{
  "expected": {
    "downgrade_rejected": true,
    "eapol_test_built": true,
    "ok": true,
    "oqs_provider_path_persistent": true,
    "radius_eaptls_accept": true,
    "tls_pqc_handshake": true
  },
  "hash_version": 2,
  "name": "eap_freeradius_persistent",
  "note": "S06 continuation queue row 17 (sealed 2026-09-02 BEFORE tools/run_eap_freeradius_linux.sh was changed). The committed artifacts/native/eap_freeradius_ci.json (colima, FreeRADIUS 3.2.5, OpenSSL 3.0.13) records downgrade_rejected true, tls_pqc_handshake true, radius_eaptls_accept true, pqc_eaptls_accept FALSE and an oqs-provider under /tmp/eap_pqc, the ephemeral path that lost the provider (S05 finding). BAR: after rebuilding liboqs 0.12.0 + oqs-provider 0.8.0 (the script's own pinned pair, not upgraded) on a PERSISTENT path inside the VM, the regenerated artifact keeps downgrade_rejected true and the three other recorded booleans true with the provider path outside /tmp. BLIND: pqc_eaptls_accept (the committed run says false; a true would be the integrated Tier-A the artifact's own note names). Kill: the provider still fails to load on the persistent path -> environment finding, NR.",
  "note_sha256": "12212e79926197747fe99eb686d9fd65d92562a93dba3a41caffb74f2ea4645a",
  "protocol": "pre-registered before the benchmark run. sha256 covers expected+tol; note_sha256 covers the prose. Neither proves ordering on its own -- the git commit of this file does, and git_blob_matches() is the anchor that makes an edit visible.",
  "sealed": true,
  "sha256": "033fa0f95e5078833748e471a55367a353503a274e4b19d15244a54c51f09c91",
  "tol": {}
}
