# golang.org/x/sys@v0.48.0 security report (Go)

- Verdict: **Critical risk** (risk level: critical)
- Scanned: 2026-10-05T19:11:03.000Z
- Files reviewed: 416
- Findings: 2 high, 12 medium, 24 low severity findings
- Report: https://security.togoder.click/go/golang.org/x/sys
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package golang.org/x/sys@v0.48.0 on Oct 5, 2026. An AI review of 416 source files produced 2 high, 12 medium, 24 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

## Findings

### [high] Feature detection bypass / forced capability enablement

Finding ID: `NPS-969DA01E649B`

File: `cpu/cpu_darwin_arm64.go:26`

The code unconditionally forces ARM64.HasAES, ARM64.HasPMULL, ARM64.HasSHA1, and ARM64.HasSHA2 to true using 'true ||' short-circuit logic. This means the runtime will report these CPU features as available even on hardware that does not support them. If any downstream code relies on these flags to select hardware-accelerated crypto routines, it could execute unsupported instructions, causing crashes, data corruption, or potentially exploitable misbehavior. This appears to be an intentional weakening of capability detection rather than benign feature reporting.

### [high] Tampering with runtime capability reporting

Finding ID: `NPS-153EB71683DB`

File: `cpu/cpu_darwin_arm64.go:27`

The 'true ||' pattern is used on four separate security-relevant flags (AES, PMULL, SHA1, SHA2), all of which are cryptographic acceleration features. Forcing them enabled is suspicious because it can silently alter which cryptographic implementation is used at runtime, potentially degrading security assumptions or introducing faults in security-sensitive code paths.

### [medium] Unsafe reflection and pointer manipulation

Finding ID: `NPS-C987CBBAB85C`

File: `execabs/execabs.go:58`

The code uses reflect and unsafe pointers to access and modify unexported fields (lookPathErr) of exec.Cmd. This bypasses Go's type safety and field visibility rules, potentially leading to memory corruption or undefined behavior. While the purpose is to fix a security issue, this technique is fragile and could be exploited if the struct layout changes.

### [medium] Build-time code execution

Finding ID: `NPS-FC9C40E789BD`

File: `unix/linux/mkall.go`

The file is a build tool (mkall.go) that spawns many external processes (make, gcc, go run, gofmt, mksyscall, mkpost, etc.) via os/exec. While this is legitimate for the Go syscall generator, any third-party package carrying this file should be treated as running arbitrary commands at build time.

### [medium] Environment variable harvesting

Finding ID: `NPS-4A9586DA0E0C`

File: `unix/linux/mkall.go`

setupEnvironment copies the entire os.Environ() into child process environments and appends GOOS/GOARCH/CC/GORUN. This propagates all host environment variables (potentially including credentials) to spawned commands.

### [medium] Commands constructed from external paths

Finding ID: `NPS-F0276B3D52F9`

File: `unix/linux/mkall.go`

LinuxDir, GlibcDir, and per-target GNUArch values derived from the targets table are used to build paths and invoke confScript (glibc configure) and make. If a caller supplies a malicious directory or the table were tampered with, arbitrary code is executed at build time.

### [medium] Unsafe temp directory usage

Finding ID: `NPS-8B9FF9F6589B`

File: `unix/linux/mkall.go:44`

Uses a hardcoded TempDir = "/tmp" with os.MkdirAll(..., os.ModePerm) (0777) to create world-writable directories (e.g. /tmp/<arch>/include). On a multi-user system this is susceptible to symlink/race attacks and clobbering by other users.

### [medium] Unsafe memory access via unsafe.Pointer

Finding ID: `NPS-DD5763C764DE`

File: `unix/syscall_linux.go`

The file makes extensive use of unsafe.Pointer for type punning, casting between socket address structures (e.g., SockaddrInet4, SockaddrInet6, SockaddrUnix, SockaddrCAN, etc.) and raw kernel structures. While expected in a syscall wrapper library, incorrect bounds checks or alignment assumptions could lead to memory corruption or information leaks. Examples include casting slices to raw sockaddr structs and using unsafe.Slice to read kernel-populated data (e.g., in anyToSockaddr for AF_UNIX, AF_PPPOX, AF_NFC).

### [medium] Potential out-of-bounds read

Finding ID: `NPS-F613CB4D5591`

File: `unix/syscall_linux.go`

In anyToSockaddr for AF_UNIX, the code assumes the path is NUL-terminated and reads up to len(pp.Path) without a hard bound check beyond the array size; although the array is fixed-size, a non-NUL-terminated kernel-provided path could cause the loop to read uninitialized bytes. Similar patterns exist in AF_PPPOX and AF_NFC LLCP where kernel-provided lengths are trusted with limited validation.

