MachineWitness: same-day capture muster-contix-2, witness witness-1

This package is ONE witness's record. The order was captured by two independent
witnesses at two providers; the sibling package is built the same way on the other
machine. Each stands on its own; neither needs us to be checked.

For every address (see manifest.json, one entry per observation <id>):

1. THE FILES MATCH THEIR HASHES
   sha256sum payload-<id>.bin shot-<id>.png dom-<id>.html cert-<id>-*.der
   payload  -> payload_sha256 in leaf-<id>.json
   shot/dom -> render.png_sha256 / render.dom_sha256 in provenance-<id>.json
   certs    -> peer_cert_chain_sha256 in provenance-<id>.json (leaf certificate first)

2. THE PICTURE IS BOUND INTO THE LEAF
   sha256sum provenance-<id>.json must equal provenance_sha256 in leaf-<id>.json
   (the file is exactly the bytes that were hashed). Because the picture's and the
   DOM's hashes are inside that file, the leaf covers them.
   leaf = sha256(0x00 || "mwleaf-v1|" || url || "|" || observed_at || "|"
                  || payload_sha256 || "|" || status || "|" || provenance_sha256)

3. THE LEAF IS IN THE ORDER ROOT (proves the minute)
   order-proof-<id>.json: fold the siblings from the leaf, in order:
     side 'left'  -> node = sha256(0x01 || sibling || node)
     side 'right' -> node = sha256(0x01 || node || sibling)
   The result must equal the second line of stichtag-muster-contix-2.root.txt, the file
   the qualified time-stamp stichtag-muster-contix-2.root.qts.tsr was issued over:
     openssl ts -verify -in stichtag-muster-contix-2.root.qts.tsr \
             -data stichtag-muster-contix-2.root.txt -CAfile <GLOBALTRUST CA chain>
   (GLOBALTRUST is a qualified trust service provider on the EU Trusted List;
   eIDAS Art. 41 presumption for date and time.)

4. THE LEAF IS IN THE DAY ROOT (the ordinary daily seal, independent of 3)
   day-proof-<id>.json, folded the same way, must equal the second line of
   2026-09-29.root.txt, which carries the day's anchors:
     2026-09-29.root.txt.ots      ots verify 2026-09-29.root.txt.ots
     2026-09-29.root.txt.tsr      openssl ts -verify (freetsa.org)
     2026-09-29.root.txt.qts.tsr  openssl ts -verify (GLOBALTRUST, qualified)

5. THE TWO WITNESSES
   Compare with the sibling package: same addresses, different machines, providers
   and IP addresses (observer_addr in provenance). Differences between the two are
   part of the record, not an error: a site may answer one witness differently.

What this package is: a record of what the listed addresses delivered to two independent witnesses at the stated times, sealed and time-stamped. What it is not: a legal assessment, an opinion on whether the content is lawful, or advice on what to do with it. MachineWitness records and does not evaluate; how the record is used, and what it means in a given dispute, is for the customer and their counsel to decide. Provided without warranty beyond what the recomputation steps in this file prove. Terms: https://machinewitness.eu/terms
