Togoder security

Go package security report

golang.org/x/sys@v0.48.0 security report

Critical: dangerous or likely malicious code found.

Critical risk Version v0.48.0 Files reviewed 416 Size 8.3 MB Scanned

Summary

Togoder Security scanned the Go package golang.org/x/sys@v0.48.0 on Oct 5, 2026. An AI review of 416 source files produced 2 high, 12 medium, 24 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

0
critical
2
high
12
medium
24
low

Findings 38

high

Feature detection bypass / forced capability enablement

NPS-969DA01E649B

The code unconditionally forces ARM64.HasAES, ARM64.HasPMULL, ARM64.HasSHA1, and ARM64.HasSHA2 to true using 'true ||' short-circuit logic. This means the runtime will report these CPU features as available even on hardware that does not support them. If any downstream code relies on these flags to select hardware-accelerated crypto routines, it could execute unsupported instructions, causing crashes, data corruption, or potentially exploitable misbehavior. This appears to be an intentional weakening of capability detection rather than benign feature reporting.

cpu/cpu_darwin_arm64.go:26
high

Tampering with runtime capability reporting

NPS-153EB71683DB

The 'true ||' pattern is used on four separate security-relevant flags (AES, PMULL, SHA1, SHA2), all of which are cryptographic acceleration features. Forcing them enabled is suspicious because it can silently alter which cryptographic implementation is used at runtime, potentially degrading security assumptions or introducing faults in security-sensitive code paths.

cpu/cpu_darwin_arm64.go:27
medium

Unsafe reflection and pointer manipulation

NPS-C987CBBAB85C

The code uses reflect and unsafe pointers to access and modify unexported fields (lookPathErr) of exec.Cmd. This bypasses Go's type safety and field visibility rules, potentially leading to memory corruption or undefined behavior. While the purpose is to fix a security issue, this technique is fragile and could be exploited if the struct layout changes.

execabs/execabs.go:58
medium

Build-time code execution

NPS-FC9C40E789BD

The file is a build tool (mkall.go) that spawns many external processes (make, gcc, go run, gofmt, mksyscall, mkpost, etc.) via os/exec. While this is legitimate for the Go syscall generator, any third-party package carrying this file should be treated as running arbitrary commands at build time.

unix/linux/mkall.go
medium

Environment variable harvesting

NPS-4A9586DA0E0C

setupEnvironment copies the entire os.Environ() into child process environments and appends GOOS/GOARCH/CC/GORUN. This propagates all host environment variables (potentially including credentials) to spawned commands.

unix/linux/mkall.go
medium

Commands constructed from external paths

NPS-F0276B3D52F9

LinuxDir, GlibcDir, and per-target GNUArch values derived from the targets table are used to build paths and invoke confScript (glibc configure) and make. If a caller supplies a malicious directory or the table were tampered with, arbitrary code is executed at build time.

unix/linux/mkall.go
medium

Unsafe temp directory usage

NPS-8B9FF9F6589B

Uses a hardcoded TempDir = "/tmp" with os.MkdirAll(..., os.ModePerm) (0777) to create world-writable directories (e.g. /tmp/<arch>/include). On a multi-user system this is susceptible to symlink/race attacks and clobbering by other users.

unix/linux/mkall.go:44
medium

Unsafe memory access via unsafe.Pointer

NPS-DD5763C764DE

The file makes extensive use of unsafe.Pointer for type punning, casting between socket address structures (e.g., SockaddrInet4, SockaddrInet6, SockaddrUnix, SockaddrCAN, etc.) and raw kernel structures. While expected in a syscall wrapper library, incorrect bounds checks or alignment assumptions could lead to memory corruption or information leaks. Examples include casting slices to raw sockaddr structs and using unsafe.Slice to read kernel-populated data (e.g., in anyToSockaddr for AF_UNIX, AF_PPPOX, AF_NFC).

unix/syscall_linux.go
medium

Potential out-of-bounds read

NPS-F613CB4D5591

In anyToSockaddr for AF_UNIX, the code assumes the path is NUL-terminated and reads up to len(pp.Path) without a hard bound check beyond the array size; although the array is fixed-size, a non-NUL-terminated kernel-provided path could cause the loop to read uninitialized bytes. Similar patterns exist in AF_PPPOX and AF_NFC LLCP where kernel-provided lengths are trusted with limited validation.

unix/syscall_linux.go
medium

Privileged operations exposed

NPS-C7907A43D649

The package provides wrappers for privileged syscalls such as ptrace, reboot, mount, swapon, init_module, delete_module, kexec_load, and keyctl. While these are legitimate system calls, exposing them without additional safeguards in a third-party library could facilitate privilege escalation or persistence if misused by downstream code.

unix/syscall_linux.go
medium

shared memory segment size race

NPS-E8489F891EF7

The segment size used to create the slice is retrieved via a separate IPC_STAT call after shmat. If another process modifies the segment size (e.g., via shmctl IPC_RMID or remapping) between shmat and IPC_STAT, the slice length may not match the mapped region, potentially causing out-of-bounds reads/writes.

unix/sysvshm_unix.go:26
medium

unsafe pointer usage

NPS-93DC0F97FA4E

The code uses unsafe.Pointer and unsafe.Slice to convert a raw memory address returned by shmat into a Go byte slice. This is an intentional part of the Unix shared memory API and is guarded by build tags for supported platforms, but unsafe usage can lead to memory corruption if the underlying segment size changes or is detached concurrently.

unix/sysvshm_unix.go:35
medium

Unsafe memory access

NPS-521D150EF866

Multiple functions use unsafe.Pointer and unsafe.Slice to interpret raw byte buffers returned from queryServiceConfig2. In RecoveryActions, if the buffer is empty or malformed, &b[0] could panic or misinterpret memory. The pointer p.Actions is dereferenced assuming valid structure layout, which could lead to out-of-bounds reads if ActionsCount is corrupted or maliciously set by a service configuration.

windows/svc/mgr/recovery.go:63
medium

Unsafe slice construction from external data

NPS-1C4E6874169C

RecoveryActions uses unsafe.Slice(p.Actions, int(p.ActionsCount)) directly on a pointer and count read from a Windows API response. If the underlying data is untrusted or corrupted, this could allow reading beyond the returned buffer. This is a potential memory safety issue.

windows/svc/mgr/recovery.go:66
low

System information gathering via sysctl

NPS-F1189D0919A4

The code calls sysctlbyname to query Darwin kernel parameters (likely for CPU feature detection). This is a standard, non-malicious use of sysctl in the Go runtime/internal/cpu package for platform detection.

cpu/syscall_darwin_arm64_gc.go
low

Use of unsafe pointer conversions

NPS-F79ED139E31B

Uses unsafe.Pointer for syscall argument marshalling, which is typical for low-level syscall wrappers in the Go standard library and runtime. No obfuscation or malicious intent.

cpu/syscall_darwin_arm64_gc.go
low

Spawns processes

NPS-780502E427A1

The package is a wrapper around os/exec and its primary function is to spawn external processes. The Command and CommandContext functions return exec.Cmd objects ready to run external commands. This is a normal but powerful capability that could be misused if the package is compromised or if input is not properly sanitized.

execabs/execabs.go:70
low

Filesystem writes outside package scope

NPS-AB2B234754E2

Writes generated outputs (zsysnum_*, zsyscall_*, ztypes_*, zerrors_*, zptrace_*, z*_linux.go) directly into the current working directory via os.Create, and also creates/removes files under /tmp.

