Summary
Togoder Security scanned the Go package github.com/bytedance/sonic@v1.15.4 on Oct 5, 2026. An AI review of 290 source files produced 63 medium, 67 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 130
unsafe pointer usage
NPS-84F0F5743F99
Extensive use of unsafe.Pointer and pointer arithmetic (e.g., rt.UnpackEface, (*rt.GoString)(unsafe.Pointer(&self.s)), native.Value calls with raw pointers) bypasses Go's memory safety guarantees. While typical for high-performance JSON libraries, this increases the risk of memory corruption or exploitable bugs if the native code has flaws.
native code interaction
NPS-568CC3753626
Calls to internal/native functions (native.Value, native.SkipOne, native.SkipOneFast, native.GetByPath) execute platform-specific assembly or C code that is not visible in this file. Such native code could contain hidden malicious behavior or vulnerabilities that cannot be audited from the provided source alone.
Unsafe memory operations
NPS-D077DF8EBF56
Extensive use of unsafe package with //go:nocheckptr directives and direct pointer arithmetic to bypass bounds checking. While typical for performance-critical JSON parsing libraries, this significantly increases risk of memory corruption if inputs are not perfectly validated. The skipBlank, decodeInt64, decodeFloat64, skipString, and skipPair functions manipulate pointers directly without bounds verification.
Potential out-of-bounds read in skipString
NPS-C6ABE1F63868
In skipString, when encountering a backslash escape character, the code does 'sp += 2' without checking if sp+1 is still within bounds. This could read past the end of the string buffer if a string ends with an unescaped backslash near the buffer boundary.
Potential out-of-bounds read in skipPair
NPS-8F1928D91837
In skipPair, when encountering a backslash, the code does 'sp += 2' without verifying sp+1 remains within the buffer bounds, potentially reading beyond the allocated memory.
Unsafe pointer usage
NPS-CB08063BD2E9
The code uses unsafe.Pointer to store a pointer to a local string variable in newError and newSyntaxError. The string variable 'msg' is allocated on the stack and its address is taken. After the function returns, the pointer stored in the Node struct points to a stack location that may be reused or invalidated, leading to a dangling pointer. When Error() dereferences this pointer later, it can cause memory corruption, crashes, or potentially leak sensitive information from other stack frames. This is a memory safety issue that could be exploited.
Unsafe pointer usage
NPS-6B427C6514BC
Similar unsafe.Pointer issue in newSyntaxError: the local variable 'msg' is stored via unsafe.Pointer in the Node returned. The pointer becomes invalid after function return, causing undefined behavior when Error() is later called.
Unsafe pointer usage
NPS-18B2DD4286F2
In unwrapError, when err is not *Node or Node, a local variable 'msg' is created and its address stored via unsafe.Pointer in a new Node. This again creates a dangling pointer after function return, leading to potential memory safety issues.
Unsafe memory manipulation
NPS-1643D5F06290
The mem2ptr function uses the unsafe package to convert a byte slice to an unsafe.Pointer by accessing internal runtime slice representation. This bypasses Go's type safety and could lead to memory corruption, out-of-bounds access, or undefined behavior if used improperly. The //go:nosplit directive prevents stack growth checks, further increasing risk. While this appears to be a legitimate utility for a high-performance JSON library (Sonic), unsafe pointer manipulation is a common vector for exploitation if the library is compromised or if callers misuse the function.
Dynamic code execution / JIT compilation
NPS-05E4EC5AB311
This file is part of a JIT (Just-In-Time) code assembler that generates and executes native x86-64 machine code at runtime. It uses the golang-asm library to emit raw assembly instructions, construct executable machine code, and jump to dynamically generated code addresses. While this is a legitimate performance optimization for the sonic JSON decoder, JIT compilation is a dual-use capability that could be abused to execute arbitrary code if the instruction stream is attacker-controlled. The _Program instruction stream originates from internal decoder logic, not external input, but the mechanism itself is a high-risk pattern.
Unsafe memory operations / direct machine code emission
NPS-0D35822EC497
The assembler emits raw machine code bytes directly (e.g., self.Byte(0xcc) for INT3 debug breakpoints, self.Byte(0x4c, 0x8d, 0x0d) for LEAQ instructions) and uses unsafe.Pointer extensively. The _asm_OP_debug function emits an INT3 (0xcc) breakpoint instruction. While these are standard for a JIT assembler, direct byte emission and unsafe pointer arithmetic bypass Go's memory safety guarantees and could lead to memory corruption if the generated code is incorrect.
Unsafe pointer operations
NPS-AA3D4B9A842C
The code uses unsafe.Pointer extensively with type-unsafe memory reinterpretation, including crafting slices from raw pointers in vs() and reconstructing Go structures from raw memory. While this is typical for JIT/compiler-style JSON decoders like sonic, it is inherently dangerous and could enable memory corruption if fed untrusted input that manipulates the compiled instruction stream.
Unsafe memory manipulation
NPS-77B2C89DA31C
The embeddedFieldPtrDecoder.FromDom function performs raw pointer arithmetic using unsafe.Pointer and uintptr to walk struct fields. This is inherent to the library's design (it is part of sonic, a high-performance JSON library by bytedance that uses unsafe for speed), but it carries memory-safety risk if field metadata is inconsistent. No malicious intent detected.
unsafe pointer/reflection usage
NPS-0405AF1A723C
The decoder heavily uses unsafe.Pointer, PtrOffset, rt.Mapassign, and related low-level runtime/reflection primitives to build Go maps from JSON AST nodes. While this is a known performance pattern in libraries like sonic (ByteDance), it bypasses Go's type safety guarantees. Incorrect handling of key memory layouts (e.g., for pointer-key map types) could lead to memory corruption or crashes if inputs are adversarial. The code also depends on runtime internals (rt.GoMapType, rt.Mapassign) that can vary across Go versions.
type confusion potential via unsafe casts
NPS-AEC63EC4D87B
Several decoder methods use unsafe casts like *(*unsafe.Pointer)(vp) = nil and *(*uint32)(unsafe.Pointer(&key)) with assumptions about the underlying type layout (e.g., mapI32KeyDecoder). If the mapType metadata does not match the actual destination type (e.g., through reflection misuse by callers), this could result in memory corruption rather than a safe type error.
unsafe pointer and memory manipulation
NPS-F2C3DB6DB22B
The code makes extensive use of the unsafe package, performing pointer arithmetic, manual memory allocation via rt.Mallocgc, rt.Memmove, and type punning (rt.UnpackType, rt.Str2Mem, rt.Mem2Str). While this is typical for high-performance JSON parsers and not inherently malicious, it creates memory-safety risks including potential out-of-bounds reads/writes that could be exploited if the native parser (native.ParseWithPadding) is fed crafted input.
dynamic memory allocation based on input size
NPS-245BE837ECBB
In Parser.parse(), a new node buffer is allocated with size derived from the remaining JSON length (calMaxNodeCap). If jsonSize is extremely large, this can lead to excessive memory allocation, a potential denial-of-service vector when parsing untrusted JSON input.
unsafe memory operations
NPS-9C8C0613B600
Extensive use of unsafe.Pointer, uintptr, ptrCast, and //go:nocheckptr for direct memory manipulation without bounds or safety checks. While typical for high-performance JSON parsers, this pattern can lead to memory corruption, out-of-bounds reads/writes, and potential exploitation if input parsing logic has flaws.
manual stack management
NPS-07A9CA64EF03
Custom boundedStack implementation with direct index arithmetic and unsafe.Pointer storage. Missing bounds checks on index (e.g., Pop decrements index without verifying > 0, Push increments without verifying < len). Could cause stack underflow/overflow leading to memory corruption.
memory pool manipulation
NPS-C61C2D945B43
efacePool allocates and reuses memory via unsafe operations. GetMap/GetSlice use unsafe.Pointer conversions; ConvTSlice/ConvF64 etc. write directly to interface slots. If pool sizing (from untrusted JSON stats) is wrong, buffer overflows may occur.
direct memory writes to interface
NPS-3A212A5125E6
AsEfaceFast writes to map/slice interface slots using rt.Mapassign_faststr and direct *vt = ...; *vp = ... assignments. Combined with manual pointer arithmetic (rt.PtrAdd), this bypasses Go's type safety and could corrupt memory if node structure assumptions are violated.
Extensive use of unsafe pointer arithmetic
NPS-FF869F6DE57F
The file heavily relies on the unsafe package and raw pointer arithmetic (e.g., unsafe.Pointer(uintptr(elems) + uintptr(i)*d.elemType.Size)) to manually compute element addresses in slices and arrays. While this is typical for high-performance decoders, it bypasses Go's memory safety guarantees. If the size/type calculations are ever incorrect or inputs are malformed, this could lead to out-of-bounds memory access, memory corruption, or potential exploitation. The //go:nocheckptr directive in arrayDecoder.FromDom further disables runtime pointer checks, increasing the risk surface. No direct malicious intent is evident, but the pattern warrants caution and careful auditing.
Unsafe pointer arithmetic
NPS-FF6F568F9DF9
The Stack type implements manual stack pointer arithmetic using unsafe.Pointer and uintptr (Top/Cur/Push/Pop). If sp is corrupted or the slab size assumptions are violated, reads/writes could occur out of bounds of the sb array, leading to memory corruption.
Memory clearing via unsafe
NPS-6A97550BAA5C
ResetStack uses rt.MemclrNoHeapPointers over an assumed StackSize. If StackSize is incorrect, this could clear beyond the object and corrupt adjacent heap memory.
Pointer retention in pooled objects
NPS-48EEDB31C74C
Pop sets *st = State{} but Push stores raw unsafe.Pointer values (p, q) into the stack. FreeStack only resets sp and returns the Stack to the pool; it does not clear the sb array, so stale unsafe.Pointer values may be reused, creating potential use-after-free semantics if those pointers are read later.
Use of go:linkname to runtime internals
NPS-174B3D4DE03B
The file uses //go:linkname to access unexported runtime functions (runtime.checkptrBase, runtime.findObject). This is a fragile and dangerous pattern that bypasses Go's type safety and can break between Go versions. While used here for debugging pointer checks, it violates encapsulation and could be misused for memory manipulation.
Unsafe pointer manipulation
NPS-EA2F4CC130A0
The code uses unsafe.Pointer and uintptr conversions to inspect pointers (checkptr, findobj). This is inherently unsafe and can lead to memory corruption or information disclosure if pointer values are printed or manipulated incorrectly.
JIT code generation and execution
NPS-24873ADE1714
The file is part of a JIT (Just-In-Time) assembler that dynamically generates and loads executable machine code into memory. While this is a legitimate part of the Sonic JSON library for performance, runtime code generation can be abused if the assembler input is not strictly controlled. The presence of a custom loader (loader.LoadOne) that maps generated machine code into executable memory is a high-risk pattern if inputs can be influenced externally.