### [medium] Privileged operations exposed

Finding ID: `NPS-C7907A43D649`

File: `unix/syscall_linux.go`

The package provides wrappers for privileged syscalls such as ptrace, reboot, mount, swapon, init_module, delete_module, kexec_load, and keyctl. While these are legitimate system calls, exposing them without additional safeguards in a third-party library could facilitate privilege escalation or persistence if misused by downstream code.

### [medium] shared memory segment size race

Finding ID: `NPS-E8489F891EF7`

File: `unix/sysvshm_unix.go:26`

The segment size used to create the slice is retrieved via a separate IPC_STAT call after shmat. If another process modifies the segment size (e.g., via shmctl IPC_RMID or remapping) between shmat and IPC_STAT, the slice length may not match the mapped region, potentially causing out-of-bounds reads/writes.

### [medium] unsafe pointer usage

Finding ID: `NPS-93DC0F97FA4E`

File: `unix/sysvshm_unix.go:35`

The code uses unsafe.Pointer and unsafe.Slice to convert a raw memory address returned by shmat into a Go byte slice. This is an intentional part of the Unix shared memory API and is guarded by build tags for supported platforms, but unsafe usage can lead to memory corruption if the underlying segment size changes or is detached concurrently.

### [medium] Unsafe memory access

Finding ID: `NPS-521D150EF866`

File: `windows/svc/mgr/recovery.go:63`

Multiple functions use unsafe.Pointer and unsafe.Slice to interpret raw byte buffers returned from queryServiceConfig2. In RecoveryActions, if the buffer is empty or malformed, &b[0] could panic or misinterpret memory. The pointer p.Actions is dereferenced assuming valid structure layout, which could lead to out-of-bounds reads if ActionsCount is corrupted or maliciously set by a service configuration.

### [medium] Unsafe slice construction from external data

Finding ID: `NPS-1C4E6874169C`

File: `windows/svc/mgr/recovery.go:66`

RecoveryActions uses unsafe.Slice(p.Actions, int(p.ActionsCount)) directly on a pointer and count read from a Windows API response. If the underlying data is untrusted or corrupted, this could allow reading beyond the returned buffer. This is a potential memory safety issue.

### [low] System information gathering via sysctl

Finding ID: `NPS-F1189D0919A4`

File: `cpu/syscall_darwin_arm64_gc.go`

The code calls sysctlbyname to query Darwin kernel parameters (likely for CPU feature detection). This is a standard, non-malicious use of sysctl in the Go runtime/internal/cpu package for platform detection.

### [low] Use of unsafe pointer conversions

Finding ID: `NPS-F79ED139E31B`

File: `cpu/syscall_darwin_arm64_gc.go`

Uses unsafe.Pointer for syscall argument marshalling, which is typical for low-level syscall wrappers in the Go standard library and runtime. No obfuscation or malicious intent.

### [low] Spawns processes

Finding ID: `NPS-780502E427A1`

File: `execabs/execabs.go:70`

The package is a wrapper around os/exec and its primary function is to spawn external processes. The Command and CommandContext functions return exec.Cmd objects ready to run external commands. This is a normal but powerful capability that could be misused if the package is compromised or if input is not properly sanitized.

### [low] Filesystem writes outside package scope

Finding ID: `NPS-AB2B234754E2`

File: `unix/linux/mkall.go`

Writes generated outputs (zsysnum_*, zsyscall_*, ztypes_*, zerrors_*, zptrace_*, z*_linux.go) directly into the current working directory via os.Create, and also creates/removes files under /tmp.

### [low] Environment variable reliance

Finding ID: `NPS-6E57792EF9BD`

File: `unix/linux/mksysnum.go:109`

Reads GOOS, GOARCH_TARGET, GOARCH, GOLANG_SYS_BUILD, and CC environment variables and hard-fails unless GOLANG_SYS_BUILD=docker and CC is set. This is expected for a controlled build tool, but demonstrates environment-driven behavior.

### [low] Dynamic process invocation

Finding ID: `NPS-8464A311E452`

File: `unix/linux/mksysnum.go:129`

The CC value is used as the executable name for os/exec without validation. If an attacker can set CC in the build environment, arbitrary binaries could be executed during generation. However, this script is a legitimate Go source-tree generator (mksysnum), runs only with the 'ignore' build tag, and requires an explicit 'go run' invocation.

