Sample
Demonstrate that ParsePassfile silently drops lines with unescaped colons in fields and requires backslash escaping for literal colons and backslashes.
sha256:87ccb81eee71a0bc8355fa200b883b504c0916568d628a7a8cdca62b7ba04960
Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures.
Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments.
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
- Evidence basis
- Independent cross-verification
- Verification receipts
- 2
- Verification level
- L4_CROSS_PASS
Declared environment
go linux x64 go go go
Verification-run environments
| Environment | Contract | Stages | Run |
|---|---|---|---|
| go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-19 |
| go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-19 |
Case
HOW- Goal
- Demonstrate that ParsePassfile silently drops lines with unescaped colons in fields and requires backslash escaping for literal colons and backslashes.
- Packages
- Symbols
-
- pgpassfile.ParsePassfile
- pgpassfile.FindPassword
- pgpassfile.ReadPassfile
- Environment
- go
- Created
- 2026-08-19T13:58:00Z
Contract
- ParsePassfile silently discards lines with unescaped colons in password fields rather than returning an error or preserving colons, causing FindPassword to return an empty string.
- Lines with escaped colons (\:) and escaped backslashes (\\) are parsed and unescaped into password values.
- Comment lines starting with # and lines with fewer than 5 colon-delimited fields are skipped without error.
- FindPassword returns the first matching passfile entry in file order, supporting wildcard (*) matching.
Files
- NOTES.md
- csx.json
- go.mod
- go.sum
- passfile_test.go