rngrep corpus and db-dump snapshot (crates.io reproducibility artifact)
收藏资源简介:
Archived crates.io db-dump (db-dump.tar.gz, pinned sha256 af2a04c11d6fbed99307167d44d28c3360090c8eae186f5bc818cf42f8b0bf36, snapshot 2026-07-08) and the full .crate source corpus (corpus.tar, 270,761 tarballs) used to produce the results in "Mining RDRAND: A Dataset of Hardware-Entropy Instruction Use Across the Rust Crate Ecosystem." This deposit exists because crates.io serves only the latest db-dump and does not guarantee a given crate tarball's availability or content indefinitely (see docs/corpus.md in the repository for a measured example of this drift). It is an archival copy for byte-for-byte reproduction of the paper's static analysis, not a new publication of the corpus's contents. Unlike an earlier snapshot of this dataset, the corpus here was fetched with license-based target filtering already applied at fetch time (see pipeline/crawler/src/license.rs in the repository): only crate-versions whose declared SPDX license permits unmodified redistribution (permissive, copyleft, or an OR mixing the two) were fetched at all. Each of the 270,761 crate tarballs retains the license its original author declared to crates.io at publication time (recorded per-crate in that crate's Cargo.toml/crates.io metadata, and summarized in this repository's manifest.csv / crates.csv). This deposit's own license field applies to the archival packaging itself, not to the mirrored crate source -- consult each crate's own declared license before reusing its code for anything beyond reproducing this study. Pipeline and derived CSV results: https://github.com/wrigjl/rngrep This deposit corresponds to the msr-submission tag of the rngrep repository (github.com/wrigjl/rngrep@msr-submission, commit 03ac2d2b41).