unix/linux/mkall.go
low

Environment variable reliance

NPS-6E57792EF9BD

Reads GOOS, GOARCH_TARGET, GOARCH, GOLANG_SYS_BUILD, and CC environment variables and hard-fails unless GOLANG_SYS_BUILD=docker and CC is set. This is expected for a controlled build tool, but demonstrates environment-driven behavior.

unix/linux/mksysnum.go:109
low

Dynamic process invocation

NPS-8464A311E452

The CC value is used as the executable name for os/exec without validation. If an attacker can set CC in the build environment, arbitrary binaries could be executed during generation. However, this script is a legitimate Go source-tree generator (mksysnum), runs only with the 'ignore' build tag, and requires an explicit 'go run' invocation.

unix/linux/mksysnum.go:129
low

Command execution via os/exec

NPS-E07106D5A00D

The script invokes an external compiler (CC environment variable) via exec.Command(cc, args...).Output(). The command name comes from the CC environment variable and is executed with arguments from os.Args. This is standard for a code generator that preprocesses kernel headers, but an attacker controlling the environment (CC, GOOS, GOARCH, GOLANG_SYS_BUILD) could influence process execution. This file is guarded by '//go:build ignore' so it is not compiled into the unix package and is only run explicitly by the Go build system.

unix/linux/mksysnum.go:132
low

code generation tool

NPS-8C3A4974F7EB

This is the standard Go source file mksyscall_aix_ppc64.go from the golang.org/x/sys repository. It is a build-time code generator that reads syscall prototypes from input files and writes generated Go source files (zsyscall_aix_ppc64.go, zsyscall_aix_ppc64_gc.go, zsyscall_aix_ppc64_gccgo.go) to the local working directory. The //go:build ignore tag prevents it from being compiled as part of the package.

unix/mksyscall_aix_ppc64.go
low

file system write

NPS-55E6D3D6E1A2

The program writes generated source files into the current working directory via os.WriteFile. This is expected behavior for a code generator and operates only on relative filenames within the current directory, not outside package scope.

unix/mksyscall_aix_ppc64.go
low

external input parsing

NPS-EEBEAD0F941E

The program reads file paths from command-line arguments and parses //sys directives. Input is trusted local source files supplied by the developer; there is no network input, no shell execution, and no interpolation of input into shell commands.

unix/mksyscall_aix_ppc64.go
low

process execution

NPS-F92338DB8292

The program uses os/exec to run /bin/cat, gofmt, and read a fixed system file. This is expected for a code generator and is not malicious.

unix/mksyscall_zos_s390x.go
low

file system manipulation

NPS-3241E641CFD7

The program creates and writes generated Go/asm files (zsyscall, zsymaddr, zsysnum) in the working directory. No files outside the package scope are modified.

unix/mksyscall_zos_s390x.go
low

build-time code generation

NPS-9F91FA0DA8DE

This file has //go:build ignore and is only run manually as a generator. It does not execute at import, build, or install time.

unix/mksyscall_zos_s390x.go:5
low

Network fetch

NPS-AF7E99D7C949

fetchFile performs HTTP GET requests to arbitrary URLs provided via command-line arguments. While this is for legitimate syscall table generation from official sources, it could be abused if the script were invoked with a malicious URL.

unix/mksysnum.go:47
low

File system access

NPS-6C601BB8F4B6

readFile opens a file specified by os.Args[1], which is outside the package scope and controlled entirely by whoever invokes the tool. Not malicious in itself but an attacker-controlled input path.

unix/mksysnum.go:56
low

Main entry point / top-level execution

NPS-AF425C4C0C6B

Contains a main() function guarded by //go:build ignore, so it does not execute at import time. Only runs when explicitly invoked via go run. This is normal for a code generator.

unix/mksysnum.go:71
low

Environment variable access

NPS-9AED79389B87

Reads GOOS_TARGET, GOOS, GOARCH_TARGET, GOARCH environment variables. This is standard for Go cross-compilation tooling and not credential harvesting.

unix/mksysnum.go:78
low

Race condition in KeyctlString

NPS-C6E79BB1B7C2

KeyctlString loops to dynamically size a buffer based on the kernel-reported length. If an attacker can modify the key data between the sizing and reading syscalls (TOCTOU), it could lead to returning a truncated or mismatched string, though not directly exploitable for memory corruption.

unix/syscall_linux.go
low

No malicious patterns detected

NPS-9663B61F1762

No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, cryptocurrency mining, backdoor installation, reverse shells, suspicious network requests, or unauthorized file system manipulation were found. The code is part of the official Go x/sys/unix package and follows standard syscall wrapper patterns.

unix/syscall_linux.go
low

memory management concern

NPS-91C612AF5981

C.CString allocations for path strings are not freed with C.free, causing a memory leak per call. This is a code quality issue rather than a security vulnerability, and is a known artifact of mksyscall-generated code.

unix/zsyscall_aix_ppc.go
low

CGO dynamic linking

NPS-A78FF3FDA255

The file uses //go:cgo_import_dynamic and //go:linkname directives to bind to AIX libc functions. These are standard mechanisms for Go's syscall package on AIX and are not malicious, but they do involve dynamic linking to system libraries.

unix/zsyscall_aix_ppc64_gc.go:12
low

Unsafe pointer usage

NPS-77A12D8FC4BC

The file uses unsafe.Pointer conversions to pass function pointers to syscall6 and rawSyscall6. This is standard in Go generated syscall wrappers and is not indicative of malicious intent.

unix/zsyscall_aix_ppc64_gc.go:328
low

DLL preloading risk (documented)

NPS-4CD77D41529E

LoadDLL and NewLazyDLL accept relative paths and are documented to be subject to DLL preloading attacks. This is a known Windows API behavior, and the code explicitly warns users to use NewLazySystemDLL or LoadLibraryEx for safe loading of system DLLs.

windows/dll_windows.go:46
low

Potential out-of-bounds slice

NPS-C1FD16E3D4DA

In SetRecoveryActions, after building a slice 'actions', &actions[0] is taken without checking if len(actions) > 0. Although RecoveryActions nil check handles nil, an empty non-nil slice would cause an index out of range panic at runtime. This is a robustness issue but not directly malicious.