Dynamic memory manipulation
NPS-142E64532BC0
Functions like Byte, From, Emit, and resolve directly manipulate memory and patch machine code at runtime. This low-level memory access can be used to bypass security mechanisms or execute arbitrary instructions if the assembler is fed untrusted input.
Dynamic code generation / JIT compilation
NPS-B330804ED1A1
This file is part of a JIT backend that assembles x86 machine code at runtime using golang-asm. It constructs executable code directly into memory (sym.P) and returns it for execution. While this is the intended purpose of the library (sonic JSON JIT), dynamic code generation inherently carries risk if input is attacker-controlled. The code itself does not appear malicious, but any vulnerability in the assembler or caller could lead to arbitrary code execution.
Dynamic code generation / JIT
NPS-CBDB982AF1C6
File is part of a JIT runtime (github.com/bytedance/sonic/internal/jit) that emits machine code at runtime using golang-asm. While not malicious on its own, dynamic code generation can be abused to execute obfuscated payloads and is a common vector for advanced threats.
Unsafe pointer manipulation
NPS-23C214F058A9
The code uses unsafe.Pointer and direct uintptr conversions to obtain raw addresses of runtime types (GoType), itabs, and function values. This bypasses Go's type safety and could be leveraged to corrupt memory or construct arbitrary jump targets if the surrounding JIT engine is misused or fed untrusted input.
Dynamic function pointer indirection with unsafe.Pointer
NPS-4178931BED26
The function F_f64toa is declared as a package-level function variable and S_f64toa as a package-level uintptr. These are presumably assigned at init time or via linking to native assembly code. The use of unsafe.Pointer with rt.NoEscape to call an indirect function pointer is a common pattern in high-performance libraries but also could be used to hide malicious native code execution. This file alone does not contain the assignment, making the ultimate behavior opaque from this file.
External function pointer assignment
NPS-9B8C0E883C0E
The variable F_i64toa is declared and expected to be assigned at runtime by native assembly code. If an attacker can control the assignment of this function pointer (e.g., via a malicious binary or improper initialization), it could lead to arbitrary code execution. However, in the context of the ByteDance sonic library, this is a standard pattern for SIMD-optimized routines.
Use of unsafe pointers
NPS-4E1CB7729083
The code uses unsafe.Pointer for low-level memory access. While this is common in performance-optimized libraries and appears legitimate for SIMD/AVX2 operations, it bypasses Go's memory safety guarantees and could lead to memory corruption if misused.
unsafe pointer usage
NPS-6DFB9A61BE08
Use of unsafe.Pointer and rt.NoEscape to pass a *string to an external function pointer without memory layout guarantees. This bypasses Go's type safety and could lead to memory corruption if the underlying assembly/native implementation mishandles the pointer.
unsafe pointer usage and linkname directives
NPS-44727520DC4A
The file heavily uses //go:linkname to bind to assembly functions and unsafe.Pointer for memory access. While this is a legitimate optimization pattern in the Sonic JSON library, it bypasses Go's type safety and could lead to memory corruption if the linked functions are not correctly implemented. This is not inherently malicious but represents a high-risk coding pattern.
unsafe pointer usage
NPS-2F7B82AC65B6
The code uses the unsafe package and passes raw pointers to a function pointer loaded from a native assembly implementation, which could potentially allow memory corruption if the native code is not properly implemented or validated.
Native code execution via loader.WrapGoC
NPS-D4084FF40E6F
This file binds Go function stubs to C functions contained in source files like sse/f64toa.c, sse/parse_with_padding.c, etc. The loader package dynamically links and executes native code at runtime. While this is a standard pattern for high-performance SIMD libraries like sonic, it introduces a trust boundary: the bundled C code could perform arbitrary operations (file system access, network calls, process spawning) that would not be visible in this Go file. The security of the package depends entirely on the integrity of the referenced .c files and the loader implementation.
Import-time code registration
NPS-7AA5EDBD9E65
The Use() function registers numerous native C functions with the Go runtime via loader.WrapGoC. If Use() is invoked during package initialization (or from an init() in the same package), native code paths become active before any application-level validation. This matches the red-flag category 'code that runs at install, build or import time'.
unsafe pointer usage
NPS-8B44ADD647B4
The use of the unsafe package to pass string and int pointers to a native function (F_skip_one_fast) bypasses Go's type safety. Although this is a common pattern in high-performance libraries (e.g., bytedance/sonic), it could theoretically be exploited if the native function is malicious or if pointers are misused to cause memory corruption. The function rt.NoEscape explicitly prevents escape analysis, which is typical for avoiding allocations but can obscure pointer lifetimes.
native function call
NPS-27B5DD03FD09
The call to F_skip_one_fast, a function pointer likely set during initialization, executes native code. While not inherently malicious, this pattern can be used to execute arbitrary native code if the function pointer is overwritten by an attacker or if the library is compromised. No evidence of such tampering in this file.
Generated code without source
NPS-E456387DD0C5
The file is marked 'Code generated by scripts, DO NOT EDIT' and only declares a symbol pointer to an externally supplied implementation (S_validate_utf8_fast). The actual executable behavior comes from an unresolved native symbol, meaning the auditable surface here is incomplete and the true implementation cannot be reviewed in this file.
Unsafe code / FFI bridge
NPS-427E181A43BD
This file uses unsafe.Pointer and runtime linkage (rt.NoEscape, function pointer F_validate_utf8_fast populated from a native/assembly implementation) to call platform-specific UTF-8 validation code. While this is typical for performance libraries like Sonic, the package replaces a safe Go implementation with a native call visible only through symbol pointers, which complicates static auditing and can be used to hide behavior outside the Go source tree.
native function binding
NPS-3EDCF38B4B0E
The variable F_vstring is declared as a function pointer but not assigned in this file. It is likely populated at runtime via dynamic linking or assembly linkage, which introduces a risk of loading untrusted native code if the linkage mechanism can be influenced by external inputs or environment. This pattern is common in performance-critical libraries but should be audited to ensure the symbol resolution is secure.
unsafe pointer usage
NPS-34A7621971EA
The code uses the unsafe package to pass Go pointers directly into a native function (F_vstring). Although the //go:nosplit directive and rt.NoEscape wrapper are intended to prevent heap escape analysis, this pattern bypasses Go's memory safety guarantees. If the native function retains any of these pointers or misuses the JsonState structure, it could lead to memory corruption, information disclosure, or arbitrary code execution.
unverified dependency / supply chain risk
NPS-133DABAE7B3A
The code imports github.com/cloudwego/base64x, a third-party package, and directly uses its encoding functions and internal symbols. If this dependency is compromised, it could lead to arbitrary code execution or data exfiltration during base64 encoding/decoding operations. The use of //go:linkname increases the attack surface by allowing access to unexported functions that may not be intended for external use.
unsafe linkage / linkname usage
NPS-7457A02B93CF
The file uses //go:linkname to reference unexported symbols (_subr__b64decode and _subr__b64encode) from the github.com/cloudwego/base64x package. This bypasses Go's type safety and encapsulation, creating a fragile and potentially exploitable dependency on internal implementation details. If the base64x package changes its internal symbols, this could cause undefined behavior or crashes. While not inherently malicious, this technique is often used to access hidden functionality.
Unsafe pointer arithmetic and memory manipulation
NPS-FA7000489916
The code uses unsafe.Pointer and direct memory manipulation (GoEface, GoSlice, Mallocgc) to convert values into interface{} representations. This bypasses Go's type safety and could lead to memory corruption, crashes, or arbitrary code execution if an attacker can influence the types or values passed to these functions. Functions like Conv, ConvNum, and ConvT64 write directly to memory addresses without bounds checking.
Use of internal/runtime-specific symbols
NPS-E53BA74E2C89
The code references internal types like GoEface, GoSlice, GoType, Mallocgc, BytesType, StringType, JsonNumberType, Uint64Type, and BoolType that are not part of the public Go standard library. These are copied from runtime internals and are version-specific. Using such internals can cause undefined behavior, crashes, or security issues when the Go runtime changes, and may be exploited if the expected memory layout differs.
Unsafe reflection and runtime internals manipulation
NPS-FE60E31FEB87
The file uses unsafe.Pointer extensively to reinterpret Go reflect.Type and interface internals, including direct memory layout assumptions (GoType, GoIface, GoEface, GoItab). It also uses go:linkname to access the runtime internal function runtime.getitab. This bypasses Go's type safety and relies on unstable runtime internals, which is fragile and can lead to memory corruption or arbitrary memory access if types are mismatched. While this is a known pattern in high-performance JSON libraries like Sonic (ByteDance), it presents a significant security risk if untrusted input influences the types being manipulated.
Use of unsafe and linkname to access runtime internals
NPS-82C4AB346063
The code uses //go:linkname to directly access unexported runtime functions and variables (runtime.gcWriteBarrier2 and runtime.writeBarrier). This bypasses Go's type safety and encapsulation, and relies on internal runtime implementation details that may change across Go versions. It also uses the unsafe package for pointer arithmetic and memory access. While this may be legitimate for low-level runtime manipulation, it is a red flag because such techniques are commonly used in malicious code to hide behavior or manipulate runtime state.
Runtime memory inspection and instruction decoding
NPS-42EBDB85B82D
The GcwbAddr function disassembles machine code at runtime using x86asm to locate the writeBarrier variable by scanning for a specific instruction pattern (CMP with memory operand and zero immediate). This involves reading and interpreting raw memory within the Go runtime, which is highly unusual for normal application code and could be used to locate and modify critical runtime structures.
Unsafe Go directive (go:linkname)
NPS-05022FCA28FD
The file uses the //go:linkname compiler directive to access unexported runtime internals (runtime.gcWriteBarrier, runtime.writeBarrier) from the standard library. This is a fragile and undocumented mechanism that bypasses Go's type and package safety guarantees. While this specific usage appears to be a legitimate low-level GC write barrier implementation (consistent with ByteDance/Sonic high-performance JSON library patterns), linkname access to runtime symbols can be abused by malicious packages to modify or read internal runtime state, hook memory management, or escape sandboxed execution contexts.
Use of unsafe package and runtime internals
NPS-CC89EDC480B1
The code uses the unsafe package and //go:linkname to access the unexported runtime.growslice function. This bypasses Go's type safety and internal runtime encapsulation. While this is a legitimate performance optimization technique used by packages like Sonic (ByteDance), it directly manipulates memory layout and relies on runtime internals that could change between Go versions, potentially leading to memory corruption or crashes.
