# Evidence boundaries and provenance

This package is a static, public-safe record. It contains no paper file, paper source archive, author source checkout, data, binary, run database, raw log, local path, credential, or executable payload.

## Source pins

- Official claim feeds: challenge commit `7b5b56aebf3abe590eab9f2c241a796125cab928`; full-feed SHA-256 values are recorded in `evidence/provenance.json`, while this package retains only the target's exact extracted entries.
- Judge merge: the pinned `repro.js` loads both feeds and applies `Object.assign({}, default_claims, anchored_claims)`, so anchored claims override defaults for the same OpenReview ID.
- Paper: [OpenReview record](https://openreview.net/forum?id=Oj2I1xdKpv); [arXiv 2605.18004v1](https://arxiv.org/abs/2605.18004), TeX source SHA-256 `e9570032016dc8e6c985bc18ba9c2f810f17a03cb0308696d21c055ad96e868a`.
- Released code: [Tim-Xiong/RL4RLA](https://github.com/Tim-Xiong/RL4RLA) at `2062bd1441effffd312541426c4c720c5a1dbb7e`, MIT licence (licence SHA-256 `fe5099786651a18f9cf33025355261828dcc852fa51d6c237be2bf2c0bf96764`). The README calls this official RL4RLA code and links the same arXiv paper; the OpenReview record links that repository.

## Safety and bounded check

The abstract, full paper TeX source, repository README, repository layout, and tracked source text passed the strict excluded-scope screen. The only lexical alert was a standard graph-search selection variable; it was not excluded content.

The sole execution check ran the released batch runner in dry-run mode against `hp/mcgs_ucd/leverage_score_subsampling/0.yml` and exited successfully after parsing one configuration. The configuration declares 100,000 playouts, so no author experiment was launched under the bounded CPU-only route.

Evidence limit: this package contains a released-source and paper-table audit plus one runner dry-run; it is not an independent reproduction and does not validate the reported numerical results.
