Exemple
github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99: profile.Parse, profile.Profile.CheckValid, profile.Profile.Write
Échantillon vérifié pour golang github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99: profile.Parse, profile.Profile.CheckValid, profile.Profile.Write.…
sha256:13f650cc7e8d0b69c1136d4a7a0273376fafecbb066012e07ab3f523cdcfd1bb
Ce réseau offre une seule chose : un échantillon qui compile. Il l'a exécuté dans un bac à sable et conservé le reçu signé. Il ne note rien et ne garantit rien : si le même code compile chez vous, il ne l'a pas mesuré.
Combien de clés de signature distinctes ont déposé un reçu de contrat réussi. Une seule, c'est l'auteur ; plus d'une signifie que quelqu'un d'autre l'a compilé aussi. Une clé est auto-générée sans identité enregistrée derrière, donc on compte des clés, pas des personnes.
MIT-0
Preuves d'exécution
L'environnement déclaré et les exécutions signées sont séparés, pour que vous voyiez exactement ce que cet échantillon a exécuté et où.
- Base de preuve
- Contrat signé réussi
- Reçus de vérification
- 1
- Clés de signature qui l’ont compilé
- 1
Environnement déclaré
go 1.26 linux 24 · ubuntu · glibc 2.39 x64 go 1.26 go go 1
Environnements des exécutions de vérification
| Environnement | Contrat | Étapes | Exécution |
|---|---|---|---|
| go 1.26 · linux debian/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1golang:1.26@sha256:e30143be198a… |
2026-09-19 |
Cas
HOW- Objectif
- verify pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99
- Symboles
-
- github.com/google/pprof/profile.Parse
- github.com/google/pprof/profile.Profile.CheckValid
- github.com/google/pprof/profile.Profile.Write
- Environnement
- go 1.26.6
- Créé
- 2026-09-19T21:16:51Z
Contrat
- profile.Profile creates and validates a structured cpu/memory profile with CheckValid
- profile.Profile.Write serializes the profile into gzip-compressed protobuf format
- profile.Parse parses serialized profile data and restores samples, locations, and functions
Fichiers
- PROMPT.md
- csx.json
- go.mod
- go.sum
- sample.go
- spec.json
- test/contract.go
Code source
Clean-room public code sample — generation instructions
Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.
A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.
Goal: verify pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99
Kind: HOW
Use EXACTLY these public packages and versions:
- pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99
Required runtime conditions:
- ecosystem: golang
- language: go
- packageManager: go@1.26.6
- runtime: go@1.26.6
Rules:
- One focused purpose; the smallest project that proves the goal.
- Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
- Pin every dependency with a lockfile so resolution is reproducible.
- No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
- No personal names, emails, company names, or project identifiers of any kind.
- No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
- Keep it under 200 files and 256KB packed.
{"case":{"caseId":"case:sha256:6f54c592f33e4a1cb2bd07175142e5063dcf5c4bacecac80e2585ea676ec0bfe","contract":["profile.Profile creates and validates a structured cpu/memory profile with CheckValid","profile.Profile.Write serializes the profile into gzip-compressed protobuf format","profile.Parse parses serialized profile data and restores samples, locations, and functions"],"goal":"verify pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99","kind":"HOW","packages":["pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99"],"schemaVersion":1,"symbols":["github.com/google/pprof/profile.Parse","github.com/google/pprof/profile.Profile.CheckValid","github.com/google/pprof/profile.Profile.Write"]},"contractCommand":["go","run","./test"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"golang","language":"go","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"go","packageManagerVersion":"1.26.6","runtime":"go","runtimeVersion":"1.26.6","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99"],"schemaVersion":1,"subject":"pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99","symbols":["github.com/google/pprof/profile.Parse","github.com/google/pprof/profile.Profile.CheckValid","github.com/google/pprof/profile.Profile.Write"],"verifierAdapter":"golang@1"}
module sample
go 1.26.6
require github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99
github.com/chzyer/logex v1.1.10/go.mod h1:+Ywpsq7O8HXn0nuIou7OrIPyXbp3wmkHB+jjWRnGsAI=
github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e/go.mod h1:nSuG5e5PlCu98SY8svDHJxuZscDgtXS6KTTbou5AhLI=
github.com/chzyer/test v0.0.0-20180213035817-a1ea475d72b1/go.mod h1:Q3SI9o4m/ZMnBNeIyt5eFwwo7qiLfzFZmjNmxjkiQlU=
github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99 h1:Ak8CrdlwwXwAZxzS66vgPt4U8yUZX7JwLvVR58FN5jM=
github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM=
github.com/ianlancetaylor/demangle v0.0.0-20181102032728-5e5cf60278f6/go.mod h1:aSSvb/t6k1mPoxDqO4vJh6VOCGPwU4O0C2/Eqndh1Sc=
golang.org/x/sys v0.0.0-20191204072324-ce4227a45e2e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
package sample
import (
"bytes"
"io"
"github.com/google/pprof/profile"
)
// BuildSampleProfile constructs a valid profile with sample type, functions, locations, and samples.
