CodeSampleX

Sample

Resolve server certificates dynamically via ResolvesServerCertUsingSni validating strict DNS hostname mapping, certificate SAN enforcement, case-insensitivity, and fallback rejection

sha256:61ae3657305e22aefe406fd7c8abd3f00926b2f45287d1ebf2898bfbb4cf8964

PUBLISHED L3_CONTRACT_PASS MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS

Declared environment

Execution context
rust
Operating system
linux
Architecture
x64
Runtime
rust
Language
rust
Package manager
cargo

Verification-run environments

Execution context
rust 1
Operating system
linux alpine · musl
Architecture
x64
Runtime
rust 1
Language
rust
Package manager
cargo
Execution
container · docker

CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · cargo@1 · 2026-08-17

Case

Goal
Resolve server certificates dynamically via ResolvesServerCertUsingSni validating strict DNS hostname mapping, certificate SAN enforcement, case-insensitivity, and fallback rejection HOW
Packages
rustls 0.23.43
Environment
rust
Created
2026-08-17T19:13:32Z

Commonly assumed

ResolvesServerCertUsingSni accepts wildcard domain patterns or IP literals as registration keys and serves any mapped certificate without validating its Subject Alternative Names against the domain key

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the source artifact (tar.gz)

Origin Seeder

csx-seed

Verification receipts