windows/svc/mgr/recovery.go:42

Files reviewed

FileVerdictWhat the reviewer saw
cpu/cpu_darwin_arm64.go critical The file contains suspicious unconditional forcing of ARM64 cryptographic feature flags to true, which tampers with CPU capability detection and could cause unsupported instruction execution or cryptographic misbehavior.
execabs/execabs.go medium The execabs package is a legitimate security-focused wrapper around os/exec that safely enforces absolute path resolution, but its use of unsafe pointer manipulation and process spawning warrants cautious review.
unix/linux/mkall.go medium This is the legitimate Go x/sys linux/mkall.go build tool that deliberately spawns compilers and make, but its unsafe /tmp/0777 usage, propagation of the full host environment to child processes, and build-time execution of external scripts warrant caution if encountered outside the official Go repository.
unix/linux/mksysnum.go medium This is a legitimate Go syscall-number generator that spawns an external compiler from the CC environment variable, but it is not part of the compiled package and contains no malicious exfiltration, credential harvesting, backdoors, or obfuscated payloads.
unix/mksysnum.go medium Legitimate Go code generator for syscall tables with benign network/file access limited to explicit command-line inputs and no malicious patterns, though arbitrary URL/path inputs carry minimal risk.
unix/syscall_linux.go medium The code is the standard Go x/sys/unix syscall wrapper with expected unsafe memory operations and privileged syscall exposure, but no malicious patterns were identified.
unix/sysvshm_unix.go medium This is a standard Go x/sys/unix wrapper for SysV shared memory that uses unsafe pointers and performs a separate IPC_STAT call, which are expected but carry inherent memory-safety risks; no malicious behavior such as exfiltration, process spawning, or backdoor installation was found.
windows/svc/mgr/recovery.go medium The code contains unsafe pointer and slice usage typical of Windows system administration APIs, with potential memory safety risks when handling untrusted service configuration data, but no direct malicious patterns such as exfiltration, backdoors, or code execution.
cpu/byteorder.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu.go safe No malicious patterns detected; this is the standard Go CPU feature detection package with no data exfiltration, obfuscation, or suspicious behavior.
cpu/cpu_aix.go safe This is a standard Go CPU feature detection file for AIX that only queries system configuration and sets capability flags with no network, filesystem, process, or obfuscation concerns.
cpu/cpu_arm.go safe No malicious patterns detected; the code only defines CPU feature constants and registers feature detection options for ARM processors.
cpu/cpu_arm64.go safe This is a legitimate Go standard library CPU feature detection file for ARM64 with no malicious patterns detected.
cpu/cpu_darwin_arm64_other.go safe No malicious patterns detected; the file only sets ARM64 CPU feature flags at init time using safe, static assignments with no network, filesystem, or process activity.
cpu/cpu_darwin_x86.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gc_arm64.go safe No malicious patterns detected
cpu/cpu_gc_riscv64.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gc_s390x.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gc_x86.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gccgo_arm64.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gccgo_s390x.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_gccgo_x86.go safe No malicious patterns detected; the file contains only standard Go runtime CPU feature detection via gccgo extern declarations.
cpu/cpu_linux.go safe No malicious patterns detected
cpu/cpu_linux_arm.go safe No malicious patterns detected
cpu/cpu_linux_arm64.go safe No malicious patterns detected
Show 391 more files
FileVerdictWhat the reviewer saw
cpu/cpu_linux_loong64.go safe No malicious patterns detected
cpu/cpu_linux_mips64x.go safe No malicious patterns detected
cpu/cpu_linux_noinit.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_linux_ppc64x.go safe No malicious patterns detected
cpu/cpu_linux_riscv64.go safe No malicious patterns detected; the code performs legitimate RISC-V CPU feature detection via the riscv_hwprobe syscall and HWCAP, with no network, filesystem, process, or dynamic execution activity.
cpu/cpu_linux_s390x.go safe No malicious patterns detected; this is standard Go CPU feature detection code for s390x using HWCAP bitmask checks.
cpu/cpu_loong64.go safe No malicious patterns detected in the Go CPU feature detection file for LoongArch64; it contains only standard hardware capability checks with no network, filesystem, or process manipulation.
cpu/cpu_mips64x.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_mipsx.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_netbsd_amd64.go safe This is standard Go standard library CPU feature detection code for NetBSD/amd64 that disables AVX features due to a known OS signal-handling bug, with no malicious patterns detected.
cpu/cpu_netbsd_arm64.go safe This is a standard Go runtime CPU feature detection file for NetBSD/arm64 that uses sysctl system calls to read hardware capabilities, with no malicious patterns detected.
cpu/cpu_openbsd_arm64.go safe No malicious patterns detected; code is standard Go standard library CPU feature detection for OpenBSD/arm64 using sysctl.
cpu/cpu_other_arm.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_other_arm64.go safe No malicious patterns detected
cpu/cpu_other_mips64x.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_other_ppc64x.go safe No malicious patterns detected
cpu/cpu_other_riscv64.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_other_x86.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_ppc64x.go safe This is a standard Go runtime internal CPU feature detection file for ppc64/ppc64le architectures with no malicious patterns.
cpu/cpu_riscv64.go safe No malicious patterns detected
cpu/cpu_s390x.go safe No malicious patterns detected
cpu/cpu_sparc64.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_wasm.go safe Cleared by Jev triage; no further analysis needed
cpu/cpu_windows.go safe Standard Go standard library CPU feature detection code with no malicious patterns detected
cpu/cpu_windows_arm64.go safe This is a legitimate Go standard library CPU feature detection file for Windows ARM64 with no malicious patterns.
cpu/cpu_x86.go safe This is a standard Go standard library CPU feature detection file that uses CPUID instructions to identify x86 processor capabilities, with no malicious patterns.
cpu/cpu_zos.go safe No malicious patterns detected
cpu/cpu_zos_s390x.go safe No malicious patterns detected
cpu/endian_big.go safe Cleared by Jev triage; no further analysis needed
cpu/endian_little.go safe Cleared by Jev triage; no further analysis needed
cpu/hwcap_linux.go safe This is standard Go standard library code that reads CPU hardware capabilities from /proc/self/auxv with no malicious patterns detected
cpu/parse.go safe Cleared by Jev triage; no further analysis needed
cpu/proc_cpuinfo_linux.go safe The code reads /proc/cpuinfo on Linux ARM64 to detect CPU features and contains no malicious patterns; it is a legitimate part of the Go standard library.
cpu/runtime_auxv.go safe No malicious patterns detected
cpu/runtime_auxv_go121.go safe No malicious patterns detected; this is a standard Go internal CPU feature detection file using linkname to access runtime auxiliary vector.
cpu/syscall_aix_gccgo.go safe The file contains a standard syscall wrapper for AIX/gccgo without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or network activity.
cpu/syscall_aix_ppc64_gc.go safe This is a legitimate, minimal Go runtime file from the standard library that makes a dynamic syscall to getsystemcfg on AIX for CPU feature detection, with no malicious patterns present.
cpu/syscall_darwin_arm64_gc.go safe The file is a legitimate Go runtime/internal/cpu helper for Darwin arm64 that makes sysctl calls for CPU feature detection; no malicious patterns were found.
cpu/syscall_darwin_x86_gc.go safe No malicious patterns detected; the code contains legitimate Darwin sysctl system call wrappers for CPU detection with no exfiltration, obfuscation, or suspicious behavior.
cpu/zcpu_windows.go safe No malicious patterns detected; code is a standard Go generated file accessing kernel32.dll for CPU feature detection on Windows.
execabs/execabs_go118.go safe No malicious patterns detected
execabs/execabs_go119.go safe No malicious patterns detected; the file contains only small helper functions wrapping standard library error checks for Go 1.19 compatibility.
plan9/const_plan9.go safe Cleared by Jev triage; no further analysis needed
