Sample
Configure global entropy and node sources in google/uuid and verify error propagation, panic boundaries, and buffer requirements
sha256:1dc5a1ef8f31f456feae26c05034ca9f3c12373ad881bd70c474f17e52603e2d
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- go
- Operating system
- linux
- Architecture
- x64
- Runtime
- go
- Language
- go
- Package manager
- gomod
Verification-run environments
- Execution context
- go 1.26
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- go 1.26
- Language
- go
- Package manager
- gomod
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17
Case
- Goal
- Configure global entropy and node sources in google/uuid and verify error propagation, panic boundaries, and buffer requirements HOW
- Packages
-
github.com/google/uuid 1.6.0
- Environment
- go
- Created
- 2026-08-17T10:37:00Z
Commonly assumed
Setting a failing random source causes uuid.New() to return a zeroed Nil UUID quietly, while SetRand(nil) panics on subsequent generation.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- uuid.SetRand with a failing entropy source causes uuid.New and uuid.NewString to panic immediately with the reader error while uuid.NewRandom returns uuid.Nil and the error, and uuid.SetRand(nil) safely restores crypto/rand without a nil pointer panic.
- uuid.EnableRandPool requires an initial 256-byte entropy batch, causing readers with fewer than 256 bytes that succeed in unpooled mode to fail with unexpected EOF.
- uuid.SetNodeID rejects byte slices shorter than 6 bytes and sets uuid.NodeInterface to user on valid slices.
- uuid.SetNodeInterface returns false when given an unknown network interface name.
- uuid.SetClockSequence masks the input integer to the lower 14 bits.
Files
- NOTES.md
- csx.json
- go.mod
- go.sum
- uuid_config_test.go
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- go 1.26 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9