build-token56,702,023size + SHA-256 matched; not executed
OrbbecViewer_v2.9.3_202607160623_b7e38ef_linux_x86_64.tar.gzviewer-distribution-separate-build-token31,732,438size + SHA-256 matched; not executed
OrbbecViewer_v2.9.3_202607161422_b7e38ef_win_x64.zipviewer-distribution-separate-build-token43,899,166size + SHA-256 matched; not executed
OrbbecViewer_v2.9.3_202607161423_b7e38ef_macOS_arm64.tar.gzviewer-distribution-separate-build-token28,163,088size + SHA-256 matched; not executed

The SDK filenames contain the tagged commit prefix 2f6561c. The four Viewer files contain b7e38ef, which the release does not map to a fixed public Viewer source commit. Hashes identify the Viewer bytes but do not close that source-to-binary gap.

Two source archives, one bounded export difference

Both generated archives expose identical 2,995-path sets and identical included bytes, matching the fixed checkout for every included path. They omit two libusb dotfiles through archive export behavior; this is a bounded archive difference, not a source corruption finding.

The recursive source tree contains 2,997 blobs and 372 directories and is not truncated. The generated tar and zip each expose 2,995 file/symlink paths; every included path matched the fixed checkout byte-for-byte.

The annotated tag and target commit are both unsigned in GitHub's verification metadata. RCI records that limitation instead of converting a stable hash into a signature claim.

A 252.6 MB model behind device authorization

The largest uploaded item is model.sm4 at 252,582,062 bytes. The fixed example documentation says the enhanced filter is limited to NVIDIA Jetson/Linux ARM64, requires a device that supports license authorization and a valid filter license, and accepts the model path.

Those are implementation boundaries—not performance results. No model card, training-data disclosure, item-specific model license, accuracy dataset, raw before/after depth frames or RCI execution is attached to this audit.

Issuer statementEvidence roleRCI boundary
LingBot Enhanced Depth Filter is available for Gemini 330 series on NVIDIA Jetson/Linux ARM64 and requires device-license activation plus model.sm4.issuer release statement plus fixed example documentationRCI matched the model bytes but did not inspect the model, activate a device license, run inference or measure depth quality.
Timestamp fitting, clock-source selection and DaBai hardware PPS behavior changed.issuer release statement and API surfaceNo clock trace, PPS test protocol, synchronization result file or physical multi-device test was published or run by RCI.
Preset, color-preset, network-state and firmware-log APIs were added or expanded.issuer release statement and fixed source surfaceAPI presence is not evidence that every listed device/firmware combination behaves correctly.
The release lists 19 supported-device/firmware rows and four supported platform families.issuer compatibility matrixRows are manufacturer support statements, not an RCI compatibility test or a blanket statement across every hardware revision.
Twelve uploaded assets expose publisher SHA-256 digests.publisher distribution metadata independently matched by RCIDigest equality proves byte identity at audit time, not security, safety, performance, license clearance or production readiness.
SDK artifact names include short commit 2f6561c while Viewer artifacts use b7e38ef.publisher filenamesThe release does not link b7e38ef to a fixed public Viewer source repository/commit, so Viewer build provenance remains incomplete.
The repository root says MIT, while extension files have separate restrictions and an EULA.fixed upstream rights documentsRCI reports the public wording conflict and does not provide legal advice or infer permission for model, binary, firmware, media or documentation reuse.
The fixed tree contains tests and a benchmark tool but no public GitHub checks at the tagged commit.source-surface and GitHub API observationTest source is not execution evidence; zero public checks does not prove that Orbbec ran no private tests.

Test source is visible; public execution is not

The fixed tree contains thirteen first-party test files across five suites and seventeen benchmark-tool files. GitHub exposes zero check runs, zero workflow runs at the tagged commit and zero legacy statuses. Source presence cannot be rewritten as successful execution, and absence of public checks cannot be rewritten as absence of private testing.

The fixed tree has 13 files across 5 first-party suites and 17 files in the benchmark-tool surface. That is useful reproducibility context, but GitHub exposes no public check run, workflow run at the target commit or legacy status to show what executed for this release.

The extension rights wording does not resolve cleanly

The fixed root license file first declares MIT for the repository, then gives the extension library a narrower Orbbec-hardware-only license with modification and reverse-engineering restrictions. The fixed EULA calls the extension proprietary and adds use and redistribution conditions.

At the same time, extensions/README.md says the extensions are not open source and “under the MIT license.” RCI does not choose one sentence as blanket permission over the others.

RCI reuse decision

Facts plus original commentary only. Link upstream; do not mirror model, binaries, firmware, documentation, source archives, tables, images or substantial release text without an item-specific rights basis.