plan9/dir_plan9.go safe Cleared by Jev triage; no further analysis needed
plan9/env_plan9.go safe No malicious patterns detected
plan9/errors_plan9.go safe This file contains only standard Plan 9 OS constant definitions and statically initialized error variables; no malicious patterns, dynamic code, network activity, or filesystem/process manipulation were detected.
plan9/mksyscall.go safe This is a legitimate Go code generation tool from the standard library that parses syscall declarations and generates system call wrapper code, with no malicious patterns detected.
plan9/pwd_plan9.go safe No malicious patterns detected; this is a minimal, legitimate Plan 9 syscall wrapper from the Go standard library.
plan9/race.go safe No malicious patterns detected; this is a standard Go standard library race detector support file for Plan 9, containing only runtime race instrumentation wrappers.
plan9/race0.go safe No malicious patterns detected
plan9/str.go safe Cleared by Jev triage; no further analysis needed
plan9/syscall.go safe No malicious patterns detected; this is standard Go x/sys Plan 9 system call support code from the Go project.
plan9/syscall_plan9.go safe No malicious patterns detected; the file contains standard Plan 9 system call bindings from the Go standard library.
plan9/zsyscall_plan9_386.go safe This is a standard Go generated syscall wrapper file for Plan 9 386 architecture, containing only legitimate system call bindings and unsafe pointer usage typical of the Go standard library, with no malicious patterns detected.
plan9/zsyscall_plan9_amd64.go safe No malicious patterns detected; this is standard auto-generated Go syscall wrapper code for Plan 9 amd64.
plan9/zsyscall_plan9_arm.go safe This is a standard Go syscall binding file for Plan 9 ARM, generated by mksyscall, containing only low-level OS syscall wrappers with no malicious patterns.
plan9/zsysnum_plan9.go safe No malicious patterns detected; the file only contains constant syscall number definitions for Plan 9.
unix/affinity_linux.go safe No malicious patterns detected; this is a standard Go syscall wrapper for Linux CPU affinity operations with no network, filesystem, or process execution behavior.
unix/aliases.go safe No malicious patterns detected
unix/auxv.go safe No malicious patterns detected
unix/auxv_unsupported.go safe This is a standard Go standard library compatibility stub that returns ENOTSUP on unsupported build configurations, with no malicious patterns detected.
unix/bluetooth_linux.go safe Cleared by Jev triage; no further analysis needed
unix/bpxsvc_zos.go safe This is legitimate z/OS-specific system call wrapper code from the Go standard library, with no malicious patterns detected.
unix/cap_freebsd.go safe Cleared by Jev triage; no further analysis needed
unix/constants.go safe Cleared by Jev triage; no further analysis needed
unix/dev_aix_ppc.go safe Cleared by Jev triage; no further analysis needed
unix/dev_aix_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/dev_darwin.go safe Cleared by Jev triage; no further analysis needed
unix/dev_dragonfly.go safe Cleared by Jev triage; no further analysis needed
unix/dev_freebsd.go safe Cleared by Jev triage; no further analysis needed
unix/dev_linux.go safe Cleared by Jev triage; no further analysis needed
unix/dev_netbsd.go safe Cleared by Jev triage; no further analysis needed
unix/dev_openbsd.go safe Cleared by Jev triage; no further analysis needed
unix/dev_zos.go safe Cleared by Jev triage; no further analysis needed
unix/dirent.go safe No malicious patterns detected in this standard Go syscall directory parsing code.
unix/endian_big.go safe Cleared by Jev triage; no further analysis needed
unix/endian_little.go safe Cleared by Jev triage; no further analysis needed
unix/env_unix.go safe No malicious patterns detected
unix/fcntl.go safe No malicious patterns detected
unix/fcntl_darwin.go safe No malicious patterns detected
unix/fcntl_linux_32bit.go safe No malicious patterns detected
unix/fdset.go safe Cleared by Jev triage; no further analysis needed
unix/gccgo.go safe No malicious patterns detected; this is a standard Go syscall wrapper for gccgo with build constraints for non-AIX/non-Hurd Unix systems.
unix/gccgo_linux_amd64.go safe No malicious patterns detected
unix/ifreq_linux.go safe No malicious patterns detected; the code is a legitimate low-level unsafe wrapper for Linux interface requests from the Go standard library.
unix/internal/mkmerge/mkmerge.go safe This is a legitimate Go source file from the Go standard library's internal tooling; it performs AST-based source merging with no network, credential, execution, or obfuscation concerns.
unix/ioctl_linux.go safe No malicious patterns detected; the code is a standard Go library ioctl wrapper with no exfiltration, obfuscation, or backdoor behavior.
unix/ioctl_signed.go safe No malicious patterns detected; the file contains standard Go ioctl wrapper functions for AIX and Solaris with no exfiltration, execution, or suspicious behavior.
unix/ioctl_unsigned.go safe The file is a standard part of the Go x/sys/unix package providing ioctl wrappers with no malicious patterns, network activity, or code execution.
unix/ioctl_zos.go safe This is a standard Go standard library ioctl wrapper file for z/OS; no malicious patterns, network activity, credential access, or dynamic code execution present.
unix/mkasm.go safe This is a standard Go code generation tool from the Go standard library that creates assembly trampolines; it performs only local file reading and writing with no malicious patterns.
unix/mkpost.go safe This is a legitimate Go source file from the standard library's golang.org/x/sys repository; it is a build-time code generation helper that performs regex-based transformations on cgo output and contains no malicious patterns.
unix/mksyscall.go safe No malicious patterns detected; this is a legitimate Go code generator for system call wrappers in the golang.org/x/sys repository.
unix/mksyscall_aix_ppc.go safe This is a legitimate Go code generation tool from the official golang.org/x/sys repository that reads syscall prototypes and generates wrapper code, with no malicious patterns detected.
unix/mksyscall_aix_ppc64.go safe This is the legitimate Go x/sys code generator for AIX syscall wrappers; it only performs local file reads/writes and contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, or shell execution.
unix/mksyscall_solaris.go safe This is a standard Go code generator from the golang.org/x/sys repository that produces syscall wrappers for Solaris; no malicious patterns, network activity, credential access, or obfuscation were detected.
unix/mksyscall_zos_s390x.go safe Standard Go syscall code generator for z/OS s390x that only reads a fixed system file and writes generated source files; no malicious patterns detected.
unix/mksysctl_openbsd.go safe No malicious patterns detected; this is a standard Go code generator that parses OpenBSD header files to produce sysctl MIB definitions.
unix/mmap_nomremap.go safe No malicious patterns detected; this is a standard Go standard-library source file defining an mmapper initialization for memory mapping utilities.
unix/mremap.go safe No malicious patterns detected; the code is a legitimate low-level memory mapping utility from the Go standard library's unix package.
unix/pagesize_unix.go safe No malicious patterns detected
unix/pledge_openbsd.go safe Cleared by Jev triage; no further analysis needed
unix/ptrace_darwin.go safe Cleared by Jev triage; no further analysis needed
unix/ptrace_ios.go safe Cleared by Jev triage; no further analysis needed
unix/race.go safe No malicious patterns detected
unix/race0.go safe This is a standard Go standard library race detector stub file with no malicious patterns; all functions are empty no-ops and no network, filesystem, process, or dynamic code execution is present.
unix/readdirent_getdents.go safe No malicious patterns detected
unix/readdirent_getdirentries.go safe This is a standard Go standard library wrapper for the getdirentries syscall on darwin/zos with no malicious patterns detected.
unix/readv_unix.go safe No malicious patterns detected; the code is a standard part of the Go standard library for vectored I/O operations.
unix/sockcmsg_dragonfly.go safe Cleared by Jev triage; no further analysis needed
unix/sockcmsg_linux.go safe No malicious patterns detected
unix/sockcmsg_unix.go safe No malicious patterns detected; this is standard Go standard-library code for socket control message parsing.
unix/sockcmsg_unix_other.go safe Cleared by Jev triage; no further analysis needed
unix/sockcmsg_zos.go safe No malicious patterns detected; this is a legitimate Go standard library syscall helper for encoding and parsing socket control messages (Unix credentials, packet info) on z/OS.
