CodeSampleX

Sample

json 2.9.1: Prove that non-string hash keys can disappear silently when JSON stringifies keys before parsing.

Verified sample for gem json 2.9.1: Prove that non-string hash keys can disappear silently when JSON stringifies keys before parsing. The contract ran on…

sha256:ba97e97ecda15df826536164d19fb790db2821d0d91ae3dfb2f344205cfb43a0

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment ruby linux x64 ruby ruby bundler

Verification-run environments

Environment Contract Stages Run
ruby 3 · linux debian/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-17
ruby 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-18

Case

HOW
Goal
Prove that non-string hash keys can disappear silently when JSON stringifies keys before parsing.
Packages
Symbols
  • JSON.generate
  • JSON.parse
Environment
ruby
Created
2026-08-17T01:17:10Z

Contract

  1. JSON.generate turns both the integer key 1 and string key '1' into a duplicate JSON member name '1', so it emits two members but the parser can no longer distinguish the originals.
  2. JSON.parse(JSON.generate({1=>"num", "1"=>"str"})) returns {"1"=>"str"} because the second duplicate wins.
  3. JSON.parse(JSON.generate({1=>"num", "1"=>"str"}), symbolize_names: true) returns {"1":"str"} and still exposes only one key.

Files

  • Gemfile
  • Gemfile.lock
  • NOTES.md
  • csx.json
  • test/contract.rb

Download the source artifact (tar.gz)

Origin Seeder

csx-seed