{
  "name": "cve_2025_guards_2026-09",
  "note": "S06 candidate 5: two shipped 2025 CVE fixes in the linear fragment, transcribed verbatim and decided by formal/check_upstream_guard_2025.py (z3 obligations + CBMC 6.10 twin runs on the real C shapes) before anyone looked. Predictions: libxml2 xmlBuildQName (CVE-2025-6021, ad346c9a) is sound only under the stated strlen-realism precondition lenp <= SIZE_MAX-1 (counterexample lenp == SIZE_MAX); OpenSSL kek_unwrap_key (CVE-2025-9230, 9c462be2) is sound unconditionally and tight because the fix IS the bounds predicate, while the pre-fix check is unsound. Run: make upstream-guard-2025. Bars derived by scripts/s06_bar.py cve_2025_guards_2026-09.",
  "predicted": {
    "bar_both_fix_refs_verified_online": true,
    "bar_libxml2_cbmc_guarded_successful": true,
    "bar_libxml2_cbmc_unguarded_failed": true,
    "bar_libxml2_guard_distinct_from_in_bounds": true,
    "bar_libxml2_sound_under_stated_precondition": true,
    "bar_openssl_cbmc_guarded_successful": true,
    "bar_openssl_cbmc_prefix_guard_failed": true,
    "bar_openssl_cbmc_unguarded_failed": true,
    "bar_openssl_fixed_guard_sound_unconditionally": true,
    "bar_openssl_fixed_guard_tight": true,
    "bar_openssl_prefix_guard_unsound": true,
    "predicted_libxml2_cbmc_no_precondition_failed": true,
    "predicted_libxml2_not_sound_unconditionally": true,
    "predicted_openssl_fix_is_the_bounds_predicate": true
  },
  "sha256": "10d6eb3febfe0eb9eb76d81feac26e69ec93b681a045af70b21e25325e4e225e"
}