unix/syscall.go safe No malicious patterns detected
unix/syscall_aix.go safe No malicious patterns detected; this is a standard Go syscall wrapper file for AIX from the golang.org/x/sys/unix package.
unix/syscall_aix_ppc.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_aix_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_bsd.go safe This is a standard Go syscall wrapper file for BSD systems from the official golang.org/x/sys/unix package, containing only legitimate system call bindings and socket address conversion routines with no malicious patterns.
unix/syscall_darwin.go safe No malicious patterns detected; this is standard Go syscall wrapper code for Darwin with no exfiltration, credential harvesting, obfuscation, or process spawning.
unix/syscall_darwin_amd64.go safe No malicious patterns detected
unix/syscall_darwin_arm64.go safe This is a standard Go syscall compatibility file with only type conversion helpers and syscall declarations; no malicious patterns were detected.
unix/syscall_darwin_libSystem.go safe This is a standard Go standard library file that declares low-level syscall functions and uses go:linkname to link them to runtime implementations, with no malicious patterns detected.
unix/syscall_dragonfly.go safe No malicious patterns detected
unix/syscall_dragonfly_amd64.go safe This is a legitimate Go standard library/x/sys file containing low-level DragonFly BSD system call wrappers and type conversion helpers with no malicious patterns.
unix/syscall_freebsd.go safe No malicious patterns detected; this is standard Go FreeBSD syscall wrapper code from the official golang.org/x/sys repository.
unix/syscall_freebsd_386.go safe No malicious patterns detected; the code is a standard part of the Go x/sys/unix package with platform-specific syscall helpers.
unix/syscall_freebsd_amd64.go safe No malicious patterns detected
unix/syscall_freebsd_arm.go safe No malicious patterns detected
unix/syscall_freebsd_arm64.go safe No malicious patterns detected; generated syscall wrapper code for FreeBSD arm64 with no external I/O, credential access, or code execution.
unix/syscall_freebsd_riscv64.go safe No malicious patterns detected; this is standard Go low-level syscall glue code for FreeBSD/riscv64 with no network, file, process, or obfuscation activity.
unix/syscall_hurd.go safe No malicious patterns detected; the code is a standard Go syscall wrapper for ioctl on Hurd with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
unix/syscall_hurd_386.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_illumos.go safe No malicious patterns detected
unix/syscall_linux_386.go safe This is a standard Go standard library syscall wrapper file for Linux 386 with no malicious patterns, obfuscation, network exfiltration, or install-time execution.
unix/syscall_linux_alarm.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_linux_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_linux_amd64_gc.go safe No malicious patterns detected
unix/syscall_linux_arm.go safe No malicious patterns detected; this is a standard Go syscall wrapper for Linux ARM with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
unix/syscall_linux_arm64.go safe This is a standard Go unix syscall wrapper file for Linux on arm64 with no malicious patterns, no network exfiltration, no credential harvesting, no obfuscated code execution, and no install-time hooks.
unix/syscall_linux_gc.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_linux_gc_386.go safe No malicious patterns detected
unix/syscall_linux_gc_arm.go safe No malicious patterns detected
unix/syscall_linux_gccgo_386.go safe This is standard Go syscall wrapper code for Linux 386 gccgo architecture with no malicious patterns detected.
unix/syscall_linux_gccgo_arm.go safe Legitimate Go standard library low-level syscall wrapper for _llseek with no malicious patterns
unix/syscall_linux_loong64.go safe No malicious patterns detected; this is standard Go syscall wrapper code for Linux on the loong64 architecture.
unix/syscall_linux_mips64x.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_linux_mipsx.go safe Standard Go syscall wrappers for Linux MIPS architectures with no malicious patterns detected
unix/syscall_linux_ppc.go safe No malicious patterns detected
unix/syscall_linux_ppc64x.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_linux_riscv64.go safe This is a legitimate portion of the Go standard library's syscall bindings for Linux riscv64, containing only standard syscall wrappers and helper functions with no malicious patterns.
unix/syscall_linux_s390x.go safe No malicious patterns detected; the file contains standard Linux s390x syscall wrappers from the Go x/sys/unix package.
unix/syscall_linux_sparc64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_netbsd.go safe This is the standard Go x/sys/unix package file for NetBSD syscall bindings; no malicious patterns, exfiltration, backdoors, or suspicious behavior detected.
unix/syscall_netbsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_netbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_netbsd_arm.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_netbsd_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd.go safe No malicious patterns detected; this is standard Go x/sys/unix OpenBSD syscall wrapper code with only expected system call bindings and data conversions.
unix/syscall_openbsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_arm.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_libc.go safe No malicious patterns detected; the file only declares low-level syscall wrappers via linkname for OpenBSD runtime integration.
unix/syscall_openbsd_mips64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_openbsd_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_solaris.go safe No malicious patterns detected; this is a standard Go standard library syscall wrapper file with no exfiltration, obfuscation, or backdoor behavior.
unix/syscall_solaris_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/syscall_unix.go safe No malicious patterns detected
unix/syscall_unix_gc.go safe No malicious patterns detected
unix/syscall_unix_gc_ppc64x.go safe No malicious patterns detected; the file contains standard syscall wrappers for ppc64/ppc64le Linux with no network, file, process, or obfuscation behavior.
unix/syscall_zos_s390x.go safe This is a standard Go syscall implementation for z/OS s390x; the init() function only reads environment variables for optional tracing configuration and does not exhibit any malicious patterns.
unix/sysvshm_linux.go safe Cleared by Jev triage; no further analysis needed
unix/sysvshm_unix_other.go safe Cleared by Jev triage; no further analysis needed
unix/timestruct.go safe Cleared by Jev triage; no further analysis needed
unix/types_aix.go safe No malicious patterns detected; this is a standard Go cgo -godefs type definition file for AIX platform bindings with only C type mappings and constants.
unix/types_darwin.go safe This is a standard Go cgo godefs type definition file from the golang.org/x/sys/unix package containing only platform type mappings with no executable logic or malicious patterns.
unix/types_dragonfly.go safe This is a standard Go cgo -godefs type definition file for DragonFly BSD, containing only C struct mappings and constants with no executable or malicious code.
unix/types_freebsd.go safe This is a standard Go cgo godefs type definition file from the golang.org/x/sys/unix package with no malicious patterns, network activity, credential access, or code execution.
unix/types_netbsd.go safe No malicious patterns detected; this is a standard Go cgo -godefs type definition file for NetBSD system structures from the golang.org/x/sys/unix package.
unix/types_openbsd.go safe No malicious patterns detected
unix/types_solaris.go safe This is a standard Go cgo type definition file for Solaris with no executable code, network calls, or malicious patterns.
unix/unveil_openbsd.go safe Cleared by Jev triage; no further analysis needed
unix/vgetrandom_linux.go safe No malicious patterns detected; the file is a standard Go runtime linkname declaration for the vgetrandom syscall wrapper in the unix package.
unix/vgetrandom_unsupported.go safe Cleared by Jev triage; no further analysis needed
unix/xattr_bsd.go safe This is standard Go standard library code for BSD extended attribute syscalls; no malicious patterns detected.
unix/zerrors_aix_ppc.go safe No malicious patterns detected; this is a standard generated Go constants file for AIX syscall definitions with no executable code, network activity, or file system access.
unix/zerrors_aix_ppc64.go safe No malicious patterns detected
unix/zerrors_darwin_amd64.go safe No malicious patterns detected