Runtime implementation dependency
NPS-15DE8661CA78
The //go:linkname growslice runtime.growslice directive depends on the exact signature and behavior of an internal runtime function. If the Go runtime implementation changes (e.g., growslice signature or GoSlice/GoType layout changes), this could cause undefined behavior, memory corruption, or arbitrary memory writes. This is a legitimate but risky pattern.
Unsafe runtime linkname usage
NPS-15B9AD6D7DD2
The file uses //go:linkname to bind GrowSlice directly to runtime.growslice, an undocumented internal runtime symbol. This bypasses Go's type safety and version compatibility guarantees. While this pattern is common in performance-oriented libraries (this appears to be from ByteDance's sonic JSON library), linkname to runtime internals can break across Go versions, can be used to circumvent memory safety, and is difficult to audit for malicious behavior. In this file, no exfiltration, credential harvesting, network calls, subprocess execution, init() side effects, or obfuscated payloads are present, so the immediate risk is low; however, the same mechanism could be abused in a malicious variant.
Unsafe memory manipulation
NPS-69C24103DE62
The code uses unsafe.Pointer and manual pointer arithmetic without bounds checking. This can lead to memory corruption, arbitrary memory read/write, or crashes if inputs are not validated. The GetSlice method does not verify that the requested size is positive or that index+size stays within pool bounds, which could result in out-of-bounds access. While not inherently malicious, such patterns are dangerous and often associated with exploitation.
Potential integer overflow
NPS-3649AB8F81FC
The calculation uintptr(self.index)*AsGoType(self.typ).Size could overflow on 32-bit platforms or with large values, leading to pointer arithmetic underflow and out-of-bounds memory access.
Use of go:linkname to access runtime internals
NPS-39C062F81B08
The file uses //go:linkname directives extensively to access unexported runtime and reflect functions (runtime.memmove, runtime.mapiternext, runtime.mallocgc, reflect.makemap, runtime.throw, etc.). This bypasses Go's type safety and encapsulation guarantees, tightly coupling the package to specific Go runtime internals. This is characteristic of high-performance libraries (this appears to be ByteDance's sonic JSON library), but it is a fragile and potentially dangerous pattern: it can break with any Go version change, and similar techniques have been abused by malicious packages to manipulate memory, bypass security checks, or invoke privileged runtime behavior. It also complicates security auditing because the actual behavior depends on undocumented runtime internals.
Extensive unsafe.Pointer arithmetic and raw memory manipulation
NPS-237AF3EEF5F8
The code performs direct memory operations via unsafe.Pointer (add, Memmove, MemclrHasPointers, MemclrNoHeapPointers, MakeSlice, GrowSlice) and type-puns slices via unsafe.Pointer(&emptyBytes). Such low-level manipulations can lead to memory corruption, use-after-free, or out-of-bounds access if misused. While consistent with the intended purpose of a runtime-reflection helper package, these primitives are the same ones that malicious code would leverage to tamper with process memory, bypass sandboxing, or execute arbitrary payloads. No actual exfiltration, credential harvesting, network activity, process spawning, or dynamic code execution is present, so the risk is limited to fragility and potential memory-safety hazards rather than direct malice.
Potential incorrect bounds handling
NPS-B725ECB14004
The IntoBytes function checks capacity but not the length of the destination slice. It uses cap(*m) < len(s) as a guard, but then writes into the slice via unsafe pointer, bypassing slice length checks. This could lead to writing beyond the slice's logical length if the caller expects the length to be respected, potentially corrupting adjacent memory.
Unsafe memory manipulation
NPS-D9D8D0C43A29
The code uses Go's unsafe package with pointer arithmetic to reinterpret slices and strings (rt.GoSlice, rt.GoString). While this is a known performance optimization technique in the sonic library, it bypasses Go's memory safety guarantees. If the native.Unquote function has a bug or is exploited, it could lead to memory corruption or arbitrary code execution.
build constraint complexity
NPS-5C9D1C40D1F5
Complex build tags restrict compilation to specific Go versions and architectures. This could be used to selectively include/exclude code across Go versions, though here it appears benign for compatibility.
informational
NPS-F45B228B048A
The file contains a build tag that is intentionally never satisfied by normal Go toolchains (references go1.28 and contradictory constraints), ensuring this compatibility fallback is excluded from standard builds. No malicious behavior is present.
init function
NPS-DBC11906CDC4
An init() function is present that calls compat.Warn, which simply logs a warning about using the pure-Go fallback. This runs at import time but performs no dangerous operations.
Error handling bypass
NPS-7D957610AE42
In decodeValue, errors from decodeInt64 and decodeFloat64 are discarded (using _), and only the return code is checked. This could mask legitimate parsing errors, though it doesn't directly create a security vulnerability.
Build Constraint Compatibility
NPS-6D1E521559CB
This file is a compatibility fallback for non-optimized architectures. It uses standard library encoding/json instead of unsafe native assembly. No malicious behavior is present.
init function warning
NPS-7DFD8F1A47FC
The init() function only calls compat.Warn('sonic/encoder'), which is a warning mechanism for using the fallback (compatibility) implementation on unsupported architectures. This is benign and does not perform any malicious activity.
unsafe package usage
NPS-23ED5F987EE9
The code uses the unsafe package to manipulate pointers and directly access runtime internals via rt.UnpackEface and rt.Strhash. While this appears to be a legitimate performance optimization for string hashing (likely part of the Sonic JSON library), direct pointer manipulation bypasses Go's memory safety guarantees and could lead to memory corruption, crashes, or undefined behavior if the runtime internals change or if the function signature expectations are violated.
runtime internal access
NPS-04527F2FB673
The code accesses Go runtime internal functions (runtime.strhash) through the internal/rt package. This creates a tight coupling with specific Go runtime versions and may break on runtime updates. If the rt.Strhash signature or behavior differs across Go versions, the unsafe.Pointer cast could cause type confusion and memory safety issues.
init() function executes at import time
NPS-DC944F178395
Go init() runs at import time, but it only reads an env var and adjusts CPU feature flags; it performs no network, file, or process operations.
Environment variable read
NPS-DEB13D87C669
The code reads the SONIC_MODE environment variable to optionally disable AVX2 CPU feature detection. This is a configuration mechanism, not credential harvesting, and does not exfiltrate any data.
code generation and JIT-style optimization
NPS-973EC616A35A
This file is part of ByteDance's Sonic JSON library, which uses assembly and unsafe code for high-performance decoding. The pretouchImpl, pretouchManyImpl, and decodeImpl assignments reference optimization functions. This is a legitimate performance optimization pattern, not obfuscation or dynamic code execution. No eval/exec equivalents are used.
init function execution
NPS-F443250915E6
The package defines an init() function that executes at import time, calling envs.EnableOptDec() and envs.EnableFastMap(). While init() functions are a common Go pattern, they do execute automatically when the package is imported. However, these calls only set internal package-level configuration flags (enabling decoder optimizations and fast map handling) with no external network, filesystem, or process activity. This is benign and consistent with the package's documented purpose.
Import-time initialization (init functions)
NPS-69F7A846872D
Multiple init() functions execute at package load time, including setting up JIT function pointers (jit.Func), computing reflection types, and initializing float pointer values. While these do not perform I/O or network operations, they do initialize the JIT subsystem and cache function addresses. This is standard for this type of library but represents top-level code that runs on import.
Use of reflection and unsafe for type manipulation
NPS-C705F220FC32
The code uses reflect.TypeOf, rt.UnpackType, unsafe.Pointer, and direct manipulation of Go runtime type structures (rt.GoType, rt.GoItab). It accesses rt.F_kind_mask and _Gt_KindFlags via unsafe offset calculations. This relies on Go internal ABI details and could break or behave unexpectedly across Go versions. The build constraint (!go1.28) indicates awareness of version fragility.
Reflection-based compilation with raw type pointers
NPS-3BBE3510633D
The compiler uses rt.UnpackType and rt.GoType with unsafe.Pointer to bypass Go's type safety. Type metadata is stored as raw pointers in instructions (newInsVt, newInsVtI). If a type-confusion bug exists, this could be exploitable, but appears to be an internal, non-attacker-controlled path.
Compile-time code execution via Unmarshaler interfaces
NPS-5AA0439DB32F
The checkMarshaler function compiles calls into json.Unmarshaler, encoding.TextUnmarshaler interfaces at decode time via _OP_unmarshal/_OP_unmarshal_text opcodes. This is standard behavior for a JSON decoder, but it does mean that any type passed to this decoder can execute arbitrary user-defined code during unmarshaling.
Recover-based error handling
NPS-5B4B8CAB3A92
The rescue() function uses recover() to convert panics to errors. Recovered panics from attacker-influenced input could mask errors or cause unexpected states, though this is a common pattern and not indicative of malice.
Debug Environment Variables
NPS-7EEB5439CDDE
The code reads SONIC_SYNC_GC and SONIC_NO_ASYNC_GC environment variables to control debug garbage collection behavior. This is a standard debugging mechanism, not credential harvesting or exfiltration.
Runtime Function Calls
NPS-D2C6BBCF36E3
Calls runtime.GC and debug.FreeOSMemory for garbage collection during debugging. These are legitimate Go runtime functions, not process spawning or shell commands.
dynamic code generation / JIT assembly
NPS-E45C9EC0948D
This file implements a JIT (Just-In-Time) compiler that emits raw assembly instructions at runtime using the golang-asm library. While this is legitimate for a high-performance JSON decoder (sonic by ByteDance), dynamic code generation/execution is a red flag that warrants scrutiny. The generated machine code is executed directly via function pointers. This could theoretically be abused if the package were compromised to emit malicious instructions, but the current code appears to be a legitimate JSON decoder implementation.
reflection and memory manipulation
NPS-E0940B8BB0B6
Uses reflect.TypeOf and unsafe-style pointer operations (jit.Ptr, WriteRecNotAX, WritePtrAX) to write directly to Go runtime memory structures like interfaces and slices. This is standard for a high-performance JSON decoder but constitutes memory manipulation that could be dangerous if the code were modified maliciously.
runtime library calls via assembly
NPS-8F11B9D14208
The code calls internal Go runtime functions (runtime.makeslice, runtime.convTslice, runtime.convTstring, runtime.mapassign_faststr, runtime.growslice, runtime.mallocgc) directly via JIT-emitted CALL instructions. These are normal for this type of optimized decoder but bypass normal Go function call safety.
