Exemple
Pin Viper 1.21.0 MergeConfigMap ownership: key normalization mutates caller maps, nested maps remain aliased, and merged config stays below explicit Set
sha256:85d242441a15089921167423b815bf5dd3b843a7305bcd229f3abfe5ab1fd578
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Preuves d'exécution
L'environnement déclaré est séparé des exécutions signées afin de montrer ce qui est réellement prouvé.
Base de preuveContrat signé réussi
Reçus de vérification1
Niveau de vérificationL3_CONTRACT_PASS
Environnement déclaré
- Contexte d'exécution
- go 1.26
- Système d'exploitation
- linux
- Architecture
- x64
- Runtime
- go 1.26
- Langage
- go
- Gestionnaire de paquets
- go
Environnements des exécutions de vérification
- Contexte d'exécution
- go 1.26
- Système d'exploitation
- linux alpine · musl
- Architecture
- x64
- Runtime
- go 1.26
- Langage
- go
- Gestionnaire de paquets
- go
- Exécution
- container · docker
CONTAINER_RUN · compile:PASS · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17
Cas
- Objectif
- Pin Viper 1.21.0 MergeConfigMap ownership: key normalization mutates caller maps, nested maps remain aliased, and merged config stays below explicit Set CONFIG
- Paquets
-
github.com/spf13/viper 1.21.0
- Environnement
- go 1.26
- Créé
- 2026-08-17T01:30:08Z
Ce que l'on suppose souvent
MergeConfigMap treats its argument as immutable input and copies it, so changing or reusing the caller's map after the call cannot alter Viper's configuration.
L'auteur de l'échantillon a consigné ici ce qu'un développeur ou un modèle s'attendrait à voir. Le contrat ci-dessous est ce qui s'est réellement exécuté.
Contrat
- assert MergeConfigMap lowercases both top-level and nested keys in the caller-supplied maps themselves
- assert mutating the first caller-owned nested map after MergeConfigMap changes the value returned by GetString, proving that nested map was retained rather than copied
- assert a later MergeConfigMap deep-merges its replacement and new sibling into the first caller-owned nested map while also normalizing the later input in place
- assert a merge after Set changes the aliased config map underneath but GetString still returns the explicit Set value because the config rung remains lower priority
Fichiers
- NOTES.md
- csx.json
- go.mod
- go.sum
- merge_config_map_test.go
Télécharger l’artefact source (tar.gz)
Seeder d'origine
csx-seed
Reçus de vérification
- go 1.26 · linux alpine/x64 · docker · CONTAINER_RUN · compile:PASS · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9