CodeSampleX

示例

github.com/quic-go/go-ossfuzz-seeds v0.1.0: CorpusEntry

已验证示例 — golang github.com/quic-go/go-ossfuzz-seeds v0.1.0: CorpusEntry. contract 在 go 1.26 · linux debian/x64 · docker 上运行并通过.

sha256:6f8170d08d71c8edc3af62b2f473c3403ad2c7113eaa5245958848e479710020

本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。 提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。 MIT-0

执行证据

声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。

证据依据
签名契约通过
验证回执
1
构建过它的签名密钥
1
声明的环境 go 1.26 linux 24 · ubuntu · glibc 2.39 x64 go 1.26 go 1.26 go 1

验证运行环境

环境 契约 阶段 运行日期
go 1.26 · linux debian/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26@sha256:e30143be198a…
2026-09-05

案例

HOW
目标
verify pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0
包
符号
  • github.com/quic-go/go-ossfuzz-seeds.CorpusEntry
环境
go 1.26.6
创建时间
2026-09-05T12:42:39Z

契约

  1. CorpusEntry encodes fixed-size arguments in big-endian binary format
  2. CorpusEntry encodes multiple dynamic string arguments with size weights prefixing the payloads
  3. CorpusEntry encodes mixed fixed and dynamic arguments into a single corpus entry
  4. CorpusEntry returns an error for unsupported argument types
  5. CorpusEntry returns ErrUnencodableDynamicCorpusArgs when dynamic argument lengths cannot be represented

文件

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

下载源代码构件 (tar.gz)

源代码

PROMPT.md
Clean-room public code sample — generation instructions

Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.

A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.

Goal: verify pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0
Kind: HOW

Use EXACTLY these public packages and versions:
  - pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0
Demonstrate these symbols/APIs:
  - github.com/quic-go/go-ossfuzz-seeds.CorpusEntry

Rules:
  - One focused purpose; the smallest project that proves the goal.
  - Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
  - Pin every dependency with a lockfile so resolution is reproducible.
  - No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
  - No personal names, emails, company names, or project identifiers of any kind.
  - No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
  - Keep it under 200 files and 256KB packed.
csx.json
{"case":{"caseId":"case:sha256:b60ed7e978c259234f2a99395982756a39b456999191ee63528069d6eccb5a98","contract":["CorpusEntry encodes fixed-size arguments in big-endian binary format","CorpusEntry encodes multiple dynamic string arguments with size weights prefixing the payloads","CorpusEntry encodes mixed fixed and dynamic arguments into a single corpus entry","CorpusEntry returns an error for unsupported argument types","CorpusEntry returns ErrUnencodableDynamicCorpusArgs when dynamic argument lengths cannot be represented"],"goal":"verify pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0","kind":"HOW","packages":["pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"],"schemaVersion":1,"symbols":["github.com/quic-go/go-ossfuzz-seeds.CorpusEntry"]},"contractCommand":["go","run","./test"],"environment":{"arch":"x64","compiler":"go","compilerVersion":"1.26.6","distro":"ubuntu","ecosystem":"golang","language":"go","languageVersion":"1.26.6","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"go","packageManagerVersion":"1.26.6","runtime":"go","runtimeVersion":"1.26.6","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"],"schemaVersion":1,"subject":"pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0","symbols":["github.com/quic-go/go-ossfuzz-seeds.CorpusEntry"],"verifierAdapter":"golang@1"}
go.mod
module example.com/sample

go 1.26.6

require github.com/quic-go/go-ossfuzz-seeds v0.1.0
go.sum
github.com/quic-go/go-ossfuzz-seeds v0.1.0 h1:APacT+iIaNF6fd8AGEiN3bT/Jtkd2jz4v4TzM7MFjy0=
github.com/quic-go/go-ossfuzz-seeds v0.1.0/go.mod h1:3IOHRbJIc+L6YKMwfDtJAM9Vj9k0YY4muhuyUYk5tbk=
main.go
package main