### [low] Command execution via os/exec

Finding ID: `NPS-E07106D5A00D`

File: `unix/linux/mksysnum.go:132`

The script invokes an external compiler (CC environment variable) via exec.Command(cc, args...).Output(). The command name comes from the CC environment variable and is executed with arguments from os.Args. This is standard for a code generator that preprocesses kernel headers, but an attacker controlling the environment (CC, GOOS, GOARCH, GOLANG_SYS_BUILD) could influence process execution. This file is guarded by '//go:build ignore' so it is not compiled into the unix package and is only run explicitly by the Go build system.

### [low] code generation tool

Finding ID: `NPS-8C3A4974F7EB`

File: `unix/mksyscall_aix_ppc64.go`

This is the standard Go source file mksyscall_aix_ppc64.go from the golang.org/x/sys repository. It is a build-time code generator that reads syscall prototypes from input files and writes generated Go source files (zsyscall_aix_ppc64.go, zsyscall_aix_ppc64_gc.go, zsyscall_aix_ppc64_gccgo.go) to the local working directory. The //go:build ignore tag prevents it from being compiled as part of the package.

### [low] file system write

Finding ID: `NPS-55E6D3D6E1A2`

File: `unix/mksyscall_aix_ppc64.go`

The program writes generated source files into the current working directory via os.WriteFile. This is expected behavior for a code generator and operates only on relative filenames within the current directory, not outside package scope.

### [low] external input parsing

Finding ID: `NPS-EEBEAD0F941E`

File: `unix/mksyscall_aix_ppc64.go`

The program reads file paths from command-line arguments and parses //sys directives. Input is trusted local source files supplied by the developer; there is no network input, no shell execution, and no interpolation of input into shell commands.

### [low] process execution

Finding ID: `NPS-F92338DB8292`

File: `unix/mksyscall_zos_s390x.go`

The program uses os/exec to run /bin/cat, gofmt, and read a fixed system file. This is expected for a code generator and is not malicious.

### [low] file system manipulation

Finding ID: `NPS-3241E641CFD7`

File: `unix/mksyscall_zos_s390x.go`

The program creates and writes generated Go/asm files (zsyscall, zsymaddr, zsysnum) in the working directory. No files outside the package scope are modified.

### [low] build-time code generation

Finding ID: `NPS-9F91FA0DA8DE`

File: `unix/mksyscall_zos_s390x.go:5`

This file has //go:build ignore and is only run manually as a generator. It does not execute at import, build, or install time.

### [low] Network fetch

Finding ID: `NPS-AF7E99D7C949`

File: `unix/mksysnum.go:47`

fetchFile performs HTTP GET requests to arbitrary URLs provided via command-line arguments. While this is for legitimate syscall table generation from official sources, it could be abused if the script were invoked with a malicious URL.

### [low] File system access

Finding ID: `NPS-6C601BB8F4B6`

File: `unix/mksysnum.go:56`

readFile opens a file specified by os.Args[1], which is outside the package scope and controlled entirely by whoever invokes the tool. Not malicious in itself but an attacker-controlled input path.

### [low] Main entry point / top-level execution

Finding ID: `NPS-AF425C4C0C6B`

File: `unix/mksysnum.go:71`

Contains a main() function guarded by //go:build ignore, so it does not execute at import time. Only runs when explicitly invoked via go run. This is normal for a code generator.

### [low] Environment variable access

Finding ID: `NPS-9AED79389B87`

File: `unix/mksysnum.go:78`

Reads GOOS_TARGET, GOOS, GOARCH_TARGET, GOARCH environment variables. This is standard for Go cross-compilation tooling and not credential harvesting.

### [low] Race condition in KeyctlString

Finding ID: `NPS-C6E79BB1B7C2`

File: `unix/syscall_linux.go`

KeyctlString loops to dynamically size a buffer based on the kernel-reported length. If an attacker can modify the key data between the sizing and reading syscalls (TOCTOU), it could lead to returning a truncated or mismatched string, though not directly exploitable for memory corruption.

### [low] No malicious patterns detected

Finding ID: `NPS-9663B61F1762`

File: `unix/syscall_linux.go`

No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, cryptocurrency mining, backdoor installation, reverse shells, suspicious network requests, or unauthorized file system manipulation were found. The code is part of the official Go x/sys/unix package and follows standard syscall wrapper patterns.

### [low] memory management concern

Finding ID: `NPS-91C612AF5981`

File: `unix/zsyscall_aix_ppc.go`

C.CString allocations for path strings are not freed with C.free, causing a memory leak per call. This is a code quality issue rather than a security vulnerability, and is a known artifact of mksyscall-generated code.

