CodeSampleX

Sample

csv 3.3.2: Show that CSV.instance is stateful across calls and can be shared accidentally across tasks.

Verified sample for gem csv 3.3.2: Show that CSV.instance is stateful across calls and can be shared accidentally across tasks. The contract ran on ruby 3 …

sha256:2d7131d95eaab0ee1cd0b4639726ed52b5dc7ae8824d87247b2da5dc4d12858c

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
1
Declared environment ruby linux x64 ruby ruby rubygems

Verification-run environments

Environment Contract Stages Run
ruby 3 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-16
ruby 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 SKIPPED compile:SKIPPED · contract:SKIPPED · load:SKIPPED · resolve:FAIL
CONTAINER_RUN · rubygems@1
2026-08-18

Case

HOW
Goal
Show that CSV.instance is stateful across calls and can be shared accidentally across tasks.
Packages
Symbols
  • CSV.instance
Environment
ruby
Created
2026-08-16T15:31:10Z

Contract

  1. CSV.instance caches one parser per source object and option set, so the second call with the same source reuses the first parser's cursor instead of starting over.
  2. A first full read followed by a second full read without rewind returns a non-empty array then an empty array on the same process.
  3. Two task-local references created with CSV.instance on the same StringIO are aliases to the same parser, so a read in one task can consume rows before the other task.

Files

  • Gemfile
  • NOTES.md
  • csx.json
  • test/contract.rb

Download the source artifact (tar.gz)

Origin Seeder

csx-seed