internal/

directory
v0.85.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 8, 2026 License: MIT

Directories

Path Synopsis
analyzers
allow
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries
Package allow is the one marked-exception mechanism for the repo analyzers: a diagnostic whose line (or the line right below a stand-alone marker line) carries
asciifold
Package asciifold catches registry lookups that fold Unicode case.
Package asciifold catches registry lookups that fold Unicode case.
callbackunderlock
Package callbackunderlock catches calls through func-typed values while a sync mutex is held.
Package callbackunderlock catches calls through func-typed values while a sync mutex is held.
compositekey
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers).
The join is recognized through the indirections a real bug wears: a local or struct field bound from it, a one-result helper whose body reduces to returning it (statements that only rebind the helper's parameters in front of the return do not hide it), and the one-arg string-preserving normalizers around it at the sink (strings.ToLower/ToUpper/TrimSpace — the usual key normalizers).
controlbytes
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub.
Package controlbytes catches request-derived strings reaching a log, span-attribute, or header sink without a control-byte scrub.
credfetch
Package credfetch catches an http.Client with no CheckRedirect used for a credential-bearing fetch.
Package credfetch catches an http.Client with no CheckRedirect used for a credential-bearing fetch.
discardeddecode
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor.
Package discardeddecode catches a request-shaped parse whose error is thrown away: `_ = json.NewDecoder(r.Body).Decode(&body)`, `_ = json.Unmarshal(b, &v)`, `_ = r.ParseForm()`, and the bare statement spelling that drops the result on the floor.
discardederr
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`.
Package discardederr catches a multi-value assignment that drops an error on the floor while keeping the values around it: `ch, cancel, _ := m.subscribeImpl(id)`.
discardmutator
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
divlimit
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1.
Package divlimit catches integer division and remainder by a caller-supplied pagination-sized value that the function never guards against 0 or 1.
emitident
Package emitident catches names formatted into emitted code without an identifier gate.
Package emitident catches names formatted into emitted code without an identifier gate.
errleak
Package errleak catches an internal error string being handed to the client on a 5xx response — or, since the 2026-09-07 round, into a JSON-RPC internal-error response.
Package errleak catches an internal error string being handed to the client on a 5xx response — or, since the 2026-09-07 round, into a JSON-RPC internal-error response.
fieldtypeswitch
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
fixedtmp
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
fmtformat
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
hygiene
Package hygiene holds the small checks whose whole point is that they currently find nothing.
Package hygiene holds the small checks whose whole point is that they currently find nothing.
internal/dominance
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node.
Package dominance provides the statement-dominance walk shared by the analyzers under internal/analyzers: which statements and conditions of a function body are guaranteed to execute before a given node.
internal/pathflow
Package pathflow holds the path-dataflow machinery the root-shaped analyzers (rootwrite, rootread) share: local-binding resolution, the root/base/dir-named root tests, the lexical Join/concat containment shapes — including the one-hop same-package helper that RETURNS a root-joined path — and the EvalSymlinks-on-the-chain judgement that separates the fix posture from a resolution on an unrelated path.
Package pathflow holds the path-dataflow machinery the root-shaped analyzers (rootwrite, rootread) share: local-binding resolution, the root/base/dir-named root tests, the lexical Join/concat containment shapes — including the one-hop same-package helper that RETURNS a root-joined path — and the EvalSymlinks-on-the-chain judgement that separates the fix posture from a resolution on an unrelated path.
intwrap
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs.
Package intwrap catches the two integer-wrap postures that slip past range checks: unsigned→signed conversion without a bound, and unary negation of MinInt inside an abs.
laxcoerce
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent.
Package laxcoerce catches a wrong type masquerading as absence: a comma-ok type assertion on a map[string]any entry whose failure path returns zero values with a nil error — or continues — as though the key had never been sent.
laxenvelope
Package laxenvelope catches a transport that decodes the SAME envelope type lax at one site while the same package — or, since the 2026-09-07 round, ANY package — decodes that type strictly at another.
Package laxenvelope catches a transport that decodes the SAME envelope type lax at one site while the same package — or, since the 2026-09-07 round, ANY package — decodes that type strictly at another.
mapwriter
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
