# Owned synthetic QScout lab, 30 September 2026

This packet records one owned Python file with a seeded MD5 pattern, a harness edit to SHA-256, a native scan/rescan, a local candidate CBOM exporter, a synthetic loopback ticket service, and a separate Node TLS key-establishment fixture. **MD5 to SHA-256 is classical hash hardening, not a PQC migration or full crypto inventory.** The QScout source candidate `03e3b4ff300b6ca8c3b9a18f49a95428b2c8466f` was local and not the deployed product at packet creation. No customer estate, peer tool, customer ticket service, production PKI, autonomous TLS change or outside assessment was tested. Qtonic Quantum Corp publishes the Index and builds QScout; QScout evidence received deeper review than peer evidence.

Absolute `/workspace/...` paths in the preserved raw CBOM and scan receipts refer only to this owned AWS lab fixture, local source candidate checkout and lab interpreter; they are observation-time paths, not customer targets or deployed runtime custody. The separately archived before and after fixture files carry the current bytes.

The original native before CBOM is preserved as `original-failing-before-cbom.json`. It fails official CycloneDX 1.7 validation; the old subset check was insufficient. The final candidate replay has one MD5 finding before and none after, with one/zero CBOM components. Both candidate documents pass the vendored official schema with effective date-time format checking. Native Finding has no stable ID; `lab-binding-manifest.json` links its exact hash to the separately archived, byte-hashed before file and labels the mutable target path historical. The after file still contains SHA-256 despite the after CBOM having zero components, so no complete algorithm inventory follows. The ML-DSA-65 signatures prove exact bytes under an ephemeral **lab-only** key, not a production release or scanner completeness.

`workflow-summary.json` is a sanitized derivative of a private full raw trace; its SHA-256 is recorded. The harness, rather than native `run_closed_loop`, polled the synthetic ticket service, changed the fixture and ran the rescan before passing results into closure logic. One positive closed, and four negatives did not. Vendor-generated closure artifacts with a misleading production-route label are deliberately excluded because this exercise used only loopback. `tls-summary.json` and the two script/receipt pairs are separate. OpenSSL trace directly prints key_share NamedGroup for X25519, X25519MLKEM768 and MLKEM768 on the corresponding successful TLS 1.3 fixture handshakes. A classical-only client failed against hybrid-only policy, and rollback served an HTTP request. The self-signed certificate was RSA and the client disabled certificate verification; this is key-establishment evidence only, not PQ authentication or a production trust-chain test. A separately sealed one-port follow-up used a SAN localhost self-signed RSA lab certificate explicitly trusted by the compatible client (`rejectUnauthorized=true`). Of 32 compatible probes, 26 returned authenticated HTTP 200 and six got `ECONNREFUSED` during two intentional approximately 251–252 ms close/rebind gaps. A classical-only client failed the hybrid handshake, an untrusted-CA client failed certificate validation, and rollback on the same port succeeded; the port was released. These are probe outcomes, not uptime or SLA. They show measured interruptions and recovery in a Node/OpenSSL harness, not uninterrupted migration, QScout-driven policy changes, post-quantum authentication or production trust. `continuity.json` keeps each probe and timestamp; the public RSA certificate, sealed protocol, script and raw OpenSSL trace are included. The trace contains NamedGroup records, but it does not mark each probe or phase, so per-probe group association is not independently attested.

## Verify this downloaded packet

With Python 3.12, `jsonschema`, `referencing`, liboqs and its Python binding already available, run from an extracted copy:

```sh
python verify.py
```

The verifier uses **only files inside this directory**. It checks SHA-256 entries, effective RFC3339 format checking, official CycloneDX 1.7 schema, the original failure, hash-bound archived fixture-to-finding link, all three ML-DSA-65 signatures, one-byte tamper rejection, and bounded workflow/TLS outcomes including all 32 continuity probes and six recorded restart failures. It exits nonzero on a changed file or invalid result. It never reads a private signing key. `schema/NOTICE` is the upstream CycloneDX schema notice. The lab signature key is distinct from product trust keys.
