CodeSampleX

Sample

net/http go1.26.5: Show that `http.Client.Timeout` is enforced while reading a slow response body.

Verified sample for golang net/http go1.26.5: Show that `http.Client.Timeout` is enforced while reading a slow response body. The contract ran on go 1.26 …

sha256:a5d71aedbea662543b6d6b4b60bce0ccd1b8876c606797a1bbab8655f25ddf1f

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment go linux x64 go go go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-16
go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-18

Case

HOW
Goal
Show that `http.Client.Timeout` is enforced while reading a slow response body.
Packages
Symbols
  • Client.Timeout
Environment
go
Created
2026-08-16T12:04:37Z

Contract

  1. A request with a short `Client.Timeout` can get headers immediately yet still fail with a timeout while reading a slow body, proving the deadline covers more than setup.

Files

  • NOTES.md
  • client_timeout_test.go
  • csx.json
  • go.mod

Download the source artifact (tar.gz)

Source

NOTES.md
search_known_solution for `pkg:golang/net/http@go1.26.5` + `Client.Timeout` returned a miss, so this uses a fresh proof.
The wrong expectation fails because the timeout still aborts mid-body reads (as `io.ReadAll` returns a deadline error) even though headers can arrive within the timeout.
client_timeout_test.go
package codesamplex

import (
	"context"
	"errors"
	"io"
	"net/http"
	"net/http/httptest"
	"testing"
	"time"
)

func TestClientTimeoutLimitsResponseBodyRead(t *testing.T) {
	srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		w.WriteHeader(http.StatusOK)
		if _, err := w.Write([]byte("ok")); err != nil {
			t.Error(err)
			return
		}
		if f, ok := w.(http.Flusher); ok {
			f.Flush()
		}

		time.Sleep(100 * time.Millisecond)
		_, err := w.Write([]byte("too late"))
		if err != nil {
			t.Error(err)
			return
		}
	}))
	defer srv.Close()

	client := &http.Client{
		Timeout: 50 * time.Millisecond,
	}

	resp, err := client.Get(srv.URL)
	if err != nil {
		t.Fatalf("unexpected error before reading body: %v", err)
	}
	defer resp.Body.Close()

	_, err = io.ReadAll(resp.Body)
	if err == nil {
		t.Fatal("expected timeout while reading body, got nil")
	}
	if !errors.Is(err, context.DeadlineExceeded) {
		t.Fatalf("expected context deadline exceeded, got %v", err)
	}
}
csx.json
{"case":{"believed":"A common model expectation is that once headers arrive, a `http.Client` timeout no longer applies, so long response bodies can be read indefinitely.","caseId":"case:sha256:8a3b9795afd5fed47a451d4a013163fc7764b661cf0e78c579edb91221b7c212","contract":["A request with a short `Client.Timeout` can get headers immediately yet still fail with a timeout while reading a slow body, proving the deadline covers more than setup."],"goal":"Show that `http.Client.Timeout` is enforced while reading a slow response body.","kind":"HOW","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["Client.Timeout"]},"contractCommand":["go","test","./..."],"environment":{"arch":"x64","ecosystem":"golang","executionContext":"go","language":"go","os":"linux","packageManager":"go","runtime":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/net/http@go1.26.5"],"schemaVersion":1,"symbols":["Client.Timeout"],"verifierAdapter":"golang@1"}
go.mod
module codesamplex

go 1.26

Origin Seeder

csx-seed