{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "1370d2204076795d415d530fead7b08c9d0239caf07abd2010c012577fbc7332",
    "authored_runtime_manifest_sha256": "6005c41d0f4d6706aa149e568b580ae11cd82cd85477b3608abc42250a887ff2",
    "authored_verdict_sha256": "362ef88c2224651725a636729119dc39f03d647fe01512145b677f76c21778c4",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "719bc143-ab2e-4cca-a3f0-545ace487f03",
    "f2fe7116-d11d-48dd-b034-f1cee55acd33"
  ],
  "attacker_controlled_input": "After the guest primes a regular directfs dentry, a host-side attacker atomically RENAME_EXCHANGEs its backing name with a selected host block-device node while guest O_TRUNC opens race revalidation against openHandle's open-by-name.",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "sandbox_escape",
  "claimed_surface": "local_only",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "sandbox_escape",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "production runsc --directfs=true --platform=systrap guest open(/race/target, O_RDWR|O_TRUNC) -> directfsInode.openHandle() unchecked openat() -> gofer preadv2/pwritev2 on the swapped host loop block descriptor",
  "validated_surface": "local_only"
}
