{
  "entrypoint_kind": "function_call",
  "entrypoint_detail": "libcurl multi API HTTPS transfers with equal primary CAfile/ssl_options but differing effective native CA policy",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "libcurl",
    "GnuTLS",
    "Python HTTPS origin"
  ],
  "target_identity": {
    "repository_url": "https://github.com/curl/curl.git",
    "commit_sha": "7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb",
    "target_digest": "12f5816fc1839b7d34b228a15a2a28259af4c7bc435288414d6ed848294658b0",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "repro/source-identity.txt",
    "repro/build-identity-vulnerable.txt",
    "repro/build-identity-fixed.txt",
    "repro/server-cert.pem",
    "repro/server.log",
    "repro/vulnerable-attempt-1.log",
    "repro/vulnerable-attempt-2.log",
    "repro/fixed-attempt-1.log",
    "repro/fixed-attempt-2.log"
  ],
  "artifact_sha256": {
    "repro/source-identity.txt": "e7948ee4a6399a739e882102ce629752a77f3523ce807971ec6c538916ff853b",
    "repro/build-identity-vulnerable.txt": "94ae6b3416fd8bb695da56d19bbfb600e3e03b529c3f1bfd0bd040d421238386",
    "repro/build-identity-fixed.txt": "753f4d79ffcc90fa655a58b756038cf500903c1bbb58ad291806b80746668b63",
    "repro/server-cert.pem": "a65ca7cabd8cb33a3e25c38b199cf087ccd9822a4864f131a94944342095ec78",
    "repro/server.log": "c7ea7d14279edfd0510e1579aa47fcba8ff2ef8a3bb289155fa94d880e3200d7",
    "repro/vulnerable-attempt-1.log": "c54a3d8cbf6efde4e8a30343254f1f1d5a1aed00d661cb62f528a9e2fbee5030",
    "repro/vulnerable-attempt-2.log": "6a3a3a62f7bc432212acec7ec45bca76ef83e23085a8ca6e194b6fd13fd744bc",
    "repro/fixed-attempt-1.log": "2deff3d3503eb4d8d0ea46c14d9654ad524ab4ad408b27290f4fc1ac2b025faf",
    "repro/fixed-attempt-2.log": "a14d565090fadd82d778c29987025886682c80dda0c42fc659b6c064e40399fa"
  },
  "notes": "Vulnerable parent reused native-trusted TLS for an explicit custom-CA policy that fails on a fresh connection; fixed commit rejected reuse. Linux GnuTLS provides equivalent native-store semantics although the advisory states production exposure is Windows/macOS."
}
