[repro 08:34:47] OTP source/build tree: /workspace/bundle/artifacts/otp [repro 08:34:47] vulnerable commit: e9f49f57cef6e38fd13c4b0cee1eb5509ef471e8 ; fixed commit: a3adf63078438c86527d704e23282b7721d8ca12 [repro 08:34:47] building OTP/inets at e9f49f57cef6e38fd13c4b0cee1eb5509ef471e8 ... [repro 08:34:49] verified: vulnerable checkout LACKS the fix hunk (bare catch present) 241: PROCESSED = (catch Module:Function([Data | Args])), [repro 08:34:49] === attempt vulnerable #1: starting fresh httpd node === [repro 08:34:49] attempt vulnerable #1: httpd on port 34773 (vsn=9.3.2.6) [healthcheck] status=closed first-line='HTTP/1.1 200 OK' [midpark_legit] status=closed first-line='HTTP/1.1 200 OK' [census t=3] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=45] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=95] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=162] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [park] after 165s observation: socket status=timeout recv=b'' [exhaustion] parked=300/300; pool_full=True (census=150 after 0.0s); legit status=closed first-line='HTTP/1.1 503 Service Unavailable' [recheck after 25s] legit status=closed first-line='HTTP/1.1 503 Service Unavailable' census=150 [after-close] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [done] wrote /workspace/bundle/repro/evidence/vulnerable_attempt1/result.json [repro 08:38:06] attempt vulnerable #1: complete (node stopped) bundle/repro/reproduction_steps.sh: line 126: 38005 Killed "$REPO/bin/erl" -noshell -pa "$REPRO_DIR/harness" -eval "server_node:main(\"$WD\")" > "$WD/stdout.log" 2>&1 [repro 08:38:06] === attempt vulnerable #2: starting fresh httpd node === [repro 08:38:06] attempt vulnerable #2: httpd on port 45439 (vsn=9.3.2.6) [healthcheck] status=closed first-line='HTTP/1.1 200 OK' [midpark_legit] status=closed first-line='HTTP/1.1 200 OK' [census t=3] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=45] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=95] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [census t=162] handlers=1 detail=<0.103.0>:[{message_queue_len,0},{status,waiting}] [park] after 165s observation: socket status=timeout recv=b'' [exhaustion] parked=300/300; pool_full=True (census=150 after 0.0s); legit status=closed first-line='HTTP/1.1 503 Service Unavailable' [recheck after 25s] legit status=closed first-line='HTTP/1.1 503 Service Unavailable' census=150 [after-close] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [done] wrote /workspace/bundle/repro/evidence/vulnerable_attempt2/result.json [repro 08:41:22] attempt vulnerable #2: complete (node stopped) bundle/repro/reproduction_steps.sh: line 126: 38573 Killed "$REPO/bin/erl" -noshell -pa "$REPRO_DIR/harness" -eval "server_node:main(\"$WD\")" > "$WD/stdout.log" 2>&1 [repro 08:41:22] building OTP/inets at a3adf63078438c86527d704e23282b7721d8ca12 ... [repro 08:41:23] verified: fixed checkout CONTAINS the fix hunk 287: catch throw:{error, Error} when Module =:= http_chunk -> [repro 08:41:23] === attempt fixed #1: starting fresh httpd node === [repro 08:41:24] attempt fixed #1: httpd on port 42591 (vsn=9.3.2.6) [healthcheck] status=closed first-line='HTTP/1.1 200 OK' [midpark_legit] status=closed first-line='HTTP/1.1 200 OK' [census t=3] handlers=0 detail= [census t=27] handlers=0 detail= [park] after 30s observation: socket status=closed recv=b'HTTP/1.1 400 Bad Request\r\nDate: Wed, 02 Sep 2026 08:41:24 GMT\r\nServer: inets/9.3' [exhaustion] parked=300/300; pool_full=None (census=None after 2.0s); legit status=closed first-line='HTTP/1.1 200 OK' [recheck after 25s] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [after-close] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [done] wrote /workspace/bundle/repro/evidence/fixed_attempt1/result.json [repro 08:42:26] attempt fixed #1: complete (node stopped) bundle/repro/reproduction_steps.sh: line 126: 39517 Killed "$REPO/bin/erl" -noshell -pa "$REPRO_DIR/harness" -eval "server_node:main(\"$WD\")" > "$WD/stdout.log" 2>&1 [repro 08:42:26] === attempt fixed #2: starting fresh httpd node === [repro 08:42:26] attempt fixed #2: httpd on port 40617 (vsn=9.3.2.6) [healthcheck] status=closed first-line='HTTP/1.1 200 OK' [midpark_legit] status=closed first-line='HTTP/1.1 200 OK' [census t=3] handlers=0 detail= [census t=27] handlers=0 detail= [park] after 30s observation: socket status=closed recv=b'HTTP/1.1 400 Bad Request\r\nDate: Wed, 02 Sep 2026 08:42:27 GMT\r\nServer: inets/9.3' [exhaustion] parked=300/300; pool_full=None (census=None after 2.0s); legit status=closed first-line='HTTP/1.1 200 OK' [recheck after 25s] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [after-close] legit status=closed first-line='HTTP/1.1 200 OK' census=0 [done] wrote /workspace/bundle/repro/evidence/fixed_attempt2/result.json [repro 08:43:28] attempt fixed #2: complete (node stopped) bundle/repro/reproduction_steps.sh: line 126: 39877 Killed "$REPO/bin/erl" -noshell -pa "$REPRO_DIR/harness" -eval "server_node:main(\"$WD\")" > "$WD/stdout.log" 2>&1 { "vulnerable_attempts": [ true, true ], "fixed_attempts": [ true, true ], "details": { "vulnerable_attempt1": { "healthcheck_200": true, "park_observed_seconds": true, "worker_parked": true, "worker_same_pid_at_start_and_end": true, "parked_socket_silent": true, "midpark_legit_200": true, "exhaustion_pool_full_observed": true, "exhaustion_wave_delivered": true, "exhausted_census_pool_full": true, "legit_denied_after_exhaustion": true, "legit_denied_firstline": "HTTP/1.1 503 Service Unavailable", "legit_still_denied_after_wait": true, "server_recovers_after_attacker_disconnect": true }, "vulnerable_attempt2": { "healthcheck_200": true, "park_observed_seconds": true, "worker_parked": true, "worker_same_pid_at_start_and_end": true, "parked_socket_silent": true, "midpark_legit_200": true, "exhaustion_pool_full_observed": true, "exhaustion_wave_delivered": true, "exhausted_census_pool_full": true, "legit_denied_after_exhaustion": true, "legit_denied_firstline": "HTTP/1.1 503 Service Unavailable", "legit_still_denied_after_wait": true, "server_recovers_after_attacker_disconnect": true }, "fixed_attempt1": { "healthcheck_200": true, "bad_chunk_gets_400": true, "connection_closed_by_server": true, "worker_reclaimed_census_0": true, "exhaustion_cannot_deny_service": true, "legit_still_200_after_wait": true }, "fixed_attempt2": { "healthcheck_200": true, "bad_chunk_gets_400": true, "connection_closed_by_server": true, "worker_reclaimed_census_0": true, "exhaustion_cannot_deny_service": true, "legit_still_200_after_wait": true } }, "pass": true } [repro 08:43:28] evaluation rc=0 wrote /workspace/bundle/repro/runtime_manifest.json [repro 08:43:28] updated cache manifest /pruva/project-cache/.pruva/cache_manifest.json [repro 08:43:28] RESULT: CVE-2026-69664 CONFIRMED on vulnerable build; fixed build fails closed