Twenty disclosure checks

FieldStatusPublic evidenceImpact
release identitydisclosedOfficial release, annotated tag, target commit and tree are fixed.The source event can be cited precisely.
tag signaturedisclosed-unsignedGitHub verification reason is unsigned.Do not claim signed-tag provenance.
commit signaturedisclosed-unsignedGitHub verification reason is unsigned.Do not claim signed-commit provenance.
publication and edit datesdisclosedAPI exposes created, published and updated timestamps; Atom exposes updated.The August radar event must be labeled an edit, not a new release publication.
uploaded asset manifestdisclosed-and-matchedTwelve assets expose names, bytes and SHA-256; all matched RCI downloads.Exact release bytes can be identified without redistribution.
generated archive digestsrci-observedRCI computed SHA-256 for the generated tar and zip.GitHub does not publish those digests in the release asset array.
archive checkout matchdisclosed-and-matchedBoth archive path sets and included bytes matched the fixed checkout.Included source bytes are independently anchored.
archive omissionsdisclosed-and-matchedTwo libusb dotfiles are present in checkout but absent from both generated archives.The bounded export difference must remain attached.
sdk build provenancepartialSeven filenames include target short commit 2f6561c; no SLSA or equivalent attestation is published.Filename agreement is weaker than a reproducible build chain.
viewer build provenanceunresolvedFour filenames include b7e38ef, not the SDK target commit, without a fixed public source mapping in the release.Viewer bytes are identifiable but source-to-binary provenance is incomplete.
model licenseunresolvedmodel.sm4 is a standalone 252,582,062-byte asset; no item-specific license was identified.Do not redistribute, inspect or generalize rights for the model.
extension license wordingconflicting-public-wordingextensions/README.md says MIT while LICENSE.txt, extensions/license.txt and EULA impose separate extension restrictions.Treat extension rights as unresolved and file-specific; seek publisher clarification.
eula in distribution packagesnot-confirmedRCI found license surfaces in listed archives but did not identify the separately named EULA in inspected SDK/Viewer archive listings.Do not infer package-level notice completeness from the repository alone.
firmware bytesnot-in-uploaded-assetsThe release links firmware versions and external firmware pages; no firmware image is one of the twelve uploaded assets.Firmware identity and update behavior remain outside this byte audit.
first party test sourcedisclosedThirteen files across five first-party tests are present in the fixed tree.Test source is inspectable but does not prove execution.
public ci resultsnot-published-at-tagChecks, Actions runs and legacy statuses each return zero at the target commit.No public pass/fail manifest can be attached to this release.
device firmware matrixissuer-disclosedNineteen release rows name devices or series and recommended firmware.Manufacturer support evidence is not independent compatibility validation.
platform matrixissuer-disclosedFour platform families are named with selected versions/hardware.No public per-platform raw result package is supplied.
physical device validation by rcinot-performedRCI installed nothing and connected no camera, LiDAR or robot.No RCI performance, stability, timing or compatibility conclusion is allowed.
release performance datasetnot-publishedNo retained raw depth, timing, PPS, frame-loss, thermal or long-run dataset was identified in release assets.Feature and fix statements remain issuer-reported.

14 of 20 checks are narrower than fully disclosed or byte-matched. The most consequential gaps are model rights, extension-license consistency, Viewer build provenance, public CI results and retained physical-device data.

What RCI independently checked

  1. Resolved the official release, annotated tag, target commit, complete tree and fixed project version.
  2. Downloaded twelve uploaded assets, recalculated every byte size and SHA-256, and executed none of them.
  3. Downloaded both generated source archives and compared normalized paths, regular-file bytes and symlink targets with each other and the tagged checkout.
  4. Queried public Checks, Actions and legacy Status APIs at the exact target commit.
  5. Inspected fixed test, benchmark, extension, example, license and EULA surfaces while keeping issuer statements separate from RCI validation.
  6. Recorded publication and edit timestamps separately and preserved the displayed-asset versus uploaded-asset count distinction.

Limits that stay attached

  • RCI did not execute model.sm4, inspect its internal format or infer its training data, architecture, safety or license.
  • RCI did not install an SDK or Viewer asset, build the source, run tests, activate a device license or access Orbbec hardware.
  • Publisher SHA-256 equality proves byte identity at audit time only; it does not establish security, non-maliciousness, compatibility or fitness.
  • No public check run exists at the tagged commit; RCI cannot infer whether private CI, hardware-in-loop or release qualification occurred.
  • The release's living documentation links may change after v2.9.3; this audit prefers fixed tag paths and records the release-page claims separately.
  • Rights observations are factual comparisons of public documents, not legal advice. The conflicting extension wording requires publisher clarification.
  • The Viewer build token b7e38ef was not mapped to a fixed public source commit by this release.
  • No cross-camera or cross-LiDAR performance ranking is supported.

Download the release audit

Download the immutable JSON release and record-level CSV. Stable aliases are current JSON and current CSV.

Suggested citation: Robot Component Index. “Orbbec SDK 2.9.3 Evidence: 12 Hash Matches, 0 Public Checks, One Unresolved License Boundary.” RCI 039, version 0.1.0, 2026-08-11. https://robotcomponentindex.com/research/orbbec-sdk-2-9-3-release-evidence-audit/