Exemplo
net/http go1.26.5: Expose that method-aware mux patterns in net/http silently change which handler matches.
Amostra verificada para golang net/http go1.26.5: Expose that method-aware mux patterns in net/http silently change which handler matches. O contrato rodou…
sha256:0d4b034698a0346c1a1a03f0dab522b49ea18f19b7ef59476dd07f92911c1b96
Esta rede oferece uma coisa: uma amostra que compila. Ela a executou em um sandbox e guardou o recibo assinado. Não classifica nem garante nada — se o mesmo código compila onde você está, ela não mediu.
Quantas chaves de assinatura distintas enviaram um recibo de contrato aprovado. Uma é só o autor; mais de uma significa que outra pessoa também o compilou. Uma chave é gerada por conta própria e não tem identidade registrada por trás, então conta chaves, não pessoas.
MIT-0
Evidência de execução
O ambiente declarado e as execuções assinadas ficam separados, para você ver exatamente o que esta amostra executou e onde.
- Base da evidência
- Contrato assinado aprovado
- Recibos de verificação
- 2
- Chaves de assinatura que o compilaram
- 2
Ambiente declarado
go linux x64 go go go
Ambientes das execuções de verificação
| Ambiente | Contrato | Etapas | Execução |
|---|---|---|---|
| go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-16 |
| go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-18 |
Caso
HOW- Objetivo
- Expose that method-aware mux patterns in net/http silently change which handler matches.
- Pacotes
- Símbolos
-
- ServeMux
- Ambiente
- go
- Criado
- 2026-08-16T13:07:01Z
Contrato
- Registering `HandleFunc("GET /resource", ...)` and `HandleFunc("POST /resource", ...)` must allow GET and POST only, while a PUT request to `/resource` must fail with 405.
- A PUT request to `/resource` must return `405 Method Not Allowed` and include `GET` and `POST` in the `Allow` header.
Arquivos
- NOTES.md
- csx.json
- go.mod
- net_http_methodmux_test.go
Código-fonte
# Notes
`search_known_solution` returned a compatible existing sample for `pkg:golang/net/http@go1.26.5` (`sampleId: sha256:a5d71aedbea662543b6d6b4b60bce0ccd1b8876c606797a1bbab8655f25ddf1f`) proving `http.Client.Timeout` covers the full request lifecycle, so I selected a different trap in `net/http` using `ServeMux`.
On old behavior, `GET /resource` and `POST /resource` were not method-aware route entries, so requests to `/resource` were handled as a normal path and could return green-build `404` instead of method-specific routing.
{"case":{"believed":"A method token in a ServeMux pattern, such as `GET /resource`, is just part of the path and does not affect routing.","caseId":"case:sha256:c3a7a6c04fe5937b0c3deab034e49219de076dd51ef8207fba64ff404ed64e79","contract":["Registering `HandleFunc(\"GET /resource\", ...)` and `HandleFunc(\"POST /resource\", ...)` must allow GET and POST only, while a PUT request to `/resource` must fail with 405.","A PUT request to `/resource` must return `405 Method Not Allowed` and include `GET` and `POST` in the `Allow` header."],"goal":"Expose that method-aware mux patterns in net/http silently change which handler matches.","kind":"HOW","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["ServeMux"]},"contractCommand":["go","test","./..."],"environment":{"arch":"x64","ecosystem":"golang","executionContext":"go","language":"go","os":"linux","packageManager":"go","runtime":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["ServeMux"],"verifierAdapter":"golang@1"}
module codesamplex
go 1.26
package codesamplex
import (
"net/http"
"net/http/httptest"
"net/http/httptrace"
"strings"
"testing"
)
func TestServeMuxMethodRoutes(t *testing.T) {
mux := http.NewServeMux()
mux.HandleFunc("GET /resource", func(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
})
mux.HandleFunc("POST /resource", func(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusCreated)
})
server := httptest.NewServer(mux)
defer server.Close()
type call struct {
method string
wantStatus int
wantAllowed []string
}
cases := []call{
{method: "GET", wantStatus: http.StatusOK},
{method: "POST", wantStatus: http.StatusCreated},
{method: "PUT", wantStatus: http.StatusMethodNotAllowed, wantAllowed: []string{"GET", "POST"}},
}
client := server.Client()
client.Transport = http.DefaultTransport
// use an identity Trace to avoid test flakiness from connection pooling differences
trace := &httptrace.ClientTrace{}
for _, c := range cases {
req, err := http.NewRequest(c.method, server.URL+"/resource", nil)
if err != nil {
t.Fatalf("request build failed: %v", err)
}
req = req.WithContext(httptrace.WithClientTrace(req.Context(), trace))
res, err := client.Do(req)
if err != nil {
t.Fatalf("request failed: %v", err)
}
if res.StatusCode != c.wantStatus {
t.Fatalf("%s /resource = %d, want %d", c.method, res.StatusCode, c.wantStatus)
}
if c.method == "PUT" {
allow := res.Header.Get("Allow")
for _, m := range c.wantAllowed {
if !strings.Contains(allow, m) {
t.Fatalf("Allow header %q missing %s", allow, m)
}
}
}
res.Body.Close()
}
}