DCENT_OS 0.9.0 Experimental beta20261002 source delivery Project source commit: c0c78663092cb7830fc0e9248c3b452aa4d326dd Buildroot source commit: 7c8edc1b402efcd7bba2dabfe0b3be877adaed7a Extract the project and Buildroot archives into the same directory. They preserve projects/dcentos, projects/dcent-schema and projects/dcent-toolbox topology. The project archive contains 4,614 files (90,643,245 uncompressed bytes), including firmware Rust and dashboard source, Buildroot external integration, installation and verification tools, manifests, licenses and curated public documentation. Each selected file matches its retained release snapshot SHA256, byte length and Git blob identity. Source files have not been rewritten or scrubbed. The Buildroot archive is derived from the exact pinned Git commit, excluding its mutable downloads and build outputs. Build scripts and package definitions retain their original source contents and paths. Internal instructions, workspace research, review/operator reports, private signing lanes, live configs, backups, build outputs and vendor firmware dumps are excluded. Public build input architecture documents and install/media docs are included. Some comments retain development references because source bytes are preserved. The selected source credential scan found no usable embedded private keys or recognized AWS/GitHub/Slack tokens; marker literals in validation/tests were structurally reviewed as synthetic examples. buildroot-matched-source-evidence-clean-v2.tar.gz contains 88 exact SHA256/size matches to retained Buildroot legal inventory records: upstream source archives, patches, series and license evidence. The inventory-listed GNU Linaro binary compiler payload is restricted and is excluded. Paths, hashes and licensing metadata may remain as build evidence. At initial bundle preparation, 170 inventory records lacked an exact retained byte match, including source archives, licenses and generated legal/config files. Additional exact-match upstream material may be delivered as a separate supplement. Local D-Central package sources are in the project archive even when their generated package tarball bytes are unavailable; no matching tarball SHA is claimed for them. This delivery is scoped project/build source and available dependency evidence. It is NOT a claim of complete corresponding source for every byte of the firmware, a reproducible full firmware build, or complete license-compliance verification. The release reuses third-party boot/kernel/FPGA components; exact corresponding kernel/U-Boot/donor source revisions are unverified and proprietary boot component inputs are not included. Independent HDL references do not establish a matching shipped bitstream. Keep those limitations with any redistribution of this release. See source-delivery-manifest-clean-v3.json, source-files-clean-v2.json and SHA256SUMS-clean-v3 for checksums and selected-file verification. Build instructions remain in each project's README/Makefile/scripts. Full image builds require separately supplied matching boot inputs and dependencies. Support: https://d-central.tech/fund/ UPSTREAM SUPPLEMENT: buildroot-upstream-source-supplement.tar.gz adds 28 exact source archive records and 66 exact license/source records from public Buildroot mirrors, verified against the retained inventory SHA256 and size. Combined exact record coverage is 182/259; 76 records remain unmatched. These include generated local-package tarballs, OpenSSL/gettext archives (further retrieval pending), license evidence and generated configuration/manifests/patch series. ADDITIONAL UPSTREAM SOURCES: buildroot-additional-upstream-sources.tar.gz adds exact OpenSSL 3.6.0 and GNU gettext 0.22.4 source archives plus matching license evidence. Final exact retained-inventory record coverage is 186/259; 72 records remain unmatched. All declared third-party target source archives are now available with exact SHA256/size matches. Five generated D-Central package tarballs remain unavailable as exact archive bytes; their original source is included in the project bundle. Third-party boot/kernel corresponding source remains unverified as stated above. CORRECTION v2: Restricted GNU Linaro compiler payload is omitted from the clean source-evidence archive. Every other member retains its original bytes. Final inventory coverage: 186 exact provided records, 72 unmatched records, and one restricted binary-toolchain record intentionally withheld (259 total). PROJECT SOURCE CORRECTION: DCENTOS_0.9.0_beta20261002_dcent-source-c0c7866-clean-v2.tar.gz excludes 15 raw stock-evidence fixture files for unrelated Cvitek targets. All 4,614 retained files remain byte-identical to the release snapshot and verified SHA256/size/Git blob identities. Author-written ABI inventory and fixture hash metadata remain. Fixture-dependent Cvitek tests require separate private inputs; no complete independently reproducible firmware build is claimed. PUBLIC REDISTRIBUTION BOUNDARY: Development signing-key approval does not establish redistribution permission or license clearance. Third-party boot/kernel source correspondence and finished-image redistribution permission remain unverified. The restricted raw GNU Linaro compiler payload and unrelated raw vendor fixtures were withdrawn and are excluded from the clean source replacements.