CodeSampleX

Sample

verify hkdf.Expand in pkg:golang/golang.org/x/crypto@v0.20.0

sha256:c51e4f6f36c218e86de73e7cb99abf33cc6a8cd9aca7a44a32475a16399046d8

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26-alpine@sha256:28d89ee9cc0f…
2026-08-27

Case

HOW
Goal
verify hkdf.Expand in pkg:golang/golang.org/x/crypto@v0.20.0
Packages
Symbols
  • hkdf.Expand
Created
2026-08-27T18:44:01Z

Contract

  1. hkdf.Expand returns an io.Reader expanding PRK into derived key stream with given hash and info
  2. hkdf.Expand matches RFC 5869 test vector 1 for SHA-256 HKDF-Expand with pre-extracted PRK
  3. hkdf.Expand produces identical key stream as hkdf.New when given extracted PRK
  4. hkdf.Expand matches RFC 5869 test vector 2 with longer PRK and info
  5. hkdf.Expand accepts nil info and empty byte slice info yielding identical derived output
  6. hkdf.Expand supports multiple sequential Read calls consuming contiguous chunks of expanded key stream
  7. hkdf.Expand with different info strings produces cryptographically distinct derived keys from the same PRK
  8. hkdf.Expand works with different hash functions such as SHA-1, SHA-384 and SHA-512
  9. hkdf.Expand returns error when requested read length exceeds RFC 5869 maximum expansion limit of 255 * hash.Size

Files

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

Download the source artifact (tar.gz)

Origin Seeder

anonymous