Directories
¶
| Path | Synopsis |
|---|---|
|
analyzers
|
|
|
allow
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries
|
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries |
|
asciifold
Package asciifold catches registry lookups that fold Unicode case.
|
Package asciifold catches registry lookups that fold Unicode case. |
|
callbackunderlock
Package callbackunderlock catches calls through func-typed values while a sync mutex is held.
|
Package callbackunderlock catches calls through func-typed values while a sync mutex is held. |
|
compositekey
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers).
|
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers). |
|
controlbytes
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub.
|
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub. |
|
discardeddecode
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor.
|
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor. |
|
discardederr
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`.
|
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`. |
|
discardmutator
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
|
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success. |
|
divlimit
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1.
|
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1. |
|
emitident
Package emitident catches names formatted into emitted code without an identifier gate.
|
Package emitident catches names formatted into emitted code without an identifier gate. |
|
errleak
Package errleak catches an internal error string being handed to the client on a 5xx response.
|
Package errleak catches an internal error string being handed to the client on a 5xx response. |
|
fieldtypeswitch
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
|
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard. |
|
fixedtmp
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
|
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd). |
|
fmtformat
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
|
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string. |
|
hygiene
Package hygiene holds the small checks whose whole point is that they currently find nothing.
|
Package hygiene holds the small checks whose whole point is that they currently find nothing. |
|
internal/dominance
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node.
|
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node. |
|
intwrap
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs.
|
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs. |
|
laxcoerce
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent.
|
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent. |
|
mapwriter
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
|
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render. |
|
names
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker.
|
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker. |
|
recovercallback
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net.
|
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net. |
|
reflectset
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request.
|
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request. |
|
reqparamlimit
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
|
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters. |
|
rootwrite
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain.
|
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain. |
|
secretcompare
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive.
|
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive. |
|
testgap
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
|
Package testgap reports validator enumeration arms that no fixture in the package ever exercises. |
|
timestampid
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability.
|
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability. |
|
unboundedbody
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
|
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory. |
|
worldreadable
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore).
|
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore). |
|
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
|
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch. |
|
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.
|
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree. |
Click to show internal directories.
Click to hide internal directories.