{
  "entrypoint_kind": "local_action",
  "entrypoint_detail": "local Unix-domain PulseAudio compatibility socket via the public PulseAudio LOAD_MODULE path (pactl load-module module-ladspa-sink plugin=<abs path>) in the pipewire-pulse daemon; client confined in a bubblewrap mount+user namespace sandbox",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "pipewire 1.6.2",
    "pipewire-pulse 1.6.2",
    "pulseaudio-utils pactl 17.0",
    "bubblewrap"
  ],
  "proof_artifacts": [
    "logs/client_fixed_attempt1.log",
    "logs/client_fixed_attempt2.log",
    "logs/client_vuln_attempt1.log",
    "logs/client_vuln_attempt2.log",
    "logs/daemon_fixed_attempt1_pipewire.log",
    "logs/daemon_fixed_attempt1_pulse.log",
    "logs/daemon_fixed_attempt2_pipewire.log",
    "logs/daemon_fixed_attempt2_pulse.log",
    "logs/daemon_vuln_attempt1_pipewire.log",
    "logs/daemon_vuln_attempt1_pulse.log",
    "logs/daemon_vuln_attempt2_pipewire.log",
    "logs/daemon_vuln_attempt2_pulse.log",
    "logs/marker_vuln_attempt1.txt",
    "logs/marker_vuln_attempt2.txt",
    "logs/negative_control_obs_fixed_attempt1.json",
    "logs/negative_control_obs_fixed_attempt2.json",
    "logs/ns_client_host_fixed_attempt1.txt",
    "logs/ns_client_host_fixed_attempt2.txt",
    "logs/ns_client_host_vuln_attempt1.txt",
    "logs/ns_client_host_vuln_attempt2.txt",
    "logs/ns_evidence_fixed_attempt1.txt",
    "logs/ns_evidence_fixed_attempt2.txt",
    "logs/ns_evidence_vuln_attempt1.txt",
    "logs/ns_evidence_vuln_attempt2.txt",
    "logs/reproduction_steps.log"
  ],
  "notes": "CVE-2026-5674 confirmed: sandboxed client loaded attacker library into out-of-sandbox pipewire-pulse via PulseAudio LOAD_MODULE (module-ladspa-sink absolute plugin path); 2/2 vulnerable attempts wrote host-only markers with live daemon pid/comm; 2/2 negative controls denied with allow-module-loading=false"
}
