{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "Unauthenticated POST/PUT http://127.0.0.1:<port>/api/v4/projects/<id>/repository/files/<segment>/ (trailing slash) and POST http://127.0.0.1:<port>/api/v4/projects/<id>/repository/commits/ (trailing slash), via GitLab omnibus nginx->workhorse->puma real HTTP boundary",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "docker:gitlab/gitlab-ce omnibus (nginx, gitlab-workhorse, puma/Rails, gitaly, postgresql, redis)",
    "vulnerable: gitlab/gitlab-ce:19.3.1-ce.0 (gitlab-rails 668508315ee5b5a59aa018424f741c27e81bafe1)",
    "fixed control: gitlab/gitlab-ce:19.3.2-ce.0 (gitlab-rails 34042bf7d00ca54c5e04079df6cdc6151485fd46)"
  ],
  "target_identity": {
    "repository_url": "https://gitlab.com/gitlab-org/gitlab",
    "target_digest": "sha256:f63df4c43029fe91db370609c0b40a1e3585cebd06e3e9637d93a9a3030eb86e",
    "runtime_digest": "sha256:f63df4c43029fe91db370609c0b40a1e3585cebd06e3e9637d93a9a3030eb86e",
    "fixed_control_digest": "sha256:05453dd1d9aba27c2c487613141596868409b4d03247647f7d66cb0b36f321b8",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "runs": 2,
  "idempotent": true,
  "script_exit_code": 1,
  "exit_code_meaning": "1 = alternate trigger reproduced on vulnerable 19.3.1 only; no bypass on fixed 19.3.2",
  "proof_artifacts": [
    "vuln_variant/artifacts/http/vuln_t1_commits_json.txt",
    "vuln_variant/artifacts/http/vuln_t2_commits_slash.txt",
    "vuln_variant/artifacts/http/vuln_t3_files_post_slash.txt",
    "vuln_variant/artifacts/http/vuln_t4_files_put_slash.txt",
    "vuln_variant/artifacts/http/vuln_t5_files_post_plain.txt",
    "vuln_variant/artifacts/http/vuln_t6_files_post_json.txt",
    "vuln_variant/artifacts/http/vuln_t7_commits_authorize.txt",
    "vuln_variant/artifacts/http/vuln_t8_files_authorize.txt",
    "vuln_variant/artifacts/http/fixed_t1_commits_json.txt",
    "vuln_variant/artifacts/http/fixed_t2_commits_slash.txt",
    "vuln_variant/artifacts/http/fixed_t3_files_post_slash.txt",
    "vuln_variant/artifacts/http/fixed_t4_files_put_slash.txt",
    "vuln_variant/artifacts/http/fixed_t5_files_post_plain.txt",
    "vuln_variant/artifacts/http/fixed_t6_files_post_json.txt",
    "vuln_variant/artifacts/http/fixed_t7_commits_authorize.txt",
    "vuln_variant/artifacts/http/fixed_t8_files_authorize.txt",
    "vuln_variant/artifacts/http/target_binding_vuln.txt",
    "vuln_variant/artifacts/http/target_binding_fixed.txt"
  ],
  "key_observations": {
    "vuln_t3_files_post_slash_echo": true,
    "vuln_t4_files_put_slash_echo": true,
    "vuln_t2_commits_trailing_slash_echo": true,
    "vuln_t1_commits_json_echo": true,
    "vuln_t5_files_plain_echo": false,
    "fixed_all_echo": false,
    "fixed_all_status": 401,
    "vuln_authorize_probes_status": 500,
    "fixed_authorize_probes_status": 401
  },
  "notes": "Canary: /tmp/canary_85706v.txt = PRUVA85706_VCANARY_VC1_d41d8cd98f00_PCTBYTE_%zz_END planted in each container; full content echoed in vulnerable 400 responses for t1-t4; controls (t5/t6, workhorse-intercepted) return 'branch is required' with no read; fixed build returns 401 for every entry point. Rootless-docker storage pool is a 12G tmpfs - the reproducer removes containers with -v and prunes volumes to keep the pool from filling."
}