unix/zerrors_darwin_arm64.go safe No malicious patterns detected in this auto-generated Go constants file, which contains only standard Darwin syscall, error, and signal numeric definitions.
unix/zerrors_dragonfly_amd64.go safe No malicious patterns detected; this is a generated Go constants file for DragonFly BSD system calls and error/signal definitions.
unix/zerrors_freebsd_386.go safe This is an auto-generated Go constants file containing only syscall constants, error tables, and signal definitions for FreeBSD/386 with no executable logic or malicious patterns.
unix/zerrors_freebsd_amd64.go safe Code contains only Go constant definitions and lookup tables for FreeBSD error and signal codes; no malicious patterns detected.
unix/zerrors_freebsd_arm.go safe This is a standard Go-generated file containing FreeBSD ARM system constants, error codes, and signal definitions with no executable logic or malicious patterns.
unix/zerrors_freebsd_arm64.go safe No malicious patterns detected; the file is a generated constants definition for FreeBSD arm64 system calls and error codes.
unix/zerrors_freebsd_riscv64.go safe No malicious patterns detected; this is a standard Go generated file containing FreeBSD riscv64 system constants, error codes, and signal definitions for the golang.org/x/sys/unix package.
unix/zerrors_linux_386.go safe No malicious patterns detected
unix/zerrors_linux_amd64.go safe This is an auto-generated Go constants file from the golang.org/x/sys/unix package containing only Linux syscall, errno, signal, and ioctl constant definitions with no executable code or malicious patterns.
unix/zerrors_linux_arm.go safe This is a standard auto-generated Go constant file for Linux ARM syscall definitions, containing only compile-time constants and static data tables with no executable code or security-relevant behavior.
unix/zerrors_linux_arm64.go safe No malicious patterns detected; this is a standard Go-generated constants file containing Linux arm64 ioctl, error, and signal definitions from the golang.org/x/sys/unix package.
unix/zerrors_linux_loong64.go safe No malicious patterns detected
unix/zerrors_linux_mips.go safe No malicious patterns detected
unix/zerrors_linux_mips64.go safe This is a standard auto-generated Go file defining Linux ioctl constants, error numbers, and signal numbers for mips64 architectures; no malicious patterns detected.
unix/zerrors_linux_mips64le.go safe This is an auto-generated Go file containing only constant definitions for Linux MIPS64LE syscall/ioctl values, with no executable code, network activity, or suspicious patterns.
unix/zerrors_linux_mipsle.go safe No malicious patterns detected; this is an auto-generated Go constants file defining Linux syscall/ioctl/error/signal values for mipsle architecture.
unix/zerrors_linux_ppc.go safe No malicious patterns detected; this file contains only generated Go constants for Linux/PPC syscall and terminal definitions with no executable logic.
unix/zerrors_linux_ppc64.go safe No malicious patterns detected; the file is a standard Go-generated constants definition for Linux ppc64 system errors, signals, and ioctl values from the golang.org/x/sys/unix package.
unix/zerrors_linux_ppc64le.go safe No malicious patterns detected; this is an auto-generated Go constants file for Linux ppc64le syscall/ioctl definitions.
unix/zerrors_linux_riscv64.go safe No malicious patterns detected
unix/zerrors_linux_s390x.go safe No malicious patterns detected; this is a generated Go file containing only Linux system constants for the s390x architecture.
unix/zerrors_linux_sparc64.go safe No malicious patterns detected; this is a standard Go generated constants file for Linux sparc64 syscall definitions with no executable code or suspicious behavior.
unix/zerrors_netbsd_386.go safe This is a standard Go generated file containing only constant definitions for NetBSD 386 syscall constants and no executable code or malicious patterns.
unix/zerrors_netbsd_amd64.go safe No malicious patterns detected
unix/zerrors_netbsd_arm.go safe This is an auto-generated Go constants file for NetBSD ARM syscalls, containing only platform-specific constant definitions with no executable or malicious code.
unix/zerrors_netbsd_arm64.go safe No malicious patterns detected
unix/zerrors_openbsd_386.go safe No malicious patterns detected; this is a standard auto-generated Go constants file for OpenBSD 386 syscall definitions.
unix/zerrors_openbsd_amd64.go safe This is an auto-generated Go file containing only OpenBSD amd64 system call constants, error codes, and signal definitions with no executable code or malicious patterns.
unix/zerrors_openbsd_arm.go safe No malicious patterns detected; this is a standard Go generated constants file for OpenBSD ARM syscall definitions.
unix/zerrors_openbsd_arm64.go safe This is an auto-generated Go constant definition file for OpenBSD arm64 syscall values with no executable logic or malicious patterns.
unix/zerrors_openbsd_mips64.go safe Generated Go constants file containing only system call, error, and signal definitions for OpenBSD mips64 with no executable or malicious code
unix/zerrors_openbsd_ppc64.go safe This is an auto-generated Go constants file from the golang.org/x/sys/unix package containing only platform-specific syscall constants, error codes, and signal tables for OpenBSD on ppc64, with no executable code or malicious patterns.
unix/zerrors_openbsd_riscv64.go safe This file contains only standard OpenBSD riscv64 system call constants, error codes, and signal definitions auto-generated by cgo; no malicious patterns detected.
unix/zerrors_solaris_amd64.go safe No malicious patterns detected; the file contains only generated constant definitions, error tables, and signal tables with no executable logic or external interactions.
unix/zerrors_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
unix/zptrace_armnn_linux.go safe This is a standard generated Go wrapper file for Linux ptrace register access on ARM/ARM64 with no malicious patterns detected.
unix/zptrace_linux_arm64.go safe No malicious patterns detected; the code is a standard ptrace register getter/setter using unsafe pointers for legitimate syscall data transfer.
unix/zptrace_mipsnn_linux.go safe No malicious patterns detected; the file contains only standard generated ptrace register access helpers for MIPS/MIPS64 in x/sys/unix.
unix/zptrace_mipsnnle_linux.go safe This is a machine-generated Go wrapper for ptrace syscalls on MIPS architectures with no malicious patterns detected.
unix/zptrace_x86_linux.go safe This generated Go file contains only standard ptrace register definitions and wrappers for 386/amd64, with no malicious patterns, network activity, or code execution.
unix/zsyscall_aix_ppc.go safe This is a standard Go syscall binding file generated by mksyscall for AIX/ppc; it contains only thin cgo wrappers around native system calls with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor code.
unix/zsyscall_aix_ppc64.go safe This is a standard auto-generated Go syscall wrapper file for AIX/ppc64 with no malicious patterns, exfiltration, or dynamic code execution.
unix/zsyscall_aix_ppc64_gc.go safe This is a standard Go generated syscall wrapper for AIX ppc64; no malicious patterns were detected.
unix/zsyscall_aix_ppc64_gccgo.go safe No malicious patterns detected; this is a standard Go syscall wrapper file generated by the Go toolchain for AIX/PowerPC64/gccgo builds.
unix/zsyscall_darwin_amd64.go safe This is a standard Go-generated syscall wrapper file for macOS (darwin/amd64) from the golang.org/x/sys/unix package, containing only legitimate libc bindings with no malicious patterns.
unix/zsyscall_darwin_arm64.go safe This is a standard Go-generated syscall binding file for darwin/arm64 from the golang.org/x/sys/unix package, containing only legitimate libc wrappers with no malicious patterns.
unix/zsyscall_dragonfly_amd64.go safe This is an auto-generated syscall wrapper file from the golang.org/x/sys/unix package for DragonFly BSD/amd64; it contains only standard low-level syscall bindings with no malicious patterns such as exfiltration, obfuscation, backdoors, or install-time execution.
unix/zsyscall_freebsd_386.go safe This is a standard Go-generated syscall wrapper file for FreeBSD 386 from golang.org/x/sys/unix with no malicious patterns, no network exfiltration, no obfuscation, no install-time hooks, and no credential harvesting.
unix/zsyscall_freebsd_amd64.go safe This is a standard Go-generated syscall wrapper file for FreeBSD/amd64 containing only low-level system call bindings with no malicious patterns.
unix/zsyscall_freebsd_arm.go safe This is a standard Go-generated syscall wrapper file for FreeBSD/ARM from the golang.org/x/sys/unix package with no malicious patterns, no network activity, no obfuscation, and no dynamic code execution.