func BuildSampleProfile(functionName, filename string, line int64, sampleCount, cpuNanos int64) (*profile.Profile, error) {
p := &profile.Profile{
SampleType: []*profile.ValueType{
{Type: "samples", Unit: "count"},
{Type: "cpu", Unit: "nanoseconds"},
},
PeriodType: &profile.ValueType{Type: "cpu", Unit: "nanoseconds"},
Period: 10000000,
}
fn := &profile.Function{
ID: 1,
Name: functionName,
SystemName: functionName,
Filename: filename,
StartLine: line,
}
p.Function = []*profile.Function{fn}
loc := &profile.Location{
ID: 1,
Line: []profile.Line{
{
Function: fn,
Line: line + 5,
},
},
}
p.Location = []*profile.Location{loc}
s := &profile.Sample{
Location: []*profile.Location{loc},
Value: []int64{sampleCount, cpuNanos},
}
p.Sample = []*profile.Sample{s}
if err := p.CheckValid(); err != nil {
return nil, err
}
return p, nil
}
// SerializeProfile writes a Profile to an io.Writer in standard pprof format.
func SerializeProfile(p *profile.Profile, w io.Writer) error {
return p.Write(w)
}
// ParseProfile parses a serialized pprof stream from an io.Reader.
func ParseProfile(r io.Reader) (*profile.Profile, error) {
return profile.Parse(r)
}
// EncodeAndDecode serializes and re-parses a profile, returning the decoded profile.
func EncodeAndDecode(p *profile.Profile) (*profile.Profile, error) {
var buf bytes.Buffer
if err := p.Write(&buf); err != nil {
return nil, err
}
return profile.Parse(&buf)
}
{
"schemaVersion": 1,
"goal": "verify pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99",
"kind": "HOW",
"packages": [
"pkg:golang/github.com/google/pprof@v0.0.0-20200708004538-1a94d8640e99"
],
"runtimeConditions": {
"ecosystem": "golang",
"language": "go",
"packageManager": "go@1.26.6",
"runtime": "go@1.26.6"
}
}
package main
import (
"bytes"
"fmt"
"os"
"github.com/google/pprof/profile"
"sample"
)
func main() {
// Assertion 1: profile.Profile creates and validates a structured cpu/memory profile with CheckValid
p, err := sample.BuildSampleProfile("worker.processTask", "worker.go", 10, 5, 50000000)
if err != nil {
fmt.Fprintf(os.Stderr, "BuildSampleProfile failed: %v\n", err)
os.Exit(1)
}
var _ *profile.Profile = p
if err := p.CheckValid(); err != nil {
fmt.Fprintf(os.Stderr, "p.CheckValid failed: %v\n", err)
os.Exit(1)
}
if len(p.Sample) != 1 {
fmt.Fprintf(os.Stderr, "expected 1 sample, got %d\n", len(p.Sample))
os.Exit(1)
}
// Assertion 2: profile.Profile.Write serializes the profile into gzip-compressed protobuf format
var buf bytes.Buffer
if err := p.Write(&buf); err != nil {
fmt.Fprintf(os.Stderr, "p.Write failed: %v\n", err)
os.Exit(1)
}
if buf.Len() == 0 {
fmt.Fprintf(os.Stderr, "serialized buffer is empty\n")
os.Exit(1)
}
// Assertion 3: profile.Parse parses serialized profile data and restores samples, locations, and functions
parsed, err := profile.Parse(&buf)
if err != nil {
fmt.Fprintf(os.Stderr, "profile.Parse failed: %v\n", err)
os.Exit(1)
}
if err := parsed.CheckValid(); err != nil {
fmt.Fprintf(os.Stderr, "parsed profile CheckValid failed: %v\n", err)
os.Exit(1)
}
if len(parsed.Sample) != 1 {
fmt.Fprintf(os.Stderr, "expected 1 sample in parsed profile, got %d\n", len(parsed.Sample))
os.Exit(1)
}
if parsed.Sample[0].Value[0] != 5 || parsed.Sample[0].Value[1] != 50000000 {
fmt.Fprintf(os.Stderr, "parsed sample values mismatch: got %v, expected [5, 50000000]\n", parsed.Sample[0].Value)
os.Exit(1)
}
if len(parsed.Function) != 1 || parsed.Function[0].Name != "worker.processTask" {
fmt.Fprintf(os.Stderr, "parsed function mismatch\n")
os.Exit(1)
}
if len(parsed.Location) != 1 || len(parsed.Location[0].Line) != 1 || parsed.Location[0].Line[0].Line != 15 {
fmt.Fprintf(os.Stderr, "parsed location line mismatch\n")
os.Exit(1)
}
fmt.Println("All pprof profile contract assertions passed.")
}
Seeder d'origine
anonyme