示例
github.com/quic-go/go-ossfuzz-seeds v0.1.0: write OSS-Fuzz corpus entries using Helper and New
已验证示例 — golang github.com/quic-go/go-ossfuzz-seeds v0.1.0: write OSS-Fuzz corpus entries using Helper and New. contract 在 go 1.26 · linux debian/x64 · docker…
sha256:50fcabd7327d692a18651cdc43460f4cede7b1bb2b1f71cb0de8ed0980e6b49b
本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。
提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。
MIT-0
执行证据
声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。
- 证据依据
- 签名契约通过
- 验证回执
- 1
- 构建过它的签名密钥
- 1
声明的环境
go 1.26 linux 24 · ubuntu · glibc 2.39 x64 go 1.26 go 1.26 go 1
验证运行环境
| 环境 | 契约 | 阶段 | 运行日期 |
|---|---|---|---|
| go 1.26 · linux debian/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1golang:1.26@sha256:e30143be198a… |
2026-09-05 |
案例
HOW- 目标
- write OSS-Fuzz corpus entries using Helper and New
- 符号
-
- github.com/quic-go/go-ossfuzz-seeds.New
- 环境
- go 1.26.6
- 创建时间
- 2026-09-05T12:51:17Z
契约
- New creates a Helper that does not write files when FUZZ_CORPUS_DIR is unset
- New creates the destination directory when FUZZ_CORPUS_DIR is set
- Helper.Add writes encoded corpus entry named by SHA-256 prefix when FUZZ_CORPUS_DIR is set
- Helper.Add writes multiple distinct corpus entries for sequential seed additions
文件
- PROMPT.md
- csx.json
- go.mod
- go.sum
- main.go
- spec.json
- test/contract.go
源代码
Clean-room public code sample — generation instructions
Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.
A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.
Goal: write OSS-Fuzz corpus entries using Helper and New
Kind: HOW
Use EXACTLY these public packages and versions:
- pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0
Demonstrate these symbols/APIs:
- github.com/quic-go/go-ossfuzz-seeds.New
Rules:
- One focused purpose; the smallest project that proves the goal.
- Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
- Pin every dependency with a lockfile so resolution is reproducible.
- No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
- No personal names, emails, company names, or project identifiers of any kind.
- No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
- Keep it under 200 files and 256KB packed.
{"case":{"caseId":"case:sha256:afa3996c632e14959a6f323e70c1abd2062eb151ca3fce1fafd2b9a5176a61df","contract":["New creates a Helper that does not write files when FUZZ_CORPUS_DIR is unset","New creates the destination directory when FUZZ_CORPUS_DIR is set","Helper.Add writes encoded corpus entry named by SHA-256 prefix when FUZZ_CORPUS_DIR is set","Helper.Add writes multiple distinct corpus entries for sequential seed additions"],"goal":"write OSS-Fuzz corpus entries using Helper and New","kind":"HOW","packages":["pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"],"schemaVersion":1,"symbols":["github.com/quic-go/go-ossfuzz-seeds.New"]},"contractCommand":["go","run","./test"],"environment":{"arch":"x64","compiler":"go","compilerVersion":"1.26.6","distro":"ubuntu","ecosystem":"golang","language":"go","languageVersion":"1.26.6","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"go","packageManagerVersion":"1.26.6","runtime":"go","runtimeVersion":"1.26.6","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"],"schemaVersion":1,"subject":"pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0","symbols":["github.com/quic-go/go-ossfuzz-seeds.New"],"verifierAdapter":"golang@1"}
module example.com/sample
go 1.26.6
require github.com/quic-go/go-ossfuzz-seeds v0.1.0
github.com/quic-go/go-ossfuzz-seeds v0.1.0 h1:APacT+iIaNF6fd8AGEiN3bT/Jtkd2jz4v4TzM7MFjy0=
github.com/quic-go/go-ossfuzz-seeds v0.1.0/go.mod h1:3IOHRbJIc+L6YKMwfDtJAM9Vj9k0YY4muhuyUYk5tbk=
package main
import (
"fmt"
"os"
"testing"
ossfuzzseeds "github.com/quic-go/go-ossfuzz-seeds"
)
func main() {
testing.Init()
corpusDir := os.Getenv("FUZZ_CORPUS_DIR")
if corpusDir == "" {
corpusDir = "./corpus"
os.Setenv("FUZZ_CORPUS_DIR", corpusDir)
defer os.RemoveAll(corpusDir)
}
f := &testing.F{}
helper := ossfuzzseeds.New(f)
helper.Add(uint8(1), "GET", []byte("/index.html"))
fmt.Printf("Helper initialized and corpus entry registered in %s\n", corpusDir)
}
{
"schemaVersion": 1,
"goal": "write OSS-Fuzz corpus entries using Helper and New",
"kind": "HOW",
"packages": [
"pkg:golang/github.com/quic-go/go-ossfuzz-seeds@v0.1.0"
],
"symbols": [
"github.com/quic-go/go-ossfuzz-seeds.New"
]
}
package main
import (
"bytes"
"crypto/sha256"
"encoding/hex"
"fmt"
"os"
"path/filepath"
"testing"
ossfuzzseeds "github.com/quic-go/go-ossfuzz-seeds"
)
func main() {
testing.Init()
if err := runContractTests(); err != nil {
fmt.Fprintf(os.Stderr, "Contract assertion failed: %v\n", err)
os.Exit(1)
}
fmt.Println("All contract assertions passed.")
