Exemple
golang.org/x/mod v0.39.0: module.Check
Échantillon vérifié pour golang golang.org/x/mod v0.39.0: module.Check. Le contrat s'est exécuté sur go 1.26 · linux debian/x64 · docker et a réussi.
sha256:f9018fc84c727ea8ff66b821d56af45b8850dfed5de9177f987bd3182342a835
Ce réseau offre une seule chose : un échantillon qui compile. Il l'a exécuté dans un bac à sable et conservé le reçu signé. Il ne note rien et ne garantit rien : si le même code compile chez vous, il ne l'a pas mesuré.
Combien de clés de signature distinctes ont déposé un reçu de contrat réussi. Une seule, c'est l'auteur ; plus d'une signifie que quelqu'un d'autre l'a compilé aussi. Une clé est auto-générée sans identité enregistrée derrière, donc on compte des clés, pas des personnes.
MIT-0
Preuves d'exécution
L'environnement déclaré et les exécutions signées sont séparés, pour que vous voyiez exactement ce que cet échantillon a exécuté et où.
- Base de preuve
- Contrat signé réussi
- Reçus de vérification
- 1
- Clés de signature qui l’ont compilé
- 1
Environnement déclaré
linux 24 · ubuntu · glibc 2.39 x64 go
Environnements des exécutions de vérification
| Environnement | Contrat | Étapes | Exécution |
|---|---|---|---|
| go 1.26 · linux debian/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1golang:1.26@sha256:e30143be198a… |
2026-09-19 |
Cas
HOW- Objectif
- verify pkg:golang/golang.org/x/mod@v0.39.0
- Paquets
- Symboles
-
- module.Check
- Créé
- 2026-09-17T21:44:13Z
Contrat
- module.Check returns nil for a valid module path and semantic version
- module.Check returns nil for major version >= 2 when path includes the matching /vN suffix
- module.Check returns InvalidVersionError when major version >= 2 is used without a matching /vN path suffix
- module.Check returns InvalidVersionError when version string is not a semantic version
- module.Check returns InvalidPathError when module path contains invalid syntax such as a leading dash
- module.Check returns InvalidPathError when module path is empty
- module.Check returns InvalidPathError when module path contains an invalid /v0 major version suffix
Fichiers
- PROMPT.md
- csx.json
- go.mod
- go.sum
- main.go
- spec.json
- test/contract.go
Code source
Clean-room public code sample — generation instructions
Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.
A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.
Goal: verify pkg:golang/golang.org/x/mod@v0.39.0
Kind: HOW
Use EXACTLY these public packages and versions:
- pkg:golang/golang.org/x/mod@v0.39.0
Rules:
- One focused purpose; the smallest project that proves the goal.
- Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
- Pin every dependency with a lockfile so resolution is reproducible.
- No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
- No personal names, emails, company names, or project identifiers of any kind.
- No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
- Keep it under 200 files and 256KB packed.
{"case":{"caseId":"case:sha256:53ac1a7291547c9d3cbe36765484965ee64f88e19965f3e771131a443f941bfe","contract":["module.Check returns nil for a valid module path and semantic version","module.Check returns nil for major version \u003e= 2 when path includes the matching /vN suffix","module.Check returns InvalidVersionError when major version \u003e= 2 is used without a matching /vN path suffix","module.Check returns InvalidVersionError when version string is not a semantic version","module.Check returns InvalidPathError when module path contains invalid syntax such as a leading dash","module.Check returns InvalidPathError when module path is empty","module.Check returns InvalidPathError when module path contains an invalid /v0 major version suffix"],"goal":"verify pkg:golang/golang.org/x/mod@v0.39.0","kind":"HOW","packages":["pkg:golang/golang.org/x/mod@v0.39.0"],"schemaVersion":1,"symbols":["module.Check"]},"contractCommand":["go","run","./test"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"golang","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/golang.org/x/mod@v0.39.0"],"schemaVersion":1,"subject":"pkg:golang/golang.org/x/mod@v0.39.0","symbols":["module.Check"],"verifierAdapter":"golang@1"}
