Glossary
csreq (code requirement blob)
The TCC.db column holding a compiled code requirement (magic 0xFADE0C00) that a program must satisfy for the row to apply to it.
csreq is a compiled code requirement stored with each TCC.db row: a big-endian blob starting with the magic 0xFADE0C00, followed by its length, a kind (1, expression form) and a prefix expression. Decoded, it reads like identifier "com.apple.Terminal" and anchor apple. indirect_object_code_identity holds the same kind of blob for an Automation target.
A requirement that is only cdhash H"..." pins one exact build, typical of ad-hoc signed code. On a Mac, csreq -r- -t decodes a blob. See decoding csreq code requirements.