unix/zsyscall_freebsd_arm64.go safe No malicious patterns detected; this is a standard machine-generated Go syscall binding file for FreeBSD arm64 from the golang.org/x/sys/unix package.
unix/zsyscall_freebsd_riscv64.go safe This is a standard Go-generated syscall wrapper file for FreeBSD/riscv64 from the golang.org/x/sys/unix package; it contains only routine system call bindings with no malicious patterns, obfuscation, network exfiltration, or dynamic code execution.
unix/zsyscall_illumos_amd64.go safe This is a standard Go syscall wrapper file generated for illumos/amd64, containing only legitimate libc dynamic import bindings for readv, preadv, writev, pwritev, and accept4 with no malicious patterns.
unix/zsyscall_linux.go safe This is a standard machine-generated Go syscall wrapper file from golang.org/x/sys/unix containing only direct syscall bindings with no malicious patterns.
unix/zsyscall_linux_386.go safe This is auto-generated Go syscall wrapper code for Linux 386, containing only standard low-level system call bindings with no malicious patterns.
unix/zsyscall_linux_amd64.go safe This is a standard Go syscall wrapper file from golang.org/x/sys/unix containing legitimate low-level Linux syscall bindings with no malicious patterns.
unix/zsyscall_linux_arm.go safe This is a standard, auto-generated Go syscall wrapper file for Linux ARM from the golang.org/x/sys/unix package with no malicious patterns detected.
unix/zsyscall_linux_arm64.go safe This is a standard Go syscall wrapper file generated by mksyscall.go for linux/arm64; no malicious patterns, network calls, process spawning, or obfuscation were detected.
unix/zsyscall_linux_loong64.go safe No malicious patterns detected; this is a standard generated syscall wrapper file for Linux loong64 from the golang.org/x/sys/unix package.
unix/zsyscall_linux_mips.go safe This is an auto-generated Go syscall wrapper file for Linux MIPS architecture from the golang.org/x/sys/unix package containing only standard libc syscall bindings with no malicious patterns.
unix/zsyscall_linux_mips64.go safe This is a standard Go syscall wrapper file auto-generated by mksyscall for linux/mips64, containing only thin wrappers around kernel syscalls with no malicious patterns.
unix/zsyscall_linux_mips64le.go safe This is a standard auto-generated Go syscall binding file for Linux mips64le architecture containing no malicious patterns.
unix/zsyscall_linux_mipsle.go safe This is a standard Go-generated syscall wrapper file for Linux/MIPSLE with no malicious patterns.
unix/zsyscall_linux_ppc.go safe This is a standard Go syscall wrapper file generated by mksyscall for Linux/ppc, containing only low-level system call bindings with no malicious patterns.
unix/zsyscall_linux_ppc64.go safe No malicious patterns detected in this auto-generated Go syscall wrapper file for linux/ppc64, which contains only standard syscall bindings.
unix/zsyscall_linux_ppc64le.go safe This is a standard generated Go syscall wrapper file for Linux ppc64le from the golang.org/x/sys/unix package, containing only direct system call bindings with no malicious patterns.
unix/zsyscall_linux_riscv64.go safe This is an auto-generated Go syscall wrapper file for linux/riscv64 from the golang.org/x/sys/unix package containing standard libc syscall bindings with no malicious patterns.
unix/zsyscall_linux_s390x.go safe This is a standard Go-generated syscall wrapper file for linux/s390x from the golang.org/x/sys/unix package, containing only direct kernel syscall bindings with no malicious patterns.
unix/zsyscall_linux_sparc64.go safe This is a standard Go generated syscall wrapper file for Linux on SPARC64 architecture, containing only legitimate low-level syscall bindings with no malicious patterns.
unix/zsyscall_netbsd_386.go safe This is a standard Go generated syscall wrapper file for NetBSD 386 from golang.org/x/sys/unix, containing only legitimate OS system call bindings with no malicious patterns.
unix/zsyscall_netbsd_amd64.go safe Generated Go syscall bindings for NetBSD/amd64 wrapping standard low-level system calls with no malicious patterns detected.
unix/zsyscall_netbsd_arm.go safe Generated Go syscall bindings for NetBSD/ARM contain only standard libc wrapper calls with no malicious patterns.
unix/zsyscall_netbsd_arm64.go safe This is a standard Go syscall wrapper file generated by mksyscall.go for NetBSD arm64; it contains only legitimate low-level system call bindings with no malicious patterns.
unix/zsyscall_openbsd_386.go safe This is a standard auto-generated Go syscall binding file for OpenBSD/386 that only provides thin wrappers around libc functions with no malicious patterns.
unix/zsyscall_openbsd_amd64.go safe Auto-generated Go syscall bindings for OpenBSD with no malicious patterns detected
unix/zsyscall_openbsd_arm.go safe This is a standard Go generated syscall binding file for OpenBSD/ARM that only wraps libc functions via cgo trampolines with no malicious patterns.
unix/zsyscall_openbsd_arm64.go safe No malicious patterns detected; this is a standard auto-generated Go syscall binding file for OpenBSD on arm64 dynamically linking to libc.
unix/zsyscall_openbsd_mips64.go safe This is a standard Go-generated syscall wrapper file for OpenBSD/mips64 from the golang.org/x/sys/unix package, containing only libc syscall trampolines and no malicious patterns.
unix/zsyscall_openbsd_ppc64.go safe No malicious patterns detected; this is a standard Go generated syscall wrapper for OpenBSD/ppc64 with only C library trampoline definitions and direct syscall invocations.
unix/zsyscall_openbsd_riscv64.go safe This is a standard Go generated syscall wrapper file for OpenBSD/riscv64 from golang.org/x/sys/unix; it contains only legitimate libc bindings with no malicious patterns.
unix/zsyscall_solaris_amd64.go safe This is a standard Go generated syscall binding file for Solaris/amd64 from golang.org/x/sys/unix; it contains only libc dynamic import declarations and syscall wrappers with no network, persistence, obfuscation, or credential-harvesting behavior.
unix/zsyscall_zos_s390x.go safe This is a standard auto-generated Go syscall wrapper file for z/OS s390x, containing only legitimate OS system call bindings with no malicious patterns.
unix/zsysctl_openbsd_386.go safe No malicious patterns detected in this auto-generated Go file defining OpenBSD sysctl MIB mappings.
unix/zsysctl_openbsd_amd64.go safe This file is an auto-generated static lookup table of OpenBSD sysctl MIB entries with no executable code, network access, file system operations, or suspicious patterns.
unix/zsysctl_openbsd_arm.go safe No malicious patterns detected; this is a generated Go table mapping OpenBSD sysctl names to MIB OIDs.
unix/zsysctl_openbsd_arm64.go safe This is a generated Go file containing only static sysctl MIB name-to-OID mapping data for OpenBSD/arm64 with no executable code or malicious patterns.
unix/zsysctl_openbsd_mips64.go safe This is a generated Go file containing only a static lookup table of sysctl MIB entries for OpenBSD on mips64, with no executable logic, network activity, or malicious patterns.
unix/zsysctl_openbsd_ppc64.go safe This is a generated Go file containing only a static lookup table of sysctl MIB entries for OpenBSD ppc64, with no executable code, network activity, file access, or other malicious patterns.
unix/zsysctl_openbsd_riscv64.go safe No malicious patterns detected; file contains a static table of OpenBSD sysctl MIB mappings for riscv64 with no executable logic, network activity, filesystem access, or process spawning.
unix/zsysnum_darwin_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_darwin_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_dragonfly_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_freebsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_freebsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_freebsd_arm.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_freebsd_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_freebsd_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_386.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_arm.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_loong64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_mips.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_mips64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_mips64le.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_mipsle.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_ppc.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_ppc64le.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_s390x.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_linux_sparc64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_netbsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_netbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_netbsd_arm.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_netbsd_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_arm.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_arm64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_mips64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/zsysnum_openbsd_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_aix_ppc.go safe This is a generated Go type definition file for AIX on PPC containing only struct layouts, constants, and type aliases, with no executable logic or malicious patterns.