Direct memory allocation
NPS-6CF65962B961
ptrDecoder.FromDom and embeddedFieldPtrDecoder.FromDom call rt.Mallocgc directly to allocate memory for pointer targets. While unusual in typical Go code, this is consistent with the library's low-level performance-oriented design and not evidence of malicious behavior.
no input size/complexity limits
NPS-DEB76278D75B
The decoders iterate over obj.Len() (the parsed JSON object length) without any explicit bound on map size or loop count, and they allocate maps using rt.Makemap with obj.Len() as the size hint. A maliciously large JSON object could cause excessive memory allocation (memory exhaustion DoS). No MAX_MAP_SIZE or similar guard is present in this file.
global mutable state and sync.Pool reuse
NPS-4A04BFB37553
A sync.Pool of Parser objects is shared globally, and reset() reinitializes fields but does not clear the underlying 'dbuf' or fully zero the reused node slices. Residual data from previous parses could persist in memory and, in combination with unsafe pointer reuse, might leak data between logically separate parsing operations.
no explicit malicious behavior
NPS-7516356D3DE0
No network calls, file system access outside package scope, process spawning, environment variable harvesting, obfuscated payloads, dynamic code execution, cryptocurrency mining, or backdoor installation were found. The code appears to be a performance-oriented JSON decoder.
Potential unsafe memory clearing
NPS-15278E696F0B
In arrayDecoder.FromDom, the code uses rt.ClearMemory with a computed pointer and size to zero out the remaining elements of an array. The comment acknowledges that the boundary pointer may point to an unknown object, and the call is guarded by if n != 0. However, if d.len and d.elemType.Size are not consistent with the actual array length, this could clear unintended memory, leading to data corruption or crashes. This is a correctness/safety concern rather than an obvious backdoor, but it reinforces the need for strict validation of type parameters.
Dynamic code generation/JIT compilation
NPS-244308114E42
This file implements a JIT (Just-In-Time) compiler that generates and executes machine code at runtime using the x86 assembler and loader packages. While this is legitimate functionality for the ByteDance Sonic JSON library to achieve high performance, dynamic code generation is an advanced technique that could potentially be abused if the library were compromised. The code uses unsafe pointers and assembles native instructions at runtime.
Use of unsafe package
NPS-DD690C3705A3
The code imports and uses the 'unsafe' package extensively (e.g., unsafe.Pointer in _KeepAlive struct). This bypasses Go's type safety guarantees. In this context it's used for JIT-compiled function pointer management and is consistent with the library's high-performance design, but represents elevated risk surface.
Init-time behavior
NPS-4508CBB6E43D
The init() function runs automatically at package import time. It configures the encoder to use JIT compilation by default. This executes code (compiler setup) at import time, though no network, filesystem, or process manipulation occurs.
Import-time initialization
NPS-BFE59F7D57B1
The file contains an init() function that calls ForceUseVM(). This runs at import time. However, the call is to a local package function (github.com/bytedance/sonic/option) and only configures encoder behavior for non-amd64 platforms; there is no evidence of malicious activity, network access, file system access, or dynamic code execution.
Environment variable access
NPS-200F17373DCE
The code reads environment variables (SONIC_SYNC_GC, SONIC_NO_ASYNC_GC, SONIC_CHECK_POINTER, SONIC_ENCODER_USE_VM) to configure debug and runtime behavior. These are not credential-harvesting patterns; they are configuration toggles for the package's own operation.
Use of unsafe package
NPS-EB6C1ED325C3
The unsafe package is used only to compute memory sizes of structs (Stack and State) at compile time. No pointer manipulation or memory-unsafe operations are performed.
Unsafe pointer usage
NPS-26CBB2DEC252
Uses unsafe.Pointer and casts to *rt.GoString for formatting. This is standard low-level trickery in the sonic library for performance and is not malicious, but misuse can cause memory corruption or crashes if inputs are not well-formed.
Panic with data inclusion
NPS-904C34CA3B22
GoPanic deliberately panics with up to maxJSONLength bytes of the JSON buffer embedded in the panic string. If this buffer contains sensitive data (credentials, tokens, PII) and panic output is logged or reported to an error tracking service, that data could be leaked. This is a defensive design choice to aid debugging, not exfiltration, but it has a data-disclosure risk.
Environment variable configuration
NPS-849E5B5D8D59
The init() function reads the SONIC_PANIC_MAX_JSON_LENGTH environment variable to configure the maximum JSON length included in panic messages. While this is a legitimate configuration mechanism used by the sonic JSON library, init() functions run automatically at import time and environment-driven behavior can be surprising. The value is validated with strconv.Atoi and only applied if parsing succeeds.
Type-unsafe Pool usage
NPS-66386B8EF5AB
bytesPool, stackPool, and bufferPool are plain sync.Pool without type guarantees. NewBytes/NewBuffer/NewStack use unchecked type assertions. While in normal operation the pools only hold their intended types, sharing a package-level pool means any code with access to the package could inject a different type and cause a panic on assertion.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| ast/api.go | medium | The code uses unsafe pointers and native assembly calls typical of a high-performance JSON library, but these patterns reduce auditability and could conceal vulnerabilities; no direct malicious intent is evident. |
| ast/decode.go | medium | This is a legitimate JSON parsing library from ByteDance's sonic project using unsafe pointer arithmetic for performance; no malicious patterns detected, but unsafe memory operations warrant caution. |
| ast/error.go | medium | The code contains unsafe pointer usage that creates dangling pointers to local stack variables, leading to potential memory corruption and undefined behavior. |
| ast/stubs.go | medium | The code uses unsafe package for slice-to-pointer conversion, a legitimate but potentially dangerous pattern that warrants review, though no active malicious behavior is present. |
| internal/caching/hashing.go | medium | The code uses unsafe pointer manipulation and Go runtime internals for string hashing performance, which is risky but appears legitimate for the Sonic JSON library with no evidence of malicious intent. |
| internal/decoder/jitdec/assembler_regabi_amd64.go | medium | This is a legitimate JIT compiler backend for the ByteDance sonic JSON library that generates native x86-64 code at runtime; while it uses high-risk techniques (runtime code generation, unsafe pointer manipulation, direct machine code emission), no malicious patterns such as data exfiltration, credential harvesting, network calls, or backdoor installation were detected. |
| internal/decoder/jitdec/compiler.go | medium | This is ByteDance's sonic JIT JSON decoder compiler; it contains no network, filesystem, process spawning, environment/credential access, obfuscation, or install-time execution patterns, but it does pervasively use unsafe pointer manipulation and reflection-based type handling which are inherent risks of the JIT design rather than evidence of malicious intent. |
| internal/decoder/jitdec/generic_regabi_amd64.go | medium | This is a legitimate JIT-based JSON decoder from the ByteDance sonic package; it uses dynamic assembly generation and runtime memory manipulation, which are unusual but expected for high-performance decoders, with no evidence of data exfiltration, credential harvesting, or backdoor behavior. |
| internal/decoder/optdec/functor.go | medium | Code is a legitimate portion of the sonic JSON decoding library using unsafe pointer arithmetic for performance; no exfiltration, credential harvesting, obfuscation, or malicious behavior is present. |
| internal/decoder/optdec/map.go | medium | The file is a legitimate JSON-to-map decoder from the ByteDance sonic library, but it relies heavily on unsafe pointers, runtime internals, and a lack of input-size limits, which are robustness/safety concerns rather than malicious patterns. |
| internal/decoder/optdec/native.go | medium | This is a legitimate high-performance JSON parser using unsafe memory operations and a native library, but it exhibits memory-safety and resource-exhaustion risks typical of such code rather than outright malicious behavior. |
| internal/decoder/optdec/node.go | medium | The code is a high-performance JSON parser using extensive unsafe pointer arithmetic and manual memory management, which presents memory safety risks but shows no overt malicious intent such as data exfiltration or backdoor installation. |
| internal/decoder/optdec/slice.go | medium | The code is a performance-oriented JSON decoder using unsafe pointer arithmetic and manual memory management; no clear malicious patterns, but the heavy reliance on unsafe operations and disabled pointer checks pose a potential security risk if not carefully validated. |
| internal/encoder/pools_amd64.go | medium | This is a legitimate JIT compiler module from the ByteDance Sonic JSON library; it uses advanced techniques (unsafe, dynamic machine code generation) that warrant caution but show no evidence of malicious behavior such as exfiltration, credential harvesting, or backdoors. |
| internal/encoder/vars/errors.go | medium | The file is part of ByteDance's sonic JSON library and contains only legitimate error-handling and panic-formatting logic; the only concerns are a benign import-time environment variable read and inclusion of a bounded amount of caller-provided JSON in panic messages. |
| internal/encoder/vars/stack.go | medium | No overtly malicious behavior found, but the file relies heavily on unsafe pointer arithmetic and type-unsafe sync.Pool usage, which carries memory-safety risk if invariants (StackSize, MaxStack, pool contents) are violated. |
| internal/encoder/x86/debug_go117.go | medium | The file contains unsafe pointer operations and runtime linkname hacks typical of a debugging JIT assembler, but no clear malicious intent such as exfiltration, backdoors, or process spawning was found. |
| internal/jit/assembler_amd64.go | medium | This is a JIT assembler for the Sonic JSON library that generates and executes machine code at runtime; while it appears to be a legitimate performance component, the dynamic code generation and import-time execution patterns carry inherent risk if the package is compromised or if inputs are not strictly controlled. |
| internal/jit/backend.go | medium | This is a legitimate JIT backend for the ByteDance sonic library; it dynamically generates x86 machine code, which is inherently sensitive, but no exfiltration, credential harvesting, obfuscation, or backdoor patterns were found. |
| internal/jit/runtime.go | medium | The file is part of a legitimate JIT compiler (sonic) but uses unsafe pointer arithmetic and runtime type introspection typical of code-generation engines, which warrants a warning rather than a safe classification. |
| internal/native/avx2/f64toa.go | medium | This appears to be a legitimate generated AVX2 assembly bridge for the sonic JSON library; no direct malicious patterns are present, though the unsafe indirect native call warrants review of its assembly implementation. |
| internal/native/avx2/i64toa.go | medium | The code uses unsafe pointers and external function pointers for performance optimization, which is typical for SIMD assembly integration but carries inherent memory safety risks; no direct malicious behavior is evident. |
| internal/native/avx2/quote.go | medium | The code appears to be a legitimate generated wrapper for an AVX2-optimized JSON quoting function from the ByteDance sonic library, using unsafe pointers for performance, but no clear malicious patterns were detected. |
| internal/native/avx2/validate_utf8_fast.go | medium | No overt malicious intent detected, but the code relies on unsafe memory operations and external function pointers, posing moderate safety and maintainability risks. |
| internal/native/avx2/value.go | medium | The code is a legitimate part of a performance-oriented JSON library using unsafe pointers and AVX2 assembly, which is a low-risk pattern but warrants caution due to unsafe native interface usage. |
