b-ids is a dated, provenance-carrying corpus of the network identity emitted
by real browser builds: TLS ClientHello bytes, HTTP/2 settings and framing,
and ordered request headers. It includes capture, validation, publication, and
offline-consumption tooling.
The primary result set is
corpus/v1/latest.json.
It maps each supported browser/platform pair to its current stable profile and
lists current profiles for every captured channel. Consumers should follow that
map instead of hard-coding a version.
Direct current results:
| result | browser/platform | link |
|---|---|---|
| User-Agent | Chrome stable / Linux | navigate.txt |
| User-Agent | Firefox stable / Windows | navigate.txt |
| ClientHello | Chrome stable / Linux | linux64.txt |
| header order | Chrome stable / Linux | navigate.list.txt |
| complete route index | all fields and profiles | routes.json |
Aggregate formats are published as
JSON,
NDJSON,
CSV,
TSV,
YAML,
TOML,
SQL, and
Protocol Buffers.
Specialized outputs remain discoverable under the data branch's
configs/,
anchors/,
packages/, and
pcap/ directories.
- A profile is measured from a real browser at a named build and capture instant. Inherited values and fixtures are not published as measurements.
- Every normalized profile retains the raw
ClientHellobytes from which it was parsed. - Per-field provenance distinguishes measured, assumed, substituted, and imported values.
latestselects stable profiles only; pre-release channels remain explicit.- The
databranch is generated fromsourceand includesMANIFEST.jsonandSHA256SUMSfor integrity checks. - Published packages embed the corpus and do not fetch data at runtime.
⚠ Coverage is the set named by latest.json, not a complete browser matrix.
A missing browser, channel, platform, or version is absent data and must not be
silently substituted.
| branch | contents | authority |
|---|---|---|
main |
code, tests, documentation, workflows, and vendored source | implementation |
source |
reviewed profiles, raw captures, vectors, and license | canonical measurements |
data |
deterministic publication output derived from source |
consumer surface |
reference |
byte-preserved upstream research archive | provenance only |
⛔ Do not edit data directly or force-push source or data. A capture
changes source; the publication workflow regenerates data.
Release archives are checksummed and receive GitHub build-provenance attestations. For the initial release:
gh release download v0.0.1 --repo Azathothas/b-ids --pattern 'b-ids-corpus-v0.0.1.tar.gz'
gh attestation verify b-ids-corpus-v0.0.1.tar.gz --repo Azathothas/b-idsA checksum beside an archive verifies transport; the attestation binds the archive to this repository, workflow, and commit.
The Rust version is pinned in rust-toolchain.toml. The
repository also requires Git, PowerShell for .ps1 checks, a POSIX shell for
.sh checks, jq, Node.js, ShellCheck, and PSScriptAnalyzer for the complete
cross-platform gate.
Start with the read-only host probe:
sh scripts/doctor/doctor.shOn Windows:
pwsh -NoProfile -File scripts/doctor/doctor.ps1Run the complete gate before publishing:
sh scripts/common/check-gate.sh --strictpwsh -NoProfile -File scripts/common/check-gate.ps1 -StrictThe gate covers formatting, warning-denied linting, tests, release builds,
script parsing, ShellCheck, links, schemas, manifests, generated snapshots,
aggregate regeneration, and check self-tests. See
docs/methodology/gate.md for individual commands.
scripts/capture/profile.sh is the workflow-backed capture entry point.
It launches a browser in a new disposable profile and records only the network
traffic sent to the local harness. It does not inspect a user's browser profile
or capture unrelated traffic.
⚠ Run provisioning and live capture only on a disposable runner or container. The scripts refuse unsafe hosts, preserve raw bytes, and separate capture from publication review.
The schema and coherence validator live in b-ids-schema and
b-ids-validator. The remaining workspace crates provide the listener, browser
driver, corpus assembler, configuration emitters, conformance CLI, and embedded
library. docs/architecture.md describes their
boundaries and data flow.
This project measures browser network identity. It does not:
- measure canvas, WebGL, audio, font, locale, or other page-visible identity;
- bypass bot challenges or CAPTCHAs;
- ship a scraping client;
- redistribute browser binaries;
- capture from a user's existing browser profile or identify a person;
- fabricate a profile for an uncaptured platform.
| document | purpose |
|---|---|
AGENTS.md |
repository invariants, layout, and maintenance routes |
docs/architecture.md |
technical model and branch data flow |
docs/inherited-claims.md |
claims from other projects and their provenance |
docs/trust-anchors.md |
observed trust-anchor extension behavior |
docs/reference-sweeps/findings.md |
review of pinned upstream evidence |
scripts/README.md |
script contracts and exit semantics |
SECURITY.md |
threat model and vulnerability reporting |
docs/history/README.md |
completed plans, reviews, and superseded claims |
Project code and generated data are released under 0BSD. The
imported archive on the reference branch
and compiled third-party source under vendor/ retain their own licenses.