{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "e48b1980262019f09a8e4f807cbf70bd0f8d701d0db108689fb11cb4469370a8",
    "authored_runtime_manifest_sha256": "53af51ac00ed2efda583bd133e54d32628fa348aeea70018cc17ecfa3ffaac0d",
    "authored_verdict_sha256": "e495eb2f54cced6ab2e67056cfb0445a7827e6fd26f9d76290c9b0c1f88106d6",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Docker-driver job submitted via POST /v1/jobs: prestart task plants symlink /alloc/escape-root -> / in the shared allocation directory; main task declares mounts = [{type=bind, source=../alloc/escape-root, target=/host-escape, readonly=false}] whose source is lexically contained in the allocation directory but resolves via the symlink to the host root",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "sandbox_escape",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "sandbox_escape",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Nomad HTTP API (POST /v1/jobs) -> scheduler -> client task runner -> drivers/docker toDockerMount()/containerBinds() lexical isParentPath containment check (volumes disabled) -> Docker daemon bind mount follows symlink -> host filesystem mounted read-write inside task container",
  "validated_surface": "api_remote"
}