Show 265 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/native/dispatch_arm64.go | medium | The code uses unsafe pointers and linkname directives for performance-critical JSON parsing, but no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected. |
| internal/native/sse/f64toa.go | medium | The file is a low-level, generated Go wrapper around an assembly implementation for float-to-ASCII conversion; it uses unsafe pointers and external function pointers but contains no direct malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution. |
| internal/native/sse/html_escape.go | medium | The file is a generated, low-level unsafe/FFI binding for an HTML escape routine; no malicious patterns are present, though its use of unsafe pointers and a mutable function-pointer indirection is worth noting as a minor attack-surface concern. |
| internal/native/sse/i64toa.go | medium | The code uses unsafe pointers and native function pointers for performance, which poses a moderate security risk but shows no clear malicious intent. |
| internal/native/sse/native_export.go | medium | The file safely wires Go to bundled native C implementations via loader.WrapGoC, but the native binding pattern and potential import-time activation represent a moderate trust-boundary risk that depends on the integrity of the referenced C source files. |
| internal/native/sse/parse_with_padding.go | medium | The file uses unsafe pointers and external function pointer assignment typical of performance-optimized native bindings, but lacks direct malicious patterns; risk is limited to unaudited native code dependency. |
| internal/native/sse/skip_number.go | medium | The code is a generated assembly stub using unsafe pointers for performance, with no active malicious patterns, but the reliance on external function pointers warrants low-level caution. |
| internal/native/sse/skip_one_fast.go | medium | The code uses unsafe pointers and a native function call for performance, which poses a moderate risk if the native implementation is malicious or memory corruption occurs, but no direct malicious patterns are present. |
| internal/native/sse/validate_utf8_fast.go | medium | The file is a generated unsafe/FFI shim for a native UTF-8 validator; it shows no overt malicious behavior but its reliance on unsafe pointers and externally resolved symbols reduces auditability. |
| internal/native/sse/vnumber.go | medium | The file uses unsafe pointers and an externally-injected function pointer, a typical native-binding pattern for the Sonic JSON library, with no direct evidence of malicious behavior in this snippet. |
| internal/native/sse/vstring.go | medium | The file contains unsafe pointer manipulation and native function bindings typical of performance-focused JSON parsing, posing medium risk if the native implementation is not securely resolved. |
| internal/rt/base64_amd64.go | medium | The code uses unsafe linkname to access internal symbols of a third-party base64 library, introducing encapsulation bypass and supply chain risks, though no direct malicious behavior is present. |
| internal/rt/fastconv.go | medium | The code uses unsafe pointer arithmetic and internal runtime types to manipulate memory, which poses a medium risk of memory corruption or undefined behavior, but no direct malicious patterns such as data exfiltration, credential harvesting, or backdoors were found. |
| internal/rt/fastvalue.go | medium | The code uses unsafe pointer arithmetic and runtime internals for reflection, which is typical for high-performance libraries but carries memory safety risks; no direct malicious behavior such as exfiltration, credential harvesting, or backdoors was found. |
| internal/rt/gcwb.go | medium | The code uses unsafe, linkname, and runtime disassembly to access and compute addresses of internal Go runtime structures, which is a security concern due to bypassing safety mechanisms and potential for runtime manipulation. |
| internal/rt/gcwb_legacy.go | medium | Code uses go:linkname to access unexported Go runtime internals, which is an unsafe but likely legitimate GC write-barrier implementation; no exfiltration, credential harvesting, or malicious behavior observed. |
| internal/rt/growslice.go | medium | The file uses legitimate but risky low-level Go runtime hacks (unsafe, go:linkname, memory layout assumptions) that carry memory-safety risks if runtime internals change, but no malicious patterns such as exfiltration, backdoors, or command execution were detected. |
| internal/rt/growslice_legacy.go | medium | The file contains an unsafe //go:linkname binding to runtime.growslice, a legitimate but risky pattern typical of ByteDance's sonic library; no malicious behavior was detected, but linkname usage warrants caution and cross-checking with sibling build-tag variants. |
| internal/rt/pool.go | medium | The code uses unsafe pointer arithmetic without sufficient bounds checking, which could lead to memory safety issues, but no overtly malicious behavior is present. |
| internal/rt/stubs.go | medium | The file contains no exfiltration, credential harvesting, network, process, or obfuscation indicators, but its heavy use of go:linkname and unsafe.Pointer runtime internals is a fragile, high-privilege pattern that warrants caution when auditing or trusting the package. |
| unquote/unquote.go | medium | The code uses unsafe memory operations for performance, which introduces memory safety risks but appears to be part of a legitimate JSON library (sonic) rather than malicious activity. |
| api.go | safe | Cleared by Jev triage; no further analysis needed |
| ast/api_compat.go | safe | This compatibility fallback file contains only benign JSON parsing helpers and a warning logger; no malicious patterns were detected. |
| ast/buffer.go | safe | No malicious patterns detected; the code implements data structure utilities with no network, filesystem, process, or obfuscated behavior. |
| ast/encode.go | safe | No malicious patterns detected |
| ast/iterator.go | safe | Cleared by Jev triage; no further analysis needed |
| ast/node.go | safe | No malicious patterns detected; the code is a legitimate JSON AST node implementation from ByteDance's sonic library with only safe operations (memory manipulation, parsing, serialization, no external I/O, exec, or network calls). |
| ast/parser.go | safe | No malicious patterns detected; the code is a legitimate JSON parser from the ByteDance Sonic library with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| ast/search.go | safe | No malicious patterns detected; the code is a legitimate JSON AST search utility from the ByteDance Sonic library with no network, filesystem, process execution, or obfuscated behavior. |
| ast/visitor.go | safe | Cleared by Jev triage; no further analysis needed |
| compat.go | safe | Cleared by Jev triage; no further analysis needed |
| decoder/decoder_compat.go | safe | No malicious patterns detected; this is a legitimate compatibility shim for the sonic JSON library. |
| decoder/decoder_native.go | safe | Cleared by Jev triage; no further analysis needed |
| encoder/encoder_compat.go | safe | The code is a safe fallback/compatibility implementation of a JSON encoder using standard library functions; no malicious patterns were detected. |
| encoder/encoder_native.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/caching/fcache.go | safe | No malicious patterns detected; code is a legitimate hash map implementation for caching field lookups with no suspicious behavior. |
| internal/caching/pcache.go | safe | No malicious patterns detected; the code implements a legitimate concurrent hash map cache for serialization programs with no network, filesystem, process, or obfuscation concerns. |
| internal/compat/warn.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cpu/features.go | safe | The file is a benign CPU feature detection helper that optionally disables AVX2 via an environment variable, with no malicious behavior. |
| internal/decoder/api/decoder.go | safe | No malicious patterns detected; this is a legitimate JSON decoder from the ByteDance sonic library with only standard decoding functionality. |
| internal/decoder/api/decoder_amd64.go | safe | No malicious patterns detected; the file only selects JIT or opt decoder implementations based on build tags and an environment variable. |
| internal/decoder/api/decoder_arm64.go | safe | The file is part of ByteDance's Sonic JSON library and contains only benign architecture-specific initialization that enables internal decoder optimizations without any malicious behavior. |
| internal/decoder/api/stream.go | safe | No malicious patterns detected; the code implements a standard streaming JSON decoder with buffer pooling and no external network, file system, or process activity. |
| internal/decoder/consts/option.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/errors/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/jitdec/asm_stubs_amd64_go117.go | safe | This file contains low-level JIT assembly helper functions for garbage collector write barriers in the Sonic JSON library; no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity were detected. |
| internal/decoder/jitdec/asm_stubs_amd64_go121.go | safe | No malicious patterns detected |
| internal/decoder/jitdec/debug.go | safe | Debug utilities using environment variables and runtime GC calls for internal debugging; no malicious patterns detected. |
| internal/decoder/jitdec/decoder.go | safe | The code is a legitimate JSON decoder from the Sonic library using unsafe pointer operations and runtime code generation, with no evidence of malicious patterns such as data exfiltration, credential harvesting, or backdoor installation. |
| internal/decoder/jitdec/pools.go | safe | No malicious patterns detected; the file is a legitimate memory pool and caching implementation for the ByteDance Sonic JSON decoder using unsafe pointer operations typical of high-performance Go code. |
| internal/decoder/jitdec/primitives.go | safe | No malicious patterns detected; the code is a legitimate part of the Sonic JSON decoder using unsafe pointers and JIT compilation, with no exfiltration, credential harvesting, obfuscation, or other red flags. |
| internal/decoder/jitdec/types.go | safe | No malicious patterns detected; the file only declares reflection type variables and a helper that converts reflect.Type to internal Go runtime type representations, all consistent with legitimate JSON decoder implementation in the Sonic library. |
| internal/decoder/jitdec/utils.go | safe | No malicious patterns detected; the file contains low-level unsafe pointer helpers and an assertion utility typical of a JIT decoder implementation with no network, filesystem, process, or obfuscation behavior. |
| internal/decoder/optdec/compile_struct.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/optdec/compiler.go | safe | No malicious patterns detected |
| internal/decoder/optdec/const.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/optdec/context.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/optdec/decoder.go | safe | No malicious patterns detected; the code is a standard JSON decoder with no exfiltration, credential harvesting, obfuscation, or process execution. |
| internal/decoder/optdec/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/optdec/helper.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/decoder/optdec/interface.go | safe | No malicious patterns detected; the code is a legitimate JSON decoder implementation using unsafe for performance optimization, with no network, filesystem, process, or obfuscation concerns. |
| internal/decoder/optdec/stringopts.go | safe | No malicious patterns detected; the code implements JSON string-to-primitive decoders using unsafe pointers and reflection helpers consistent with the bytedance/sonic library's internal operations. |
| internal/decoder/optdec/structs.go | safe | No malicious patterns detected; the code is a standard JSON struct decoder using reflection and unsafe pointers for performance, with no exfiltration, obfuscation, or suspicious behavior. |
| internal/decoder/optdec/types.go | safe | No malicious patterns detected; the file only contains standard reflect type definitions and unsafe pointer conversions for JSON decoding. |
| internal/encoder/alg/mapiter.go | safe | No malicious patterns detected; this is a legitimate Go JSON encoder map iterator with standard unsafe/reflection usage but no exfiltration, code execution, or backdoor mechanisms. |