### [low] CGO dynamic linking

Finding ID: `NPS-A78FF3FDA255`

File: `unix/zsyscall_aix_ppc64_gc.go:12`

The file uses //go:cgo_import_dynamic and //go:linkname directives to bind to AIX libc functions. These are standard mechanisms for Go's syscall package on AIX and are not malicious, but they do involve dynamic linking to system libraries.

### [low] Unsafe pointer usage

Finding ID: `NPS-77A12D8FC4BC`

File: `unix/zsyscall_aix_ppc64_gc.go:328`

The file uses unsafe.Pointer conversions to pass function pointers to syscall6 and rawSyscall6. This is standard in Go generated syscall wrappers and is not indicative of malicious intent.

### [low] DLL preloading risk (documented)

Finding ID: `NPS-4CD77D41529E`

File: `windows/dll_windows.go:46`

LoadDLL and NewLazyDLL accept relative paths and are documented to be subject to DLL preloading attacks. This is a known Windows API behavior, and the code explicitly warns users to use NewLazySystemDLL or LoadLibraryEx for safe loading of system DLLs.

### [low] Potential out-of-bounds slice

Finding ID: `NPS-C1FD16E3D4DA`

File: `windows/svc/mgr/recovery.go:42`

In SetRecoveryActions, after building a slice 'actions', &actions[0] is taken without checking if len(actions) > 0. Although RecoveryActions nil check handles nil, an empty non-nil slice would cause an index out of range panic at runtime. This is a robustness issue but not directly malicious.

## Files reviewed

- `cpu/cpu_darwin_arm64.go` (critical): The file contains suspicious unconditional forcing of ARM64 cryptographic feature flags to true, which tampers with CPU capability detection and could cause unsupported instruction execution or cryptographic misbehavior.
- `execabs/execabs.go` (medium): The execabs package is a legitimate security-focused wrapper around os/exec that safely enforces absolute path resolution, but its use of unsafe pointer manipulation and process spawning warrants cautious review.
- `unix/linux/mkall.go` (medium): This is the legitimate Go x/sys linux/mkall.go build tool that deliberately spawns compilers and make, but its unsafe /tmp/0777 usage, propagation of the full host environment to child processes, and build-time execution of external scripts warrant caution if encountered outside the official Go repository.
- `unix/linux/mksysnum.go` (medium): This is a legitimate Go syscall-number generator that spawns an external compiler from the CC environment variable, but it is not part of the compiled package and contains no malicious exfiltration, credential harvesting, backdoors, or obfuscated payloads.
- `unix/mksysnum.go` (medium): Legitimate Go code generator for syscall tables with benign network/file access limited to explicit command-line inputs and no malicious patterns, though arbitrary URL/path inputs carry minimal risk.
- `unix/syscall_linux.go` (medium): The code is the standard Go x/sys/unix syscall wrapper with expected unsafe memory operations and privileged syscall exposure, but no malicious patterns were identified.
- `unix/sysvshm_unix.go` (medium): This is a standard Go x/sys/unix wrapper for SysV shared memory that uses unsafe pointers and performs a separate IPC_STAT call, which are expected but carry inherent memory-safety risks; no malicious behavior such as exfiltration, process spawning, or backdoor installation was found.
- `windows/svc/mgr/recovery.go` (medium): The code contains unsafe pointer and slice usage typical of Windows system administration APIs, with potential memory safety risks when handling untrusted service configuration data, but no direct malicious patterns such as exfiltration, backdoors, or code execution.
- `cpu/byteorder.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu.go` (safe): No malicious patterns detected; this is the standard Go CPU feature detection package with no data exfiltration, obfuscation, or suspicious behavior.
- `cpu/cpu_aix.go` (safe): This is a standard Go CPU feature detection file for AIX that only queries system configuration and sets capability flags with no network, filesystem, process, or obfuscation concerns.
- `cpu/cpu_arm.go` (safe): No malicious patterns detected; the code only defines CPU feature constants and registers feature detection options for ARM processors.
- `cpu/cpu_arm64.go` (safe): This is a legitimate Go standard library CPU feature detection file for ARM64 with no malicious patterns detected.
- `cpu/cpu_darwin_arm64_other.go` (safe): No malicious patterns detected; the file only sets ARM64 CPU feature flags at init time using safe, static assignments with no network, filesystem, or process activity.
- `cpu/cpu_darwin_x86.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gc_arm64.go` (safe): No malicious patterns detected
- `cpu/cpu_gc_riscv64.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gc_s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gc_x86.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gccgo_arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gccgo_s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_gccgo_x86.go` (safe): No malicious patterns detected; the file contains only standard Go runtime CPU feature detection via gccgo extern declarations.
- `cpu/cpu_linux.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_arm.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_arm64.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_loong64.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_mips64x.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_noinit.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_linux_ppc64x.go` (safe): No malicious patterns detected
- `cpu/cpu_linux_riscv64.go` (safe): No malicious patterns detected; the code performs legitimate RISC-V CPU feature detection via the riscv_hwprobe syscall and HWCAP, with no network, filesystem, process, or dynamic execution activity.
- `cpu/cpu_linux_s390x.go` (safe): No malicious patterns detected; this is standard Go CPU feature detection code for s390x using HWCAP bitmask checks.
- `cpu/cpu_loong64.go` (safe): No malicious patterns detected in the Go CPU feature detection file for LoongArch64; it contains only standard hardware capability checks with no network, filesystem, or process manipulation.
- `cpu/cpu_mips64x.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_mipsx.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_netbsd_amd64.go` (safe): This is standard Go standard library CPU feature detection code for NetBSD/amd64 that disables AVX features due to a known OS signal-handling bug, with no malicious patterns detected.
- `cpu/cpu_netbsd_arm64.go` (safe): This is a standard Go runtime CPU feature detection file for NetBSD/arm64 that uses sysctl system calls to read hardware capabilities, with no malicious patterns detected.
- `cpu/cpu_openbsd_arm64.go` (safe): No malicious patterns detected; code is standard Go standard library CPU feature detection for OpenBSD/arm64 using sysctl.
- `cpu/cpu_other_arm.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_other_arm64.go` (safe): No malicious patterns detected
- `cpu/cpu_other_mips64x.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_other_ppc64x.go` (safe): No malicious patterns detected
- `cpu/cpu_other_riscv64.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_other_x86.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_ppc64x.go` (safe): This is a standard Go runtime internal CPU feature detection file for ppc64/ppc64le architectures with no malicious patterns.
- `cpu/cpu_riscv64.go` (safe): No malicious patterns detected
- `cpu/cpu_s390x.go` (safe): No malicious patterns detected
- `cpu/cpu_sparc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_wasm.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/cpu_windows.go` (safe): Standard Go standard library CPU feature detection code with no malicious patterns detected
- `cpu/cpu_windows_arm64.go` (safe): This is a legitimate Go standard library CPU feature detection file for Windows ARM64 with no malicious patterns.
- `cpu/cpu_x86.go` (safe): This is a standard Go standard library CPU feature detection file that uses CPUID instructions to identify x86 processor capabilities, with no malicious patterns.
- `cpu/cpu_zos.go` (safe): No malicious patterns detected
- `cpu/cpu_zos_s390x.go` (safe): No malicious patterns detected
- `cpu/endian_big.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/endian_little.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/hwcap_linux.go` (safe): This is standard Go standard library code that reads CPU hardware capabilities from /proc/self/auxv with no malicious patterns detected
- `cpu/parse.go` (safe): Cleared by Jev triage; no further analysis needed
- `cpu/proc_cpuinfo_linux.go` (safe): The code reads /proc/cpuinfo on Linux ARM64 to detect CPU features and contains no malicious patterns; it is a legitimate part of the Go standard library.
- `cpu/runtime_auxv.go` (safe): No malicious patterns detected
- `cpu/runtime_auxv_go121.go` (safe): No malicious patterns detected; this is a standard Go internal CPU feature detection file using linkname to access runtime auxiliary vector.
- `cpu/syscall_aix_gccgo.go` (safe): The file contains a standard syscall wrapper for AIX/gccgo without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or network activity.
- `cpu/syscall_aix_ppc64_gc.go` (safe): This is a legitimate, minimal Go runtime file from the standard library that makes a dynamic syscall to getsystemcfg on AIX for CPU feature detection, with no malicious patterns present.
- `cpu/syscall_darwin_arm64_gc.go` (safe): The file is a legitimate Go runtime/internal/cpu helper for Darwin arm64 that makes sysctl calls for CPU feature detection; no malicious patterns were found.
- `cpu/syscall_darwin_x86_gc.go` (safe): No malicious patterns detected; the code contains legitimate Darwin sysctl system call wrappers for CPU detection with no exfiltration, obfuscation, or suspicious behavior.
- `cpu/zcpu_windows.go` (safe): No malicious patterns detected; code is a standard Go generated file accessing kernel32.dll for CPU feature detection on Windows.
- `execabs/execabs_go118.go` (safe): No malicious patterns detected
- `execabs/execabs_go119.go` (safe): No malicious patterns detected; the file contains only small helper functions wrapping standard library error checks for Go 1.19 compatibility.
- `plan9/const_plan9.go` (safe): Cleared by Jev triage; no further analysis needed
- `plan9/dir_plan9.go` (safe): Cleared by Jev triage; no further analysis needed
- `plan9/env_plan9.go` (safe): No malicious patterns detected
- `plan9/errors_plan9.go` (safe): This file contains only standard Plan 9 OS constant definitions and statically initialized error variables; no malicious patterns, dynamic code, network activity, or filesystem/process manipulation were detected.
- `plan9/mksyscall.go` (safe): This is a legitimate Go code generation tool from the standard library that parses syscall declarations and generates system call wrapper code, with no malicious patterns detected.
- `plan9/pwd_plan9.go` (safe): No malicious patterns detected; this is a minimal, legitimate Plan 9 syscall wrapper from the Go standard library.
- `plan9/race.go` (safe): No malicious patterns detected; this is a standard Go standard library race detector support file for Plan 9, containing only runtime race instrumentation wrappers.
- `plan9/race0.go` (safe): No malicious patterns detected
- `plan9/str.go` (safe): Cleared by Jev triage; no further analysis needed
- `plan9/syscall.go` (safe): No malicious patterns detected; this is standard Go x/sys Plan 9 system call support code from the Go project.
- `plan9/syscall_plan9.go` (safe): No malicious patterns detected; the file contains standard Plan 9 system call bindings from the Go standard library.
- `plan9/zsyscall_plan9_386.go` (safe): This is a standard Go generated syscall wrapper file for Plan 9 386 architecture, containing only legitimate system call bindings and unsafe pointer usage typical of the Go standard library, with no malicious patterns detected.
- `plan9/zsyscall_plan9_amd64.go` (safe): No malicious patterns detected; this is standard auto-generated Go syscall wrapper code for Plan 9 amd64.
- `plan9/zsyscall_plan9_arm.go` (safe): This is a standard Go syscall binding file for Plan 9 ARM, generated by mksyscall, containing only low-level OS syscall wrappers with no malicious patterns.
- `plan9/zsysnum_plan9.go` (safe): No malicious patterns detected; the file only contains constant syscall number definitions for Plan 9.
- `unix/affinity_linux.go` (safe): No malicious patterns detected; this is a standard Go syscall wrapper for Linux CPU affinity operations with no network, filesystem, or process execution behavior.
- `unix/aliases.go` (safe): No malicious patterns detected
- `unix/auxv.go` (safe): No malicious patterns detected
- `unix/auxv_unsupported.go` (safe): This is a standard Go standard library compatibility stub that returns ENOTSUP on unsupported build configurations, with no malicious patterns detected.
- `unix/bluetooth_linux.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/bpxsvc_zos.go` (safe): This is legitimate z/OS-specific system call wrapper code from the Go standard library, with no malicious patterns detected.
- `unix/cap_freebsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/constants.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_aix_ppc.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_aix_ppc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_darwin.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_dragonfly.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_freebsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_linux.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_netbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_openbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dev_zos.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/dirent.go` (safe): No malicious patterns detected in this standard Go syscall directory parsing code.
- `unix/endian_big.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/endian_little.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/env_unix.go` (safe): No malicious patterns detected
- `unix/fcntl.go` (safe): No malicious patterns detected
- `unix/fcntl_darwin.go` (safe): No malicious patterns detected
- `unix/fcntl_linux_32bit.go` (safe): No malicious patterns detected
- `unix/fdset.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/gccgo.go` (safe): No malicious patterns detected; this is a standard Go syscall wrapper for gccgo with build constraints for non-AIX/non-Hurd Unix systems.
- `unix/gccgo_linux_amd64.go` (safe): No malicious patterns detected
- `unix/ifreq_linux.go` (safe): No malicious patterns detected; the code is a legitimate low-level unsafe wrapper for Linux interface requests from the Go standard library.
- `unix/internal/mkmerge/mkmerge.go` (safe): This is a legitimate Go source file from the Go standard library's internal tooling; it performs AST-based source merging with no network, credential, execution, or obfuscation concerns.
- `unix/ioctl_linux.go` (safe): No malicious patterns detected; the code is a standard Go library ioctl wrapper with no exfiltration, obfuscation, or backdoor behavior.
- `unix/ioctl_signed.go` (safe): No malicious patterns detected; the file contains standard Go ioctl wrapper functions for AIX and Solaris with no exfiltration, execution, or suspicious behavior.
- `unix/ioctl_unsigned.go` (safe): The file is a standard part of the Go x/sys/unix package providing ioctl wrappers with no malicious patterns, network activity, or code execution.
- `unix/ioctl_zos.go` (safe): This is a standard Go standard library ioctl wrapper file for z/OS; no malicious patterns, network activity, credential access, or dynamic code execution present.
- `unix/mkasm.go` (safe): This is a standard Go code generation tool from the Go standard library that creates assembly trampolines; it performs only local file reading and writing with no malicious patterns.
- `unix/mkpost.go` (safe): This is a legitimate Go source file from the standard library's golang.org/x/sys repository; it is a build-time code generation helper that performs regex-based transformations on cgo output and contains no malicious patterns.
- `unix/mksyscall.go` (safe): No malicious patterns detected; this is a legitimate Go code generator for system call wrappers in the golang.org/x/sys repository.
- `unix/mksyscall_aix_ppc.go` (safe): This is a legitimate Go code generation tool from the official golang.org/x/sys repository that reads syscall prototypes and generates wrapper code, with no malicious patterns detected.
- `unix/mksyscall_aix_ppc64.go` (safe): This is the legitimate Go x/sys code generator for AIX syscall wrappers; it only performs local file reads/writes and contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, or shell execution.
- `unix/mksyscall_solaris.go` (safe): This is a standard Go code generator from the golang.org/x/sys repository that produces syscall wrappers for Solaris; no malicious patterns, network activity, credential access, or obfuscation were detected.
- `unix/mksyscall_zos_s390x.go` (safe): Standard Go syscall code generator for z/OS s390x that only reads a fixed system file and writes generated source files; no malicious patterns detected.
- `unix/mksysctl_openbsd.go` (safe): No malicious patterns detected; this is a standard Go code generator that parses OpenBSD header files to produce sysctl MIB definitions.
- `unix/mmap_nomremap.go` (safe): No malicious patterns detected; this is a standard Go standard-library source file defining an mmapper initialization for memory mapping utilities.
- `unix/mremap.go` (safe): No malicious patterns detected; the code is a legitimate low-level memory mapping utility from the Go standard library's unix package.
- `unix/pagesize_unix.go` (safe): No malicious patterns detected
- `unix/pledge_openbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/ptrace_darwin.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/ptrace_ios.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/race.go` (safe): No malicious patterns detected
- `unix/race0.go` (safe): This is a standard Go standard library race detector stub file with no malicious patterns; all functions are empty no-ops and no network, filesystem, process, or dynamic code execution is present.
- `unix/readdirent_getdents.go` (safe): No malicious patterns detected
- `unix/readdirent_getdirentries.go` (safe): This is a standard Go standard library wrapper for the getdirentries syscall on darwin/zos with no malicious patterns detected.
- `unix/readv_unix.go` (safe): No malicious patterns detected; the code is a standard part of the Go standard library for vectored I/O operations.
- `unix/sockcmsg_dragonfly.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/sockcmsg_linux.go` (safe): No malicious patterns detected
- `unix/sockcmsg_unix.go` (safe): No malicious patterns detected; this is standard Go standard-library code for socket control message parsing.
- `unix/sockcmsg_unix_other.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/sockcmsg_zos.go` (safe): No malicious patterns detected; this is a legitimate Go standard library syscall helper for encoding and parsing socket control messages (Unix credentials, packet info) on z/OS.
- `unix/syscall.go` (safe): No malicious patterns detected
- `unix/syscall_aix.go` (safe): No malicious patterns detected; this is a standard Go syscall wrapper file for AIX from the golang.org/x/sys/unix package.
- `unix/syscall_aix_ppc.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_aix_ppc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_bsd.go` (safe): This is a standard Go syscall wrapper file for BSD systems from the official golang.org/x/sys/unix package, containing only legitimate system call bindings and socket address conversion routines with no malicious patterns.
- `unix/syscall_darwin.go` (safe): No malicious patterns detected; this is standard Go syscall wrapper code for Darwin with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `unix/syscall_darwin_amd64.go` (safe): No malicious patterns detected
