internal/

directory
v0.82.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 4, 2026 License: MIT

Directories

Path Synopsis
analyzers
allow
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries
asciifold
Package asciifold catches registry lookups that fold Unicode case.
Package asciifold catches registry lookups that fold Unicode case.
callbackunderlock
Package callbackunderlock catches calls through func-typed values while a sync mutex is held.
Package callbackunderlock catches calls through func-typed values while a sync mutex is held.
compositekey
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers).
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers).
controlbytes
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub.
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub.
discardeddecode
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor.
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor.
discardederr
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`.
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`.
discardmutator
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
divlimit
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1.
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1.
emitident
Package emitident catches names formatted into emitted code without an identifier gate.
Package emitident catches names formatted into emitted code without an identifier gate.
errleak
Package errleak catches an internal error string being handed to the client on a 5xx response.
Package errleak catches an internal error string being handed to the client on a 5xx response.
fieldtypeswitch
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
fixedtmp
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
fmtformat
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
hygiene
Package hygiene holds the small checks whose whole point is that they currently find nothing.
Package hygiene holds the small checks whose whole point is that they currently find nothing.
internal/dominance
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node.
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node.
intwrap
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs.
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs.
laxcoerce
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent.
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent.
mapwriter
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
names
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker.
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker.
recovercallback
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net.
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net.
reflectset
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request.
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request.
reqparamlimit
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
rootwrite
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain.
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain.
secretcompare
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive.
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive.
testgap
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
timestampid
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability.
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability.
unboundedbody
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
worldreadable
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore).
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore).
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL