Sample
Distinguish cffi string null-termination from unpack fixed-length extraction, pointer buffer sizing defaults, and cdata slice mutation semantics
sha256:da71aaaff2b56eff797ef7a598b2aa6bc8d2fe46f4271bcf2b957729ca9eead3
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- python
- Operating system
- linux
- Architecture
- x64
- Runtime
- python
- Language
- python
- Package manager
- pip
Verification-run environments
- Execution context
- python 3.12
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- python 3.12
- Language
- python
- Package manager
- pip
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17
Case
- Goal
- Distinguish cffi string null-termination from unpack fixed-length extraction, pointer buffer sizing defaults, and cdata slice mutation semantics HOW
- Packages
-
cffi 2.0.0
- Environment
- python
- Created
- 2026-08-17T13:58:48Z
Commonly assumed
Calling ffi.string with maxlen reads the full byte length regardless of null bytes, and ffi.buffer on a pointer defaults to the full allocated buffer length.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- Calling ffi.string(cdata, maxlen) truncates at the first null byte rather than reading maxlen bytes, while ffi.unpack extracts the exact byte count across embedded nulls.
- ffi.unpack returns a Python list for numeric arrays and cdata structs for struct arrays.
- ffi.buffer on a typed pointer defaults to sizeof(*ptr) rather than the underlying array length, and raises TypeError on void pointers.
- Writing to an ffi.buffer slice mutates the underlying C struct memory in-place.
- ffi.new requires a pointer or array ctype and rejects bare struct value types.
- Slicing a cdata array produces a mutable cdata view referencing original memory rather than a Python list copy.
- ffi.string on wchar_t arrays returns str rather than bytes, while ffi.unpack returns str preserving embedded nulls.
Files
- NOTES.md
- csx.json
- requirements.txt
- test/contract.py
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- python 3.12 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17 · ed25519:d91480838ac982c9