{
  "entrypoint_kind": "cli_command",
  "entrypoint_detail": "bwrap --bind <untrusted-tree> / --dir /subdir/newdir --file 3 /subdir/newdir/ESCAPE_MARKER.txt /usr/bin/true, where the untrusted tree contains subdir -> /oldroot<host_target>",
  "service_started": false,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "bubblewrap-v0.11.0 (vulnerable)",
    "bubblewrap-v0.12.0 (fixed)",
    "linux-user-namespaces",
    "linux-mount-namespaces"
  ],
  "target_identity": {
    "repository_url": "https://github.com/containers/bubblewrap.git",
    "commit_sha": "9ca3b05ec787acfb4b17bed37db5719fa777834f",
    "target_digest": "da48463ddef1411883a983880d22319ce0e518520e58c2d313ebb49aaaa9074c",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "logs/smoke_test.log",
    "logs/attempt-vuln-1.log",
    "logs/attempt-vuln-2.log",
    "logs/attempt-fixed-1.log",
    "logs/attempt-fixed-2.log",
    "repro/proof_summary.txt",
    "repro/markers/ESCAPE_MARKER-vuln-1.txt",
    "repro/markers/ESCAPE_MARKER-vuln-2.txt"
  ],
  "artifact_sha256": {
    "logs/smoke_test.log": "26873c7d40e4f3974b354b25a4d22ac4f0f3697251a8e7b13122932dfc30c898",
    "logs/attempt-vuln-1.log": "f5da8601d5d71326d49784d8cfb1f4d9a2d6a52d17395bcaadb6f1a0b922214c",
    "logs/attempt-vuln-2.log": "ed1c4e233d7212f390db90afcceec045d3347267862c9b88512027edaffca057",
    "logs/attempt-fixed-1.log": "6474c03c41221b9744263747b14f938a131ac1d0caf9017a888c508829434e14",
    "logs/attempt-fixed-2.log": "4ba3ba26ce795f4b4d056f2e3c9b57a921f47d3c9eec71ced54d59ba6207e977",
    "repro/proof_summary.txt": "687c26c49672ac6637a22bcddd9fc4b2a9bf77188486020456b78690f3b7e547",
    "repro/markers/ESCAPE_MARKER-vuln-1.txt": "dae9ae067f1ff8ed486c96e1d8a1f8ccdc323d5531d64fa99a861755876bd61c",
    "repro/markers/ESCAPE_MARKER-vuln-2.txt": "dae9ae067f1ff8ed486c96e1d8a1f8ccdc323d5531d64fa99a861755876bd61c"
  },
  "notes": "cli_local surface: real bwrap CLI executed unprivileged via user namespaces. Vulnerable v0.11.0 followed the /oldroot absolute symlink and created a directory plus attacker-content marker file on the host (outside the sandbox) in 2/2 attempts; fixed v0.12.0 failed closed (RESOLVE_IN_ROOT) in 2/2 attempts. No service needed: entrypoint is the bwrap CLI itself."
}