- `unix/syscall_darwin_arm64.go` (safe): This is a standard Go syscall compatibility file with only type conversion helpers and syscall declarations; no malicious patterns were detected.
- `unix/syscall_darwin_libSystem.go` (safe): This is a standard Go standard library file that declares low-level syscall functions and uses go:linkname to link them to runtime implementations, with no malicious patterns detected.
- `unix/syscall_dragonfly.go` (safe): No malicious patterns detected
- `unix/syscall_dragonfly_amd64.go` (safe): This is a legitimate Go standard library/x/sys file containing low-level DragonFly BSD system call wrappers and type conversion helpers with no malicious patterns.
- `unix/syscall_freebsd.go` (safe): No malicious patterns detected; this is standard Go FreeBSD syscall wrapper code from the official golang.org/x/sys repository.
- `unix/syscall_freebsd_386.go` (safe): No malicious patterns detected; the code is a standard part of the Go x/sys/unix package with platform-specific syscall helpers.
- `unix/syscall_freebsd_amd64.go` (safe): No malicious patterns detected
- `unix/syscall_freebsd_arm.go` (safe): No malicious patterns detected
- `unix/syscall_freebsd_arm64.go` (safe): No malicious patterns detected; generated syscall wrapper code for FreeBSD arm64 with no external I/O, credential access, or code execution.
- `unix/syscall_freebsd_riscv64.go` (safe): No malicious patterns detected; this is standard Go low-level syscall glue code for FreeBSD/riscv64 with no network, file, process, or obfuscation activity.
- `unix/syscall_hurd.go` (safe): No malicious patterns detected; the code is a standard Go syscall wrapper for ioctl on Hurd with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `unix/syscall_hurd_386.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_illumos.go` (safe): No malicious patterns detected
- `unix/syscall_linux_386.go` (safe): This is a standard Go standard library syscall wrapper file for Linux 386 with no malicious patterns, obfuscation, network exfiltration, or install-time execution.
- `unix/syscall_linux_alarm.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_linux_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_linux_amd64_gc.go` (safe): No malicious patterns detected
- `unix/syscall_linux_arm.go` (safe): No malicious patterns detected; this is a standard Go syscall wrapper for Linux ARM with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `unix/syscall_linux_arm64.go` (safe): This is a standard Go unix syscall wrapper file for Linux on arm64 with no malicious patterns, no network exfiltration, no credential harvesting, no obfuscated code execution, and no install-time hooks.
- `unix/syscall_linux_gc.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_linux_gc_386.go` (safe): No malicious patterns detected
- `unix/syscall_linux_gc_arm.go` (safe): No malicious patterns detected
- `unix/syscall_linux_gccgo_386.go` (safe): This is standard Go syscall wrapper code for Linux 386 gccgo architecture with no malicious patterns detected.
- `unix/syscall_linux_gccgo_arm.go` (safe): Legitimate Go standard library low-level syscall wrapper for _llseek with no malicious patterns
- `unix/syscall_linux_loong64.go` (safe): No malicious patterns detected; this is standard Go syscall wrapper code for Linux on the loong64 architecture.
- `unix/syscall_linux_mips64x.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_linux_mipsx.go` (safe): Standard Go syscall wrappers for Linux MIPS architectures with no malicious patterns detected
- `unix/syscall_linux_ppc.go` (safe): No malicious patterns detected
- `unix/syscall_linux_ppc64x.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_linux_riscv64.go` (safe): This is a legitimate portion of the Go standard library's syscall bindings for Linux riscv64, containing only standard syscall wrappers and helper functions with no malicious patterns.
- `unix/syscall_linux_s390x.go` (safe): No malicious patterns detected; the file contains standard Linux s390x syscall wrappers from the Go x/sys/unix package.
- `unix/syscall_linux_sparc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_netbsd.go` (safe): This is the standard Go x/sys/unix package file for NetBSD syscall bindings; no malicious patterns, exfiltration, backdoors, or suspicious behavior detected.
- `unix/syscall_netbsd_386.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_netbsd_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_netbsd_arm.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_netbsd_arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd.go` (safe): No malicious patterns detected; this is standard Go x/sys/unix OpenBSD syscall wrapper code with only expected system call bindings and data conversions.
- `unix/syscall_openbsd_386.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_arm.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_libc.go` (safe): No malicious patterns detected; the file only declares low-level syscall wrappers via linkname for OpenBSD runtime integration.
- `unix/syscall_openbsd_mips64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_ppc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_openbsd_riscv64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_solaris.go` (safe): No malicious patterns detected; this is a standard Go standard library syscall wrapper file with no exfiltration, obfuscation, or backdoor behavior.
- `unix/syscall_solaris_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/syscall_unix.go` (safe): No malicious patterns detected
- `unix/syscall_unix_gc.go` (safe): No malicious patterns detected
- `unix/syscall_unix_gc_ppc64x.go` (safe): No malicious patterns detected; the file contains standard syscall wrappers for ppc64/ppc64le Linux with no network, file, process, or obfuscation behavior.
- `unix/syscall_zos_s390x.go` (safe): This is a standard Go syscall implementation for z/OS s390x; the init() function only reads environment variables for optional tracing configuration and does not exhibit any malicious patterns.
- `unix/sysvshm_linux.go` (safe): Cleared by Jev triage; no further analysis needed
- `unix/sysvshm_unix_other.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