names
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker.
Package names is the dependency-free list of repo analyzer names: the vocabulary of the //gofastr:allow(<name>) marker.
negdur
Package negdur catches time.Duration zero-tests that silently fold a NEGATIVE lifetime onto the "zero means default" or "nonzero means expiry" arm.
Package negdur catches time.Duration zero-tests that silently fold a NEGATIVE lifetime onto the "zero means default" or "nonzero means expiry" arm.
nonfinite
Package nonfinite catches a strconv.ParseFloat result stored or returned without a NaN/Inf gate.
Package nonfinite catches a strconv.ParseFloat result stored or returned without a NaN/Inf gate.
nostore
Package nostore catches a per-caller 2xx response written with no Cache-Control on its path.
Package nostore catches a per-caller 2xx response written with no Cache-Control on its path.
nowaitdelay
Package nowaitdelay catches an exec.CommandContext child with captured stdout started with no WaitDelay bound.
Package nowaitdelay catches an exec.CommandContext child with captured stdout started with no WaitDelay bound.
recovercallback
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net.
Package recovercallback catches registry callbacks invoked with no recover in scope on a dispatch path that has no net.
recoverlog
Package recoverlog catches a recover() value reaching a log sink without a scrub.
Package recoverlog catches a recover() value reaching a log sink without a scrub.
reflectset
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request.
Package reflectset catches reflect.Value mutation of a struct field that never passed through CanSet: Set, SetString, SetInt, and the rest of the Set* family panic on values obtained from an unexported field, and the panic fires at injection time, not at declaration time, so a single lowercased tagged field takes down every request.
reqparamlimit
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
rootread
Package rootread catches reads whose containment under a root is resolved lexically only — the read twin of rootwrite.
Package rootread catches reads whose containment under a root is resolved lexically only — the read twin of rootwrite.
rootwrite
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll / os.Remove on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain.
Package rootwrite catches writes whose containment under a root is resolved lexically only: os.WriteFile / os.Create / os.OpenFile(write flag) / os.MkdirAll / os.Remove on a path built under a root — filepath.Join, or a flat `root + "/" + x` concatenation — where the root is a caller-supplied parameter or field — with no filepath.EvalSymlinks on that path's chain — plus the archive twin: zip.Writer entry names assembled from a parameter with no path.Clean on the entry-name chain.
secretcompare
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive.
Package secretcompare catches a client-supplied credential compared with == or != instead of a constant-time primitive.
testgap
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
timestampid
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability.
Package timestampid catches an identifier minted from wall-clock time: a time.Now().Unix()/.UnixMilli()/.UnixNano() value formatted into a string (fmt.Sprintf, strconv.FormatInt/FormatUint/Itoa, or + concatenation) and bound to a name ending in id, token, session, key, nonce, secret, or capability.
unboundedbody
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
unboundedresp
Package unboundedresp catches the unbounded read of an HTTP RESPONSE body: io.ReadAll(resp.Body), or a json/xml/yaml Decoder seated on it, with no io.LimitReader or http.MaxBytesReader anywhere on that body's chain in the function — or one hop away in a same-package helper the body is passed to.
Package unboundedresp catches the unbounded read of an HTTP RESPONSE body: io.ReadAll(resp.Body), or a json/xml/yaml Decoder seated on it, with no io.LimitReader or http.MaxBytesReader anywhere on that body's chain in the function — or one hop away in a same-package helper the body is passed to.
unseated
Package unseated catches a long-lived stream surface that admits a connection without any seat acquisition reachable on its open path.
Package unseated catches a long-lived stream surface that admits a connection without any seat acquisition reachable on its open path.
worldreadable
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore).
Package worldreadable catches files and directories written for state or secrets with group/other permission bits: os.WriteFile / os.Create / os.OpenFile(write flags) / os.Mkdir / os.MkdirAll whose mode is a CONSTANT literal carrying group or other bits (0644, 0755, 0666, 0777; os.Create is umask-default 0666), while this repo's own discipline for that artifact class is owner-only (0600/0700 plus fileperm.Restrict, pinned by battery/log, upload storage, the session sqlite store and DEK, freeze's world.json, and the credstore).
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
Package dsnredact strips credentials from database DSNs so the remainder can be logged or committed (host/db name are configuration, not secrets).
Package dsnredact strips credentials from database DSNs so the remainder can be logged or committed (host/db name are configuration, not secrets).
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL