E.1 Preparation

Verify the source and reference files against the supplied manifest before changing the experiment. Record the OpenSSL executable version and the development package selected by pkg-config. If several OpenSSL installations exist on the machine, identify the one used by both compilation and execution. Build in the local project directory; do not install the teaching module into a system provider directory merely to reproduce the tests.

E.2 Baseline reproduction

./implementation/build.sh
cat results/tests.json
cat results/providers.txt

There should be eight successful baseline checks. Confirm that the programmatic client reports provider=edu. Compare the abc digest with the known value in the paper. Confirm that the expected property failure is recorded as a passing negative test rather than being ignored.

E.3 Expanded reproduction

./implementation/extended-build.sh
cat results/extended-tests.json
tail -n 2 results/extended-build.log

The saved log in this edition contains the observed run. When reproducing, redirect output to a new file if the original record must be preserved. The callback test should complete its assertions, and the integration harness should report 37 cases. If a run fails, preserve the compiler output, command, environment, and error text before changing the implementation.

E.4 Questions for source review

Review areaQuestion
InitializationAre outputs returned only after required provider resources exist?
Partial failureCan every allocated resource be released on the path where a later step fails?
AdvertisementDoes each algorithm table remain alive for as long as the core may use it?
DispatchDo function identifiers match callback signatures?
Input handlingAre byte lengths preserved across wrapper and backend calls?
Output handlingAre capacity, written length, and backend finalization ordered correctly?
DuplicationDoes a new operation own independent mutable state?
PolicyIs the backend selection explicit and consistent with the intended assurance?
CleanupAre operation contexts released before the resources they depend on?

E.5 Suggested additional experiments

Feed different suffixes to duplicated contexts and compare against two expected values. Introduce controlled allocator failures and record whether cleanup remains correct. Build with memory instrumentation and rerun the same deterministic tests. Add an in-process multithreaded client with independent digest contexts. These are suggested extensions, not completed experiments in this edition.

For a performance project, implement both direct-default and bridge paths in the same executable. Separate provider loading, method fetching, and warm digest processing. Report message sizes, update fragmentation, iteration counts, uncertainty, and output validation. Avoid using the large-message functional case as a performance measurement: no timing was recorded for that purpose.

E.6 Artifact interpretation

The PDF explains the reasoning; the source defines the implementation; the scripts define the procedure; the result files record observed execution. If these disagree after an edit, regenerate the affected artifacts and update the claims. An archived result should never be presented as evidence for changed code without rerunning the relevant tests.

E.7 Completed and proposed work

Completed in this editionStill proposed or outside scope
Dynamic provider and application client.Independent SHA-256 implementation.
Eight baseline and 37 extended integration cases.Exhaustive state-space exploration.
Direct callback capacity and parameter checks.Allocation-failure campaign and sanitizers.
Sixteen independent parallel processes.In-process thread-safety stress tests.
Version-pinned reference collection.Independent clean-machine reproduction.
Functional results on OpenSSL 3.5.5.FIPS validation or production security approval.

This distinction is the final acceptance criterion for the paper itself: every experimental claim should correspond to an executable procedure and a recorded result, while proposals should remain visibly labeled as proposals.