module example.com/sample
go 1.26.6
require golang.org/x/mod v0.39.0
golang.org/x/mod v0.39.0 h1:UF5zwQdCRRUpHfyPwr7d4UrGiVeldIsogtzWVnczL74=
golang.org/x/mod v0.39.0/go.mod h1:bvIbwjQ0HUFFf5AKukeeYQG4ZBUG9yxQbR9aEweIwYY=
package main
import (
"fmt"
"log"
"golang.org/x/mod/module"
)
func main() {
modulePath := "example.com/pkg/demo"
version := "v1.2.3"
if err := module.Check(modulePath, version); err != nil {
log.Fatalf("Unexpected check failure for %s@%s: %v", modulePath, version, err)
}
fmt.Printf("Validated module %s@%s successfully.\n", modulePath, version)
v2Path := "example.com/pkg/demo/v2"
v2Version := "v2.0.0"
if err := module.Check(v2Path, v2Version); err != nil {
log.Fatalf("Unexpected check failure for %s@%s: %v", v2Path, v2Version, err)
}
fmt.Printf("Validated v2 module %s@%s successfully.\n", v2Path, v2Version)
if err := module.Check(modulePath, v2Version); err != nil {
fmt.Printf("Correctly rejected mismatched major version: %v\n", err)
}
}
{
"schemaVersion": 1,
"goal": "verify pkg:golang/golang.org/x/mod@v0.39.0",
"kind": "HOW",
"packages": [
"pkg:golang/golang.org/x/mod@v0.39.0"
]
}
package main
import (
"errors"
"fmt"
"os"
"golang.org/x/mod/module"
)
func main() {
// 1. module.Check returns nil for a valid module path and semantic version
if err := module.Check("example.com/pkg/foo", "v1.2.3"); err != nil {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo, v1.2.3) failed: %v\n", err)
os.Exit(1)
}
// 2. module.Check returns nil for major version >= 2 when path includes the matching /vN suffix
if err := module.Check("example.com/pkg/foo/v2", "v2.0.0"); err != nil {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo/v2, v2.0.0) failed: %v\n", err)
os.Exit(1)
}
// 3. module.Check returns InvalidVersionError when major version >= 2 is used without a matching /vN path suffix
errV2Mismatch := module.Check("example.com/pkg/foo", "v2.0.0")
if errV2Mismatch == nil {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo, v2.0.0) expected error, got nil\n")
os.Exit(1)
}
var verErr *module.InvalidVersionError
if !errors.As(errV2Mismatch, &verErr) {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo, v2.0.0) expected InvalidVersionError, got %T (%v)\n", errV2Mismatch, errV2Mismatch)
os.Exit(1)
}
// 4. module.Check returns InvalidVersionError when version string is not a semantic version
errNotSemver := module.Check("example.com/pkg/foo", "1.2.3")
if errNotSemver == nil {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo, 1.2.3) expected error, got nil\n")
os.Exit(1)
}
if !errors.As(errNotSemver, &verErr) {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo, 1.2.3) expected InvalidVersionError, got %T (%v)\n", errNotSemver, errNotSemver)
os.Exit(1)
}
// 5. module.Check returns InvalidPathError when module path contains invalid syntax such as a leading dash
errLeadingDash := module.Check("-invalid/path", "v1.0.0")
if errLeadingDash == nil {
fmt.Fprintf(os.Stderr, "Check(-invalid/path, v1.0.0) expected error, got nil\n")
os.Exit(1)
}
var pathErr *module.InvalidPathError
if !errors.As(errLeadingDash, &pathErr) {
fmt.Fprintf(os.Stderr, "Check(-invalid/path, v1.0.0) expected InvalidPathError, got %T (%v)\n", errLeadingDash, errLeadingDash)
os.Exit(1)
}
// 6. module.Check returns InvalidPathError when module path is empty
errEmptyPath := module.Check("", "v1.0.0")
if errEmptyPath == nil {
fmt.Fprintf(os.Stderr, "Check(\"\", v1.0.0) expected error, got nil\n")
os.Exit(1)
}
if !errors.As(errEmptyPath, &pathErr) {
fmt.Fprintf(os.Stderr, "Check(\"\", v1.0.0) expected InvalidPathError, got %T (%v)\n", errEmptyPath, errEmptyPath)
os.Exit(1)
}
// 7. module.Check returns InvalidPathError when module path contains an invalid /v0 major version suffix
errV0Path := module.Check("example.com/pkg/foo/v0", "v0.1.0")
if errV0Path == nil {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo/v0, v0.1.0) expected error, got nil\n")
os.Exit(1)
}
if !errors.As(errV0Path, &pathErr) {
fmt.Fprintf(os.Stderr, "Check(example.com/pkg/foo/v0, v0.1.0) expected InvalidPathError, got %T (%v)\n", errV0Path, errV0Path)
os.Exit(1)
}
fmt.Println("All contract assertions passed.")
}
Seeder d'origine
anonyme