CodeSampleX

Sample

net/http go1.26.5: Prove that net/http mutates a gzip response at the client boundary instead of preserving raw transfer shape.

Verified sample for golang net/http go1.26.5: Prove that net/http mutates a gzip response at the client boundary instead of preserving raw transfer shape.…

sha256:78e4711f9d506993f466ebedaae4f1c6636c420b765ce7576ba6a2b5a239991f

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment go linux x64 go go golang

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-16
go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-18

Case

HOW
Goal
Prove that net/http mutates a gzip response at the client boundary instead of preserving raw transfer shape.
Packages
Symbols
  • http.Client
Environment
go
Created
2026-08-16T13:09:01Z

Contract

  1. When a server writes a gzip-compressed body, a default http.Client request must return plain text bytes, not gzip bytes.
  2. The response seen by the caller must have Uncompressed set to true and lose Content-Encoding after decoding.

Files

  • NOTES.md
  • csx.json
  • go.mod
  • gzip_roundtrip_test.go

Download the source artifact (tar.gz)

Source

NOTES.md
A prior cache lookup found net/http cases for timeout sample `case:sha256:8a3b9795afd5fed47a451d4a013163fc7764b661cf0e78c579edb91221b7c212` and ServeMux method-pattern sample `case:sha256:0d4b034698a0346c1a1a03f0dab522b49ea18f19b7ef59476dd07f92911c1b96`; this sample deliberately uses a different boundary trap: implicit gzip decoding in the `http.Client` response path.

On this environment, the wrong model expectation is that transport returns the encoded bytes and `Content-Encoding` metadata unchanged; that passes compile but fails the contract as a wrong model would predict gzip payload, while the real result is auto-decoded bytes with decoded metadata.
csx.json
{"case":{"believed":"A caller using a default http.Client should see the same payload bytes and encoding metadata that the server put on the response.","caseId":"case:sha256:4571ecad28f768631797459437c7c601d82486411426911c5f821ba35978b938","contract":["When a server writes a gzip-compressed body, a default http.Client request must return plain text bytes, not gzip bytes.","The response seen by the caller must have Uncompressed set to true and lose Content-Encoding after decoding."],"goal":"Prove that net/http mutates a gzip response at the client boundary instead of preserving raw transfer shape.","kind":"HOW","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["http.Client"]},"contractCommand":["go","test","./..."],"environment":{"arch":"x64","ecosystem":"golang","executionContext":"go","language":"go","os":"linux","packageManager":"golang","runtime":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["http.Client"],"verifierAdapter":"golang@1"}
go.mod
module github.com/example/http-boundary-sample

go 1.26

gzip_roundtrip_test.go
package main

import (
    "bytes"
    "compress/gzip"
    "io"
    "net/http"
    "net/http/httptest"
    "testing"
)

func TestHTTPClientAutoDecompressesGzipResponse(t *testing.T) {
    plain := []byte("answer=42")

    var gzPayload bytes.Buffer
    writer := gzip.NewWriter(&gzPayload)
    if _, err := writer.Write(plain); err != nil {
        t.Fatalf("gzip write failed: %v", err)
    }
    if err := writer.Close(); err != nil {
        t.Fatalf("gzip close failed: %v", err)
    }

    server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
        w.Header().Set("Content-Type", "text/plain")
        w.Header().Set("Content-Encoding", "gzip")
        _, _ = w.Write(gzPayload.Bytes())
    }))
    defer server.Close()

    response, err := http.Get(server.URL)
    if err != nil {
        t.Fatalf("request failed: %v", err)
    }
    defer response.Body.Close()

    body, err := io.ReadAll(response.Body)
    if err != nil {
        t.Fatalf("read body failed: %v", err)
    }

    if !bytes.Equal(body, plain) {
        t.Fatalf("expected decompressed body %q, got %q", plain, body)
    }
    if response.Uncompressed != true {
        t.Fatalf("expected Uncompressed=true on auto-decoded response")
    }
    if response.Header.Get("Content-Encoding") != "" {
        t.Fatalf("expected Content-Encoding to be stripped after auto-decoding, got %q", response.Header.Get("Content-Encoding"))
    }
}

Origin Seeder

csx-seed