import (
	"fmt"
	"os"

	ossfuzzseeds "github.com/quic-go/go-ossfuzz-seeds"
)

func main() {
	// Encode seed arguments into raw OSS-Fuzz corpus format
	entry, err := ossfuzzseeds.CorpusEntry(uint8(1), "GET", []byte("/index.html"))
	if err != nil {
		fmt.Fprintf(os.Stderr, "CorpusEntry failed: %v\n", err)
		os.Exit(1)
	}

	fmt.Printf("Encoded corpus entry (%d bytes): %x\n", len(entry), entry)
}
spec.json
{
  "schemaVersion": 1,
  "goal": "verify pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0",
  "kind": "HOW",
  "packages": [
    "pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"
  ],
  "symbols": [
    "github.com/quic-go/go-ossfuzz-seeds.CorpusEntry"
  ]
}
test/contract.go
package main

import (
	"bytes"
	"errors"
	"fmt"
	"os"

	ossfuzzseeds "github.com/quic-go/go-ossfuzz-seeds"
)

func main() {
	if err := runContractTests(); err != nil {
		fmt.Fprintf(os.Stderr, "Contract assertion failed: %v\n", err)
		os.Exit(1)
	}
	fmt.Println("All contract assertions passed.")
}

func runContractTests() error {
	// Assertion 1: CorpusEntry encodes fixed-size arguments in big-endian binary format
	{
		entry, err := ossfuzzseeds.CorpusEntry(true, uint32(42))
		if err != nil {
			return fmt.Errorf("assertion 1 failed: %w", err)
		}
		expected := []byte{0x01, 0x00, 0x00, 0x00, 0x2a}
		if !bytes.Equal(entry, expected) {
			return fmt.Errorf("assertion 1 mismatch: got %x, want %x", entry, expected)
		}
	}

	// Assertion 2: CorpusEntry encodes multiple dynamic string arguments with size weights prefixing the payloads
	{
		entry, err := ossfuzzseeds.CorpusEntry("foo", "bar")
		if err != nil {
			return fmt.Errorf("assertion 2 failed: %w", err)
		}
		expected := []byte{0x03, 0x03, 'f', 'o', 'o', 'b', 'a', 'r'}
		if !bytes.Equal(entry, expected) {
			return fmt.Errorf("assertion 2 mismatch: got %x, want %x", entry, expected)
		}
	}

	// Assertion 3: CorpusEntry encodes mixed fixed and dynamic arguments into a single corpus entry
	{
		entry, err := ossfuzzseeds.CorpusEntry(uint8(1), "GET", []byte("/index.html"))
		if err != nil {
			return fmt.Errorf("assertion 3 failed: %w", err)
		}
		expected := append([]byte{0x01, 0x03, 0x0b}, append([]byte("GET"), []byte("/index.html")...)...)
		if !bytes.Equal(entry, expected) {
			return fmt.Errorf("assertion 3 mismatch: got %x, want %x", entry, expected)
		}
	}

	// Assertion 4: CorpusEntry returns an error for unsupported argument types
	{
		_, err := ossfuzzseeds.CorpusEntry(struct{}{})
		if err == nil {
			return errors.New("assertion 4 failed: expected error for unsupported type struct{}, got nil")
		}
	}

	// Assertion 5: CorpusEntry returns ErrUnencodableDynamicCorpusArgs when dynamic argument lengths cannot be represented
	{
		_, err := ossfuzzseeds.CorpusEntry(make([]byte, 1), make([]byte, 1), make([]byte, 100000))
		if err == nil {
			return errors.New("assertion 5 failed: expected error for unencodable dynamic lengths, got nil")
		}
		if !errors.Is(err, ossfuzzseeds.ErrUnencodableDynamicCorpusArgs) {
			return fmt.Errorf("assertion 5 failed: expected ErrUnencodableDynamicCorpusArgs, got %w", err)
		}
	}

	return nil
}

原始种子者

匿名