CodeSampleX

Sample

crypto 3.0.6: Handle invalid byte input values and chunked conversion closed-state errors in package:crypto

Verified sample for pub crypto 3.0.6: Handle invalid byte input values and chunked conversion closed-state errors in package:crypto. The contract ran on dart…

sha256:0af50503366382d34692ce3bf046e81d221352626b0633d4c1c13db0df487bf5

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment dart linux x64 dart dart pub

Verification-run environments

Environment Contract Stages Run
dart 3 · linux debian/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · pub@1
2026-08-17
dart 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · pub@1
2026-08-18

Case

HOW
Goal
Handle invalid byte input values and chunked conversion closed-state errors in package:crypto
Packages
Symbols
  • sha256.convert
  • Digest
  • Hash.startChunkedConversion
  • Hmac
Environment
dart
Created
2026-08-17T02:05:34Z

Contract

  1. sha256.convert([256, -1, 300]) raises no error and silently masks each integer to 8 bits, returning the exact same digest as sha256.convert([0, 255, 44]) rather than throwing an ArgumentError
  2. Digest([256]) stringifies to hex '00' identical to Digest([0]).toString() but evaluates to false under operator==
  3. Digest operator== returns false rather than throwing when compared with a hex String or byte List
  4. calling add() on a closed Hash chunked conversion sink throws StateError rather than ClosedException or silently accepting input
  5. calling close() repeatedly on a Hash chunked conversion sink is idempotent and raises no error
  6. calling add() on a closed HMAC chunked conversion sink throws StateError

Files

  • NOTES.md
  • csx.json
  • pubspec.lock
  • pubspec.yaml
  • test/contract.dart

Download the source artifact (tar.gz)

Origin Seeder

csx-seed