| internal/encoder/alg/opts.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/alg/sort.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/alg/spec.go | safe | No malicious patterns detected; the code is a legitimate performance-optimized JSON encoder with unsafe operations for speed, but no security concerns like data exfiltration, backdoors, or code execution. |
| internal/encoder/alg/spec_compat.go | safe | The Go file contains standard JSON encoding utilities with no suspicious network, filesystem, process execution, or obfuscated behavior. |
| internal/encoder/compiler.go | safe | The code is a JSON encoder compiler from the Sonic library and contains no malicious patterns. |
| internal/encoder/encode_norace.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/encode_race.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/encoder.go | safe | No malicious patterns detected in the analyzed Go encoder source file. |
| internal/encoder/ir/op.go | safe | No malicious patterns detected; the code is a legitimate part of the Sonic JSON encoder/decoder library implementing instruction set operations with no exfiltration, obfuscation, or dynamic execution. |
| internal/encoder/pools_compt.go | safe | No malicious patterns detected; the only import-time code is a benign local configuration call for non-amd64 builds. |
| internal/encoder/prim/primitives.go | safe | No malicious patterns detected; the code is a legitimate JSON encoding helper from ByteDance's Sonic library with only standard unsafe/reflect usage for performance. |
| internal/encoder/stream.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/vars/cache.go | safe | No malicious patterns detected; the file contains a straightforward program cache for a JSON encoder library. |
| internal/encoder/vars/const.go | safe | The file only defines constants and reads environment variables for configuration; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor behavior were detected. |
| internal/encoder/vars/types.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoder/vm/stbus.go | safe | No malicious patterns detected; the code is a legitimate part of the Sonic JSON encoder with no signs of data exfiltration, credential harvesting, or other security concerns. |
| internal/encoder/vm/vm.go | safe | No malicious patterns detected |
| internal/encoder/x86/asm_stubs_amd64_go117.go | safe | The code is a low-level Go assembler stub for write barriers and does not contain any malicious patterns; it is a legitimate part of the Sonic JSON library. |
| internal/encoder/x86/asm_stubs_amd64_go121.go | safe | The file contains low-level x86 assembly stubs for Go runtime write barriers and exhibits no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution. |
| internal/encoder/x86/assembler_export_amd64.go | safe | No malicious patterns detected; the code is a simple build-constrained export wrapper for an assembler. |
| internal/encoder/x86/assembler_regabi_amd64.go | safe | The file is a legitimate JIT assembler for the Sonic JSON encoder; no malicious patterns were detected. |
| internal/encoder/x86/debug_go116.go | safe | No malicious patterns detected; the code is a legitimate Go debug helper for JIT assembler with GC triggering controlled by environment variables, all functions are internal and standard library based. |
| internal/encoder/x86/stbus.go | safe | No malicious patterns detected; the code is a legitimate low-level encoder utility from the Sonic JSON library using standard Go unsafe operations. |
| internal/envs/decode.go | safe | No malicious patterns detected; the code only reads two environment variables and provides toggle functions for internal flags. |
| internal/jit/arch_amd64.go | safe | No malicious patterns detected; the code is a benign JIT architecture helper for AMD64 with no network, file, process, or obfuscation activity. |
| internal/native/avx2/f32toa.go | safe | This file contains only a safe, generated wrapper around a SIMD-accelerated float-to-ASCII conversion function with no malicious patterns. |
| internal/native/avx2/f32toa_subr.go | safe | This is a generated assembly metadata file for an AVX2 f32-to-ASCII conversion function in the bytedance/sonic library, containing only PC/SP tables and loader.CFunc definitions with no malicious patterns. |
| internal/native/avx2/f32toa_text_amd64.go | safe | No malicious patterns detected; the file contains auto-generated AMD64 assembly bytes for a float-to-ASCII conversion routine, with no network, filesystem, process, or dynamic code execution behavior. |
| internal/native/avx2/f64toa_subr.go | safe | No malicious patterns detected; the file is a generated assembly metadata declaration for the bytedance/sonic AVX2 f64toa routine with no executable or suspicious logic. |
| internal/native/avx2/get_by_path.go | safe | No malicious patterns detected; the file is a generated FFI wrapper for AVX2-accelerated JSON path lookup with only unsafe.Pointer conversions and no suspicious behavior. |
| internal/native/avx2/get_by_path_subr.go | safe | Auto-generated assembly metadata for an AVX2 native function; contains no malicious patterns. |
| internal/native/avx2/html_escape.go | safe | No malicious patterns detected; the file is a generated AVX2 assembly wrapper for HTML escaping with only unsafe pointer usage for performance and no network, file, credential, process, or obfuscated behavior. |
| internal/native/avx2/html_escape_subr.go | safe | The file contains only static metadata and function registration for an AVX2 assembly routine; no malicious patterns, dynamic execution, network activity, or filesystem access were detected. |
| internal/native/avx2/html_escape_text_amd64.go | safe | No malicious patterns detected |
| internal/native/avx2/i64toa_subr.go | safe | This is an autogenerated Go assembly wrapper for bytedance/sonic's AVX2 i64toa function containing only static metadata and no malicious patterns. |
| internal/native/avx2/i64toa_text_amd64.go | safe | This is an auto-generated Go assembly file implementing AVX2-accelerated integer-to-ASCII conversion with no network, filesystem, process, or dynamic code execution capabilities. |
| internal/native/avx2/lspace.go | safe | No malicious patterns detected; the file defines a low-level unsafe-pointer function binding for AVX2 lspace with no network, file, process, or dynamic execution behavior. |
| internal/native/avx2/lspace_subr.go | safe | No malicious patterns detected; the file is a generated assembly metadata stub for an AVX2 function within the bytedance/sonic library. |
| internal/native/avx2/lspace_text_amd64.go | safe | This file contains generated AVX2 assembly bytecode for an lspace (left-space/whitespace skipping) function, with no network, filesystem, process, credential, or code-execution behavior. |
| internal/native/avx2/native_export.go | safe | No malicious patterns detected; the file contains only JIT function registration for a known performance library (sonic AVX2). |
| internal/native/avx2/parse_with_padding.go | safe | No malicious patterns detected; the file is a generated, legitimate wrapper for a native AVX2 JSON parsing function from the Sonic library with no external calls, file access, or obfuscation. |
| internal/native/avx2/parse_with_padding_subr.go | safe | This is a generated Go assembly-wrapper file for an AVX2 JSON parser with only static function metadata and no malicious patterns. |
| internal/native/avx2/quote_subr.go | safe | This is an auto-generated Go assembly metadata file for the Sonic JSON library's AVX2 quote function; it contains only static tables of PC/SP offsets and function descriptors with no executable logic, I/O, network calls, or other malicious patterns. |
| internal/native/avx2/skip_array.go | safe | No malicious patterns detected |
| internal/native/avx2/skip_array_subr.go | safe | Generated AVX2 assembly wrapper for JSON skip_array with no imports beyond a local loader package and no malicious patterns. |
| internal/native/avx2/skip_number.go | safe | No malicious patterns detected |
| internal/native/avx2/skip_number_subr.go | safe | No malicious patterns detected; this is a generated assembly support file for the sonic JSON library containing only metadata tables for a native skip_number function. |
| internal/native/avx2/skip_number_text_amd64.go | safe | This is a generated AVX2 assembly byte array for a UTF-8 number-skipping routine with no network, filesystem, process, or dynamic code execution activity. |
| internal/native/avx2/skip_object.go | safe | No malicious patterns detected; the file is a generated Go wrapper around an AVX2 skip_object function using unsafe pointers for performance, with no network, filesystem, process execution, or credential access. |
| internal/native/avx2/skip_object_subr.go | safe | No malicious patterns detected |
| internal/native/avx2/skip_one.go | safe | This is a generated Go file from the ByteDance Sonic JSON library that provides a thin wrapper around an AVX2 assembly function using unsafe pointers; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution were detected. |
| internal/native/avx2/skip_one_fast.go | safe | No malicious patterns detected; the file only declares an assembly-backed function pointer used by the sonic JSON library for AVX2 acceleration, with no network, filesystem, process, credential, or obfuscation behavior. |
| internal/native/avx2/skip_one_fast_subr.go | safe | No malicious patterns detected; the file contains only generated assembly metadata and loader registration for AVX2 optimized JSON parsing. |
| internal/native/avx2/skip_one_fast_text_amd64.go | safe | No malicious patterns detected; the file contains only machine-generated AVX2 assembly bytecode for a JSON skip-one-fast function with no network, filesystem, process, credential, or dynamic execution activity. |
| internal/native/avx2/skip_one_subr.go | safe | No malicious patterns detected in the analyzed Go assembly-metadata file; it only declares constants and a loader.CFunc table for a statically linked AVX2 routine. |
| internal/native/avx2/u64toa.go | safe | No malicious patterns detected; the file only provides a thin unsafe wrapper around a function pointer for uint64-to-ASCII conversion. |
| internal/native/avx2/u64toa_subr.go | safe | This is a generated assembly metadata file for the Sonic JSON library's u64toa function with no malicious patterns. |
| internal/native/avx2/u64toa_text_amd64.go | safe | This is a machine-generated assembly bytecode file for optimized integer-to-string conversion with no malicious patterns, network activity, filesystem access, or code execution beyond its intended purpose. |
| internal/native/avx2/unquote.go | safe | No malicious patterns detected |
| internal/native/avx2/unquote_subr.go | safe | No malicious patterns detected; the file only contains generated metadata for an assembly function registration. |
| internal/native/avx2/unquote_text_amd64.go | safe | No malicious patterns detected; this is a generated assembly byte slice implementing JSON string unquoting in the AVX2 assembly routine. |
| internal/native/avx2/validate_one.go | safe | No malicious patterns detected; the file contains only a generated Go binding to a native AVX2 validation function within the ByteDance Sonic JSON library. |
| internal/native/avx2/validate_one_subr.go | safe | This is a generated assembly metadata file for an AVX2-optimized JSON validation routine in the Sonic library, containing only static stack/PC mapping tables and loader function descriptors with no network, filesystem, process, or dynamic execution behavior. |
| internal/native/avx2/validate_utf8.go | safe | No malicious patterns detected; the file contains generated Go bindings for AVX2 UTF-8 validation without external network, filesystem, process, or code-execution activity. |
| internal/native/avx2/validate_utf8_fast_subr.go | safe | No malicious patterns detected; the file contains generated AVX2 assembly metadata and function registration for UTF-8 validation with no suspicious behavior. |
| internal/native/avx2/validate_utf8_fast_text_amd64.go | safe | No malicious patterns detected; the file contains only generated assembly data for an AVX2 UTF-8 validation routine with no network, filesystem, process, or dynamic execution behavior. |
| internal/native/avx2/validate_utf8_subr.go | safe | This is a generated Go assembly metadata file for UTF-8 validation using AVX2, containing only loader function descriptors and stack frame metadata with no malicious patterns. |
| internal/native/avx2/validate_utf8_text_amd64.go | safe | No malicious patterns detected; this file contains only generated x86-64 assembly bytes for a UTF-8 validation routine. |
