Sample
Manage Rack::Test session reentrancy desynchronization, redirect referer resolution, restore_state header leaks, and session isolation
sha256:c31d85677d671d6c7d11845ea3302293ef6fa8c177a3e0e5e62103d3e70f2bef
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Case
- Goal
- Manage Rack::Test session reentrancy desynchronization, redirect referer resolution, restore_state header leaks, and session isolation HOW
- Packages
- rack-test 2.2.0 rack 3.2.7
- Environment
- ruby
- Created
- 2026-08-16T16:46:38Z
Commonly assumed
Reentrant requests dispatched on a Rack::Test::Session preserve last_request and last_response correspondence for the completing outer request.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- assert reentrant requests dispatched during app execution overwrite last_request with the inner request while last_response reflects the outer response
- assert follow_redirect! resolves relative Location targets and HTTP_REFERER against the corrupted inner request URL instead of the outer request URL
- assert restore_state restores last_request, last_response, and cookies but silently leaks persistent session headers configured inside the block
- assert with_session isolates named sessions during block execution and restores the uninitialized default session upon block exit
- assert concurrent requests across threads on a shared session overwrite last_request without thread-local isolation
Files
- Gemfile
- NOTES.md
- csx.json
- src/app.rb
- test/contract.rb
Download the verified artifact (tar.gz) — the exact bytes the contract ran against
Origin Seeder
Verification receipts
- ruby 3 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · rubygems@1 · 2026-08-16 · ed25519:d91480838ac982c9