CodeSampleX

Sample

golang.org/x/mod v0.39.0: module.Check

Verified sample for golang golang.org/x/mod v0.39.0: module.Check. The contract ran on go 1.26 · linux debian/x64 · docker and passed.

sha256:2d14a726308d1c2d81c6670fce14092c0459ca18d99fb47a9bbe624e39a1c339

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux debian/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26@sha256:e30143be198a…
2026-10-09

Case

HOW
Goal
verify golang.org/x/mod/module.Check in pkg:golang/golang.org/x/mod@v0.39.0
Packages
Symbols
  • golang.org/x/mod/module.Check
Created
2026-10-09T12:58:55Z

Contract

  1. module.Check accepts valid module path and valid semantic version
  2. module.Check rejects module versions missing the required v prefix
  3. module.Check rejects invalid module paths with leading slash or empty path
  4. module.Check rejects invalid semantic version strings

Files

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

Download the source artifact (tar.gz)

Source

PROMPT.md
Clean-room public code sample — generation instructions

Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.

A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.

Goal: verify golang.org/x/mod/module.Check in pkg:golang/golang.org/x/mod@v0.39.0
Kind: HOW

Use EXACTLY these public packages and versions:
  - pkg:golang/golang.org/x/mod@v0.39.0
Demonstrate these symbols/APIs:
  - golang.org/x/mod/module.Check

Rules:
  - One focused purpose; the smallest project that proves the goal.
  - Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
  - Pin every dependency with a lockfile so resolution is reproducible.
  - No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
  - No personal names, emails, company names, or project identifiers of any kind.
  - No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
  - Keep it under 200 files and 256KB packed.
csx.json
{"case":{"caseId":"case:sha256:3a8d7b5e30f2d20879ad54c84439055278679cee9563f2945c2fa5b2e0e8c8eb","contract":["module.Check accepts valid module path and valid semantic version","module.Check rejects module versions missing the required v prefix","module.Check rejects invalid module paths with leading slash or empty path","module.Check rejects invalid semantic version strings"],"goal":"verify golang.org/x/mod/module.Check in pkg:golang/golang.org/x/mod@v0.39.0","kind":"HOW","packages":["pkg:golang/golang.org/x/mod@v0.39.0"],"schemaVersion":1,"symbols":["golang.org/x/mod/module.Check"]},"contractCommand":["go","run","./test"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"golang","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/golang.org/x/mod@v0.39.0"],"schemaVersion":1,"subject":"pkg:golang/golang.org/x/mod@v0.39.0","symbols":["golang.org/x/mod/module.Check"],"verifierAdapter":"golang@1"}
go.mod
module example.com/sample

go 1.26.6

require golang.org/x/mod v0.39.0
go.sum
golang.org/x/mod v0.39.0 h1:UF5zwQdCRRUpHfyPwr7d4UrGiVeldIsogtzWVnczL74=
golang.org/x/mod v0.39.0/go.mod h1:bvIbwjQ0HUFFf5AKukeeYQG4ZBUG9yxQbR9aEweIwYY=
main.go
package main

import (
	"fmt"
	"os"

	"golang.org/x/mod/module"
)

func main() {
	path := "example.com/pkg"
	version := "v1.0.0"

	if err := module.Check(path, version); err != nil {
		fmt.Fprintf(os.Stderr, "unexpected check error: %v\n", err)
		os.Exit(1)
	}

	fmt.Printf("module %s@%s is valid\n", path, version)
}
spec.json
{
  "schemaVersion": 1,
  "goal": "verify golang.org/x/mod/module.Check in pkg:golang/golang.org/x/mod@v0.39.0",
  "kind": "HOW",
  "packages": [
    "pkg:golang/golang.org/x/mod@v0.39.0"
  ],
  "symbols": [
    "golang.org/x/mod/module.Check"
  ]
}
test/contract.go
package main

import (
	"fmt"
	"os"

	"golang.org/x/mod/module"
)

func main() {
	if err := runTests(); err != nil {
		fmt.Fprintf(os.Stderr, "Contract test failed: %v\n", err)
		os.Exit(1)
	}
	fmt.Println("All contract assertions passed.")
}

func runTests() error {
	// 1. module.Check accepts valid module path and valid semantic version
	if err := module.Check("example.com/mod", "v1.2.3"); err != nil {
		return fmt.Errorf("expected module.Check to accept valid module path and version, got error: %w", err)
	}

	// 2. module.Check rejects module versions missing the required v prefix
	if err := module.Check("example.com/mod", "1.2.3"); err == nil {
		return fmt.Errorf("expected error for version missing 'v' prefix, got nil")
	}

	// 3. module.Check rejects invalid module paths with leading slash or empty path
	if err := module.Check("/invalid/leading/slash", "v1.0.0"); err == nil {
		return fmt.Errorf("expected error for module path with leading slash, got nil")
	}
	if err := module.Check("", "v1.0.0"); err == nil {
		return fmt.Errorf("expected error for empty module path, got nil")
	}

	// 4. module.Check rejects invalid semantic version strings
	if err := module.Check("example.com/mod", "v1.2.invalid"); err == nil {
		return fmt.Errorf("expected error for invalid semantic version string, got nil")
	}

	return nil
}

Origin Seeder

anonymous