| internal/native/avx2/value_subr.go | safe | No malicious patterns detected; the file contains only generated assembly metadata and loader configuration for an AVX2-optimized value parser. |
| internal/native/avx2/vnumber.go | safe | No malicious patterns detected; the file contains only Go bindings for AVX2 assembly routines without network, filesystem, or process manipulation. |
| internal/native/avx2/vnumber_subr.go | safe | No malicious patterns detected in this generated Go assembly metadata file; it only defines function entry sizes, stack sizes, and PCSP mappings for an AVX2 native function. |
| internal/native/avx2/vsigned.go | safe | No malicious patterns detected; the code is a legitimate unsafe pointer wrapper for AVX2 native JSON parsing with no network, file, process, or dynamic execution behavior. |
| internal/native/avx2/vsigned_subr.go | safe | No malicious patterns detected; this is a generated assembly loader file from the sonic project defining metadata for a signed comparison routine, containing no executable logic, network activity, or suspicious behavior. |
| internal/native/avx2/vsigned_text_amd64.go | safe | No malicious patterns detected; this is a generated assembly byte slice for an AVX2-accelerated signed integer parsing routine with no network, filesystem, process, or dynamic code execution behavior. |
| internal/native/avx2/vstring.go | safe | No malicious patterns detected; the file is a legitimate low-level wrapper for calling an assembly-implemented JSON string function using unsafe pointers and does not perform any exfiltration, credential harvesting, code execution, or other suspicious activity. |
| internal/native/avx2/vstring_subr.go | safe | No malicious patterns detected; this is a generated Go assembly wrapper file defining metadata tables for a native AVX2 string function. |
| internal/native/avx2/vstring_text_amd64.go | safe | This is a machine-generated AVX2 assembly bytecode blob for JSON string scanning (looking for quotes, backslashes, and control characters) with no malicious patterns detected. |
| internal/native/avx2/vunsigned.go | safe | No malicious patterns detected; the file is a thin Go wrapper around a native AVX2 function using unsafe pointers for JSON parsing, a standard pattern in the sonic library. |
| internal/native/avx2/vunsigned_subr.go | safe | No malicious patterns detected; this is a generated assembly wrapper for AVX2 SIMD code with no executable logic or suspicious behavior. |
| internal/native/avx2/vunsigned_text_amd64.go | safe | This is a generated assembly implementation of an unsigned integer parsing routine for a JSON package, with no malicious patterns detected. |
| internal/native/dispatch_amd64.go | safe | No malicious patterns detected; the file contains legitimate CPU dispatch logic for selecting optimized JSON parsing implementations (AVX2/SSE) in the ByteDance sonic library. |
| internal/native/neon/f32toa_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/f32toa_subr_arm64.go | safe | No malicious patterns detected in the generated Go assembly stub, which only declares a stack size, a function entry pointer, and compile-time no-op variable references. |
| internal/native/neon/f64toa_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/f64toa_subr_arm64.go | safe | This file is a machine-generated assembly binding stub for an ARM64 float-to-ASCII conversion routine with no executable logic, network, filesystem, or process-spawning behavior. |
| internal/native/neon/get_by_path_arm64.go | safe | The file contains only a simple wrapper function for a native assembly implementation of get_by_path, with no network, filesystem, process, or obfuscated code patterns. |
| internal/native/neon/get_by_path_subr_arm64.go | safe | Generated assembly stub file contains only a symbol declaration and stack size constants with no executable logic or malicious patterns. |
| internal/native/neon/html_escape_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/html_escape_subr_arm64.go | safe | Generated assembly stub file with no executable logic, only a function declaration and constant definitions; no malicious patterns detected |
| internal/native/neon/i64toa_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/i64toa_subr_arm64.go | safe | No malicious patterns detected; this is a generated assembly bridge for i64toa with only symbol declarations and no executable logic. |
| internal/native/neon/lspace_arm64.go | safe | No malicious patterns detected; the file contains only a Go assembly function declaration for JSON whitespace skipping from the bytedance/sonic library. |
| internal/native/neon/lspace_subr_arm64.go | safe | No malicious patterns detected in this generated ARM64 NEON assembly entry stub; it only declares a nosplit/noescape function pointer and stack size constants with no network, filesystem, exec, or obfuscation behavior. |
| internal/native/neon/native_export_arm64.go | safe | No malicious patterns detected; the file only contains variable assignments to internal function symbols for ARM64 SIMD routines, with no dynamic code execution, network activity, or filesystem manipulation. |
| internal/native/neon/parse_with_padding_arm64.go | safe | This file contains only a thin Go wrapper declaring an ARM64 assembly function using unsafe pointers and runtime escape marking; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were identified. |
| internal/native/neon/parse_with_padding_subr_arm64.go | safe | No malicious patterns detected; the file is a generated assembly stub with only function pointer and stack size declarations. |
| internal/native/neon/quote_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/quote_subr_arm64.go | safe | This is a generated assembly stub for a NEON quote function with no executable Go logic, network access, or suspicious behavior. |
| internal/native/neon/skip_array_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/skip_array_subr_arm64.go | safe | No malicious patterns detected; this is a generated assembly bridge stub for a NEON SIMD JSON skip-array routine with no executable logic or external interaction. |
| internal/native/neon/skip_number_arm64.go | safe | No malicious patterns detected; the file is a generated, declarative Go binding to an assembly function for skipping numbers. |
| internal/native/neon/skip_number_subr_arm64.go | safe | No malicious patterns detected in this generated assembly stub file. |
| internal/native/neon/skip_object_arm64.go | safe | No malicious patterns detected; this is a standard generated Go assembly binding stub for a JSON object skipping function. |
| internal/native/neon/skip_object_subr_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/skip_one_arm64.go | safe | No malicious patterns detected; the file is a benign Go assembly wrapper for a JSON skip function in the Sonic library. |
| internal/native/neon/skip_one_fast_arm64.go | safe | The file contains only a Go function declaration for an ARM64 assembly stub generated by scripts, with no malicious patterns detected. |
| internal/native/neon/skip_one_fast_subr_arm64.go | safe | Assembly-linked SIMD helper stub with no executable logic, network, filesystem, or import-time behavior; only build-tag gated symbol declarations. |
| internal/native/neon/skip_one_subr_arm64.go | safe | This is a generated Go assembly binding file with only function declarations and constants, containing no malicious patterns. |
| internal/native/neon/u64toa_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/u64toa_subr_arm64.go | safe | This is a machine-generated assembly stub file for a Go NEON u64toa routine with no suspicious behavior, network calls, or dynamic execution. |
| internal/native/neon/unquote_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/unquote_subr_arm64.go | safe | No malicious patterns detected; the file contains only an assembly trampoline declaration with no executable logic, network access, or file system interaction. |
| internal/native/neon/validate_one_arm64.go | safe | No malicious patterns detected; the file contains only a declaration and wrapper for an assembly-implemented validation function with no executable behavior at import time. |
| internal/native/neon/validate_one_subr_arm64.go | safe | No malicious patterns detected in the generated assembly binding stub; it contains only build tags, package declaration, function declaration, and variable/constant assignments with no external interactions or file system/network activity. |
| internal/native/neon/validate_utf8_arm64.go | safe | No malicious patterns detected; the file is a generated Go source with a standard ARM64 assembly declaration for UTF-8 validation. |
| internal/native/neon/validate_utf8_fast_arm64.go | safe | No malicious patterns detected; the file contains only a standard Go wrapper for an ARM64 NEON-optimized UTF-8 validation function generated by Sonic, with no network, file, process, or obfuscated behavior. |
| internal/native/neon/validate_utf8_fast_subr_arm64.go | safe | This is a generated assembly bridge file for UTF-8 validation with no executable logic, network, file system, or process manipulation, and no malicious patterns detected. |
| internal/native/neon/validate_utf8_subr_arm64.go | safe | No malicious patterns detected; the file contains only generated assembly entry-point declarations for a UTF-8 validation routine with no executable code, network access, file manipulation, or dynamic loading behaviors. |
| internal/native/neon/value_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/value_subr_arm64.go | safe | No malicious patterns detected; the file is a minimal asm2asm-generated wrapper for the Go neon (Sonic) JSON library exposing a static subroutine entry point with no I/O, network, process, or dynamic execution behavior. |
| internal/native/neon/vnumber_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/native/neon/vnumber_subr_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/vsigned_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/native/neon/vsigned_subr_arm64.go | safe | No malicious patterns detected |
| internal/native/neon/vstring_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/native/neon/vstring_subr_arm64.go | safe | No malicious patterns detected; the file only declares a subroutine entry point and stack constants for generated assembly, with no network, filesystem, process, or dynamic execution activity. |
| internal/native/neon/vunsigned_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/native/neon/vunsigned_subr_arm64.go | safe | This is a generated Go assembly stub for a NEON subroutine entry point with no malicious patterns, network activity, credential access, or dynamic execution. |
| internal/native/sse/f32toa.go | safe | No malicious patterns detected; the file is a generated Go assembly wrapper for float32-to-string conversion using unsafe pointers without any exfiltration, execution, or installation-time behavior. |
| internal/native/sse/f32toa_subr.go | safe | This file is auto-generated assembly metadata for a float-to-string conversion routine with no network, filesystem, process, or obfuscation activity; no malicious patterns detected. |
| internal/native/sse/f32toa_text_amd64.go | safe | This file contains generated x86-64 assembly byte slices and constant lookup tables for a floating-point-to-ASCII conversion routine; no malicious patterns, network access, process execution, or credential harvesting were detected. |
| internal/native/sse/f64toa_subr.go | safe | This is a generated Go assembly binding file for a floating-point to ASCII conversion routine from the sonic JSON library, containing only PC/stack metadata and function registration with no executable or network code. |
| internal/native/sse/get_by_path.go | safe | No malicious patterns detected in the generated SSE get_by_path wrapper; it only performs an unsafe-pointer FFI call to a native function without exfiltration, execution, network, or filesystem activity. |
| internal/native/sse/get_by_path_subr.go | safe | Generated assembly support file for the bytedance/sonic JSON library; contains only metadata tables and loader registrations, with no malicious patterns detected. |
| internal/native/sse/html_escape_subr.go | safe | No malicious patterns detected; this is a generated assembly metadata file for the bytedance/sonic JSON library defining stack/PC mapping for an HTML escape function. |
| internal/native/sse/html_escape_text_amd64.go | safe | No malicious patterns detected; the file contains only generated x86-64 assembly for HTML escaping with no network, filesystem, process, or dynamic code execution behavior. |