}
func sha256Prefix(data []byte) string {
h := sha256.Sum256(data)
return hex.EncodeToString(h[:8])
}
func runContractTests() error {
// Assertion 1: New creates a Helper that does not write files when FUZZ_CORPUS_DIR is unset
{
os.Unsetenv("FUZZ_CORPUS_DIR")
f := &testing.F{}
h := ossfuzzseeds.New(f)
if h == nil {
return fmt.Errorf("assertion 1 failed: New returned nil Helper")
}
h.Add(uint8(1), "test-no-write")
}
// Assertion 2: New creates the destination directory when FUZZ_CORPUS_DIR is set
tmpBase, err := os.MkdirTemp("", "csx-test-*")
if err != nil {
return fmt.Errorf("failed to create temp dir: %w", err)
}
defer os.RemoveAll(tmpBase)
targetDir := filepath.Join(tmpBase, "corpus", "nested")
{
os.Setenv("FUZZ_CORPUS_DIR", targetDir)
defer os.Unsetenv("FUZZ_CORPUS_DIR")
f := &testing.F{}
h := ossfuzzseeds.New(f)
if h == nil {
return fmt.Errorf("assertion 2 failed: New returned nil")
}
info, err := os.Stat(targetDir)
if err != nil {
return fmt.Errorf("assertion 2 failed: expected target directory %s to be created: %w", targetDir, err)
}
if !info.IsDir() {
return fmt.Errorf("assertion 2 failed: expected %s to be a directory", targetDir)
}
}
// Assertion 3: Helper.Add writes encoded corpus entry named by SHA-256 prefix when FUZZ_CORPUS_DIR is set
{
corpusDir := filepath.Join(tmpBase, "corpus-entries")
os.Setenv("FUZZ_CORPUS_DIR", corpusDir)
f := &testing.F{}
h := ossfuzzseeds.New(f)
seedArgs := []any{uint8(42), "seed-data", []byte{0xde, 0xad, 0xbe, 0xef}}
h.Add(seedArgs...)
expectedBytes, err := ossfuzzseeds.CorpusEntry(seedArgs...)
if err != nil {
return fmt.Errorf("assertion 3 failed: CorpusEntry failed: %w", err)
}
expectedFilename := sha256Prefix(expectedBytes)
filePath := filepath.Join(corpusDir, expectedFilename)
content, err := os.ReadFile(filePath)
if err != nil {
return fmt.Errorf("assertion 3 failed: failed reading corpus file %s: %w", filePath, err)
}
if !bytes.Equal(content, expectedBytes) {
return fmt.Errorf("assertion 3 failed: content mismatch for %s: got %x, want %x", filePath, content, expectedBytes)
}
}
// Assertion 4: Helper.Add writes multiple distinct corpus entries for sequential seed additions
{
corpusDir := filepath.Join(tmpBase, "multi-corpus")
os.Setenv("FUZZ_CORPUS_DIR", corpusDir)
f := &testing.F{}
h := ossfuzzseeds.New(f)
seed1 := []any{"first", uint32(100)}
seed2 := []any{"second", uint32(200)}
h.Add(seed1...)
h.Add(seed2...)
files, err := os.ReadDir(corpusDir)
if err != nil {
return fmt.Errorf("assertion 4 failed: ReadDir failed: %w", err)
}
if len(files) != 2 {
return fmt.Errorf("assertion 4 failed: expected 2 files, found %d", len(files))
}
entry1, err := ossfuzzseeds.CorpusEntry(seed1...)
if err != nil {
return fmt.Errorf("assertion 4 failed: failed to encode seed1: %w", err)
}
entry2, err := ossfuzzseeds.CorpusEntry(seed2...)
if err != nil {
return fmt.Errorf("assertion 4 failed: failed to encode seed2: %w", err)
}
file1 := filepath.Join(corpusDir, sha256Prefix(entry1))
file2 := filepath.Join(corpusDir, sha256Prefix(entry2))
c1, err := os.ReadFile(file1)
if err != nil || !bytes.Equal(c1, entry1) {
return fmt.Errorf("assertion 4 failed: seed1 file invalid: %w", err)
}
c2, err := os.ReadFile(file2)
if err != nil || !bytes.Equal(c2, entry2) {
return fmt.Errorf("assertion 4 failed: seed2 file invalid: %w", err)
}
}
return nil
}
原始种子者
匿名