Sample
Pin MarkupSafe byte escaping semantics, format_map dynamic mapping auto-escaping, subclass type preservation across string operations, and __radd__ coercion.
sha256:7f582cabdd480d1750a50f39dbad6a382681185b4bfaa4e9528393f75c2ff245
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- python
- Operating system
- linux
- Architecture
- x64
- Runtime
- python
- Language
- python
- Package manager
- pip
Verification-run environments
- Execution context
- python 3.12
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- python 3.12
- Language
- python
- Package manager
- pip
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17
Case
- Goal
- Pin MarkupSafe byte escaping semantics, format_map dynamic mapping auto-escaping, subclass type preservation across string operations, and __radd__ coercion. HOW
- Packages
-
markupsafe 3.0.3
- Environment
- python
- Created
- 2026-08-17T19:51:17Z
Commonly assumed
escape() decodes UTF-8 byte sequences before HTML-escaping them, and str.join() escapes raw strings when concatenating with Markup elements.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- escape() converts bytes objects via str() to their literal repr 'b\'...\'' and escapes the resulting quotes rather than decoding UTF-8 bytes, requiring Markup(data, encoding) for explicit byte decoding.
- Markup.format_map() queries Mapping instances dynamically without requiring keyword unpacking, auto-escaping plain string values while preserving Markup instances.
- Markup subclasses preserve their custom subtype across escape classmethods, binary additions, partitions, splits, and case transformations.
- Markup.__radd__ auto-escapes left-hand plain string operands during concatenation, whereas str.join returns an unescaped plain str.
- Markup.replace matches search targets literally against the internal escaped representation and auto-escapes plain string replacement arguments.
Files
- NOTES.md
- csx.json
- requirements.txt
- src/__init__.py
- src/template_engine.py
- test/contract.py
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- python 3.12 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17 · ed25519:d91480838ac982c9