| internal/native/sse/i64toa_subr.go | safe | No malicious patterns detected; the file contains only generated metadata for assembly function registration in the sonic library. |
| internal/native/sse/i64toa_text_amd64.go | safe | This file contains only auto-generated assembly byte arrays and lookup tables for a 64-bit integer to ASCII conversion routine, with no malicious patterns detected. |
| internal/native/sse/lspace.go | safe | No malicious patterns detected; the file is a generated low-level SIMD/assembly bridging stub for bytedance/sonic with no network, credential, or dynamic execution behavior. |
| internal/native/sse/lspace_subr.go | safe | No malicious patterns detected; this is auto-generated assembly-bridge metadata for the sonic JSON library with no network, filesystem, process, or dynamic execution behavior. |
| internal/native/sse/lspace_text_amd64.go | safe | This is auto-generated x86-64 assembly for a whitespace-skipping routine in a JSON parsing library; no malicious patterns detected. |
| internal/native/sse/parse_with_padding_subr.go | safe | No malicious patterns detected; the file contains generated metadata for a native SSE parsing function from the sonic JSON library. |
| internal/native/sse/quote.go | safe | No malicious patterns detected |
| internal/native/sse/quote_subr.go | safe | This is generated assembly metadata for the sonic JSON library's SSE quote function, containing only stack frame and PCSP tables with no executable or suspicious logic. |
| internal/native/sse/skip_array.go | safe | No malicious patterns detected; the file contains legitimate SIMD/SSE parsing stub code from the sonic JSON library using unsafe pointers and a function variable bound to a native symbol. |
| internal/native/sse/skip_array_subr.go | safe | No malicious patterns detected |
| internal/native/sse/skip_number_subr.go | safe | No malicious patterns detected; the file contains only generated metadata for a Go assembly function in the sonic library. |
| internal/native/sse/skip_number_text_amd64.go | safe | No malicious patterns detected; the file contains generated x86-64 assembly data for a Go SSE number-skipping routine with no external I/O, network, process, or credential access. |
| internal/native/sse/skip_object.go | safe | No malicious patterns detected; the file is a generated Go wrapper for a native skip_object function using unsafe pointers without exfiltration, execution, or filesystem manipulation. |
| internal/native/sse/skip_object_subr.go | safe | No malicious patterns detected; the file is a generated assembly trampoline for the bytedance/sonic JSON library with no network, filesystem, process, or credential-access behavior. |
| internal/native/sse/skip_one.go | safe | No malicious patterns detected; the file is a generated low-level FFI binding for JSON parsing within the ByteDance sonic library. |
| internal/native/sse/skip_one_fast_subr.go | safe | No malicious patterns detected; the file only contains generated metadata for a platform-specific assembly routine in the bytedance/sonic library. |
| internal/native/sse/skip_one_fast_text_amd64.go | safe | This is a generated assembly byte array for a JSON SSE skip-scan routine; it contains no network, filesystem, process, or credential-access logic. |
| internal/native/sse/skip_one_subr.go | safe | No malicious patterns detected |
| internal/native/sse/u64toa.go | safe | No malicious patterns detected; the file is a generated Go wrapper for a native uint64-to-ASCII conversion routine using unsafe pointers but contains no exfiltration, credential harvesting, dynamic execution, or other red-flag behavior. |
| internal/native/sse/u64toa_subr.go | safe | Generated assembly metadata file contains only static function pointer tables and stack layout information for an integer-to-string conversion routine, with no executable code or malicious patterns. |
| internal/native/sse/u64toa_text_amd64.go | safe | This is a generated x86-64 assembly implementation of an unsigned 64-bit integer to ASCII conversion routine with only numeric lookup tables and no malicious behavior. |
| internal/native/sse/unquote.go | safe | No malicious patterns detected; the file contains a generated, low-level unquote wrapper using unsafe pointers from the ByteDance Sonic JSON library with no data exfiltration, credential harvesting, obfuscated execution, network access, or install-time behavior. |
| internal/native/sse/unquote_subr.go | safe | No malicious patterns detected; file is generated assembly metadata for a JSON unquote function with no executable, network, or credential-harvesting behavior. |
| internal/native/sse/unquote_text_amd64.go | safe | This file contains only precompiled amd64 assembly for a JSON string unquoting routine, with no network, filesystem, process, credential, or dynamic execution behavior. |
| internal/native/sse/validate_one.go | safe | The file is a generated Go wrapper for a native SSE validation function using unsafe pointers and cgo-style function pointers, with no malicious patterns detected. |
| internal/native/sse/validate_one_subr.go | safe | No malicious patterns detected; file contains only generated metadata for an assembly validation function with no network, filesystem, process, or dynamic execution activity. |
| internal/native/sse/validate_utf8.go | safe | No malicious patterns detected; the code is a generated internal wrapper for a UTF-8 validation function using unsafe pointers as expected for performance-critical native code. |
| internal/native/sse/validate_utf8_fast_subr.go | safe | No malicious patterns detected; the file contains only auto-generated metadata for an assembly-based UTF-8 validation function from the bytedance/sonic package. |
| internal/native/sse/validate_utf8_fast_text_amd64.go | safe | This is a generated AMD64 assembly implementation of a UTF-8 validation function with no malicious patterns, network calls, file access, or dynamic execution. |
| internal/native/sse/validate_utf8_subr.go | safe | This is an auto-generated Go assembly stub for UTF-8 validation in the bytedance/sonic library with no malicious patterns, network activity, credential access, or dynamic code execution. |
| internal/native/sse/validate_utf8_text_amd64.go | safe | This file contains only auto-generated x86-64 assembly bytecode implementing a UTF-8 validation routine for the Go runtime's internal SSE package, with no network, filesystem, process, or dynamic execution behavior. |
| internal/native/sse/value.go | safe | No malicious patterns detected; this is a legitimate JSON parser internal file using unsafe pointers for performance, typical of the ByteDance Sonic library. |
| internal/native/sse/value_subr.go | safe | No malicious patterns detected; the file contains only generated assembly metadata for a JSON parsing library with no network, filesystem, process, or dynamic code execution behavior. |
| internal/native/sse/vnumber_subr.go | safe | No malicious patterns detected; the file contains only generated assembly metadata and function registration for a JSON number parser, with no network, filesystem, process, or dynamic execution behavior. |
| internal/native/sse/vsigned.go | safe | No malicious patterns detected; the code only bridges Go to optimized assembly for JSON parsing, with no network, filesystem, exec, or credential access. |
| internal/native/sse/vsigned_subr.go | safe | No malicious patterns detected; the file contains generated assembly registration metadata for the Sonic JSON library's SSE implementation. |
| internal/native/sse/vsigned_text_amd64.go | safe | This file contains generated x86-64 assembly for a JSON number-parsing routine (vsigned), implementing standard integer parse logic with no network, filesystem, process, or credential access, and no malicious patterns. |
| internal/native/sse/vstring_subr.go | safe | No malicious patterns detected in this asm2asm-generated SSE vstring function registration file for the bytedance/sonic JSON library. |
| internal/native/sse/vstring_text_amd64.go | safe | This file contains only auto-generated AMD64 assembly (as byte arrays) for a SIMD-optimized JSON string validation routine from the sonic/amd64 SIMD library; no malicious patterns such as network calls, credential harvesting, code execution, or process spawning are present. |
| internal/native/sse/vunsigned.go | safe | No malicious patterns detected; the file only contains low-level native function bindings with unsafe pointers for JSON parsing, consistent with the ByteDance Sonic library. |
| internal/native/sse/vunsigned_subr.go | safe | Generated assembly metadata file with no executable code, network, filesystem, or dynamic execution patterns detected. |
| internal/native/sse/vunsigned_text_amd64.go | safe | This is a generated Go assembly file containing x86-64 machine code for an unsigned integer parsing routine, with no malicious patterns, network activity, file system access, or dynamic code execution. |
| internal/native/types/types.go | safe | No malicious patterns detected; this is legitimate JSON parser type definitions and pooling utilities from the Sonic library. |
| internal/optcaching/fcache.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/resolver/fields.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/resolver/resolver.go | safe | No malicious patterns detected; the code is a legitimate reflection-based struct field resolver from ByteDance's sonic JSON library. |
| internal/rt/assertI2I.go | safe | No malicious patterns detected; the file contains legitimate low-level Go runtime type assertion code using unsafe imports as part of ByteDance's sonic library, with no exfiltration, exec, network, or file system activity. |
| internal/rt/base64_compat.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/rt/fastmem.go | safe | No malicious patterns detected; the code contains low-level unsafe memory manipulation utilities typical of high-performance parsers, with no data exfiltration, credential harvesting, obfuscation, or harmful behavior. |
| internal/rt/gotype_go126.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/rt/gotype_legacy.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/rt/int48.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/rt/map.go | safe | The file defines a struct that mirrors Go runtime map iterator layout using unsafe.Pointer for compatibility with Go runtime internals, with no network, filesystem, process, installation, or obfuscated code patterns detected. |
| internal/rt/table.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/rt/types.go | safe | No malicious patterns detected; the code only uses unsafe.Pointer for reflect type conversion and defines common Go type constants, with no network, filesystem, process, or dynamic execution activity. |
| internal/utils/skip.go | safe | The file contains only low-level string parsing utilities using unsafe pointer arithmetic for performance; no data exfiltration, credential harvesting, obfuscated payloads, network activity, process spawning, or other malicious patterns were found. |
| option/option.go | safe | Cleared by Jev triage; no further analysis needed |
| rawmessage.go | safe | Cleared by Jev triage; no further analysis needed |
| sonic.go | safe | Cleared by Jev triage; no further analysis needed |
| testdata/small.go | safe | Cleared by Jev triage; no further analysis needed |
| testdata/twitter.go | safe | Cleared by Jev triage; no further analysis needed |
| unquote/unquote_fallback.go | safe | Cleared by Jev triage; no further analysis needed |
| utf8/utf8.go | safe | No malicious patterns detected; the code is a UTF-8 validation and correction utility with no network, filesystem, process, or obfuscated behavior. |
| utf8/utf8_fallback.go | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of github.com/bytedance/sonic
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v1.15.4 | Needs review | 290 | Oct 5, 2026 |
Frequently asked questions
Is github.com/bytedance/sonic safe to use?
No confirmed malware was found in github.com/bytedance/sonic@v1.15.4, but the review flagged 63 medium, 67 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/bytedance/sonic contain malware?
No malware was identified in github.com/bytedance/sonic@v1.15.4 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/bytedance/sonic checked?
Togoder Security downloaded the published Go package and had an AI model read its 290 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/bytedance/sonic together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/bytedance/sonic@v1.15.4, cost nothing.