unix/ztypes_aix_ppc64.go safe No malicious patterns detected; this is a standard Go-generated type definition file for AIX ppc64 syscall/struct bindings.
unix/ztypes_darwin_amd64.go safe No malicious patterns detected; this is a standard Go generated file containing only type definitions, constants, and struct layouts for Darwin/amd64 system calls.
unix/ztypes_darwin_arm64.go safe No malicious patterns detected; the file contains only generated Go type definitions and constants for Darwin arm64 system interfaces.
unix/ztypes_dragonfly_amd64.go safe No malicious patterns detected; this is an auto-generated Go struct definition file for DragonFly BSD system types from the golang.org/x/sys/unix package, containing only type declarations and constants with no executable code, network activity, or filesystem manipulation.
unix/ztypes_freebsd_386.go safe This is an auto-generated Go type definition file for FreeBSD 386 system structures, containing only constant declarations and struct type definitions with no executable code or malicious patterns.
unix/ztypes_freebsd_amd64.go safe No malicious patterns detected; this is an auto-generated Go type definition file for FreeBSD syscall structures with no executable code or suspicious behavior.
unix/ztypes_freebsd_arm.go safe No malicious patterns detected
unix/ztypes_freebsd_arm64.go safe No malicious patterns detected; the file is a standard Go generated type definition for FreeBSD arm64, containing only constants, structs, and type aliases with no executable code or network/file system operations.
unix/ztypes_freebsd_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_linux_386.go safe No malicious patterns detected; this is an auto-generated Go type definition file for Linux 386 syscall structures.
unix/ztypes_linux_amd64.go safe No malicious patterns detected; this is a standard Go generated type definition file for Linux amd64 syscalls.
unix/ztypes_linux_arm.go safe This is an auto-generated Go type definition file for Linux ARM system structures with no executable code or malicious patterns.
unix/ztypes_linux_arm64.go safe This file contains only Go type definitions and constants for Linux arm64 syscall structures, with no executable code, network operations, or malicious patterns.
unix/ztypes_linux_loong64.go safe No malicious patterns detected
unix/ztypes_linux_mips.go safe This is a generated Go types file containing only architecture-specific struct, constant, and type definitions for Linux/mips with no executable logic or malicious patterns.
unix/ztypes_linux_mips64.go safe No malicious patterns detected
unix/ztypes_linux_mips64le.go safe No malicious patterns detected; this is an auto-generated Go type definition file for Linux mips64le syscall structures and constants.
unix/ztypes_linux_mipsle.go safe No malicious patterns detected in the generated Go type definitions.
unix/ztypes_linux_ppc.go safe No malicious patterns detected; this is a generated Go type definition file for Linux ppc syscall constants and structures.
unix/ztypes_linux_ppc64.go safe No malicious patterns detected
unix/ztypes_linux_ppc64le.go safe This is an auto-generated Go type definitions file for the golang.org/x/sys/unix package containing only constants and struct layouts with no executable code or malicious patterns.
unix/ztypes_linux_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_linux_s390x.go safe Generated Go type definitions for Linux s390x syscall bindings; contains no executable logic, network activity, or malicious patterns.
unix/ztypes_linux_sparc64.go safe This is a generated Go type definition file for Linux SPARC64 system structures with no executable code, no I/O operations, and no malicious patterns.
unix/ztypes_netbsd_386.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_netbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_netbsd_arm.go safe No malicious patterns detected
unix/ztypes_netbsd_arm64.go safe No malicious patterns detected; this is a generated Go type definition file for NetBSD on ARM64 with only constant and struct declarations.
unix/ztypes_openbsd_386.go safe No malicious patterns detected; the file contains only generated Go type and constant definitions for OpenBSD system interfaces.
unix/ztypes_openbsd_amd64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_openbsd_arm.go safe This is an auto-generated Go type definition file for OpenBSD ARM syscall structures with no executable code or malicious patterns.
unix/ztypes_openbsd_arm64.go safe No malicious patterns detected; this is a standard Go generated type definitions file for OpenBSD arm64 with no executable code, network access, filesystem manipulation, or obfuscation.
unix/ztypes_openbsd_mips64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_openbsd_ppc64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_openbsd_riscv64.go safe Cleared by Jev triage; no further analysis needed
unix/ztypes_solaris_amd64.go safe No malicious patterns detected
unix/ztypes_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
windows/aliases.go safe No malicious patterns detected
windows/dll_windows.go safe This is a standard Go standard library file for Windows DLL handling; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors, though it correctly documents inherent DLL preloading risks.
windows/env_windows.go safe No malicious patterns detected; this is legitimate Go standard library Windows environment variable handling code.
windows/eventlog.go safe Cleared by Jev triage; no further analysis needed
windows/exec_windows.go safe No malicious patterns detected
windows/memory_windows.go safe Cleared by Jev triage; no further analysis needed
windows/mksyscall.go safe This is a standard Go code generation directive file from the official golang.org/x/sys repository with no malicious patterns detected.
windows/mkwinsyscall/mkwinsyscall.go safe No malicious patterns detected; this is the standard Go mkwinsyscall code generator that parses //sys comments and emits Windows syscall wrappers without any network, credential, or obfuscation behavior.
windows/race.go safe No malicious patterns detected
windows/race0.go safe No malicious patterns detected; this is a legitimate Go standard library race detector stub file with empty no-op functions under the windows && !race build constraint.
windows/registry/key.go safe No malicious patterns detected; this is legitimate Go standard library Windows registry access code.
windows/registry/mksyscall.go safe No malicious patterns detected in this build-tagged Go generate file that only invokes the standard mkwinsyscall tool for registry syscall generation.
windows/registry/syscall.go safe This is a standard Go standard-library Windows registry syscall binding file with no malicious patterns, network activity, credential harvesting, or dynamic code execution.
windows/registry/value.go safe This is a standard Go standard library Windows registry access file with no malicious patterns detected
windows/registry/zsyscall_windows.go safe No malicious patterns detected; file contains standard Go-generated syscall bindings for Windows registry operations from golang.org/x/sys/windows.
windows/security_windows.go safe No malicious patterns detected; this is a standard Go standard library Windows security API binding.
windows/service.go safe Cleared by Jev triage; no further analysis needed
windows/setupapi_windows.go safe No malicious patterns detected; code is a legitimate Go wrapper for Windows SetupAPI/CfgMgr32 functions with no exfiltration, credential harvesting, obfuscation, or other security concerns.
windows/str.go safe Cleared by Jev triage; no further analysis needed
windows/svc/debug/log.go safe Cleared by Jev triage; no further analysis needed
windows/svc/debug/service.go safe This is a standard Go standard library debug helper for running Windows services on console; no malicious patterns detected.
windows/svc/eventlog/install.go safe This is a legitimate Go standard library file for Windows event log registry management with no malicious patterns.
windows/svc/eventlog/log.go safe No malicious patterns detected
windows/svc/example/beep.go safe No malicious patterns detected; the code only calls the Windows MessageBeep API via syscall, which is benign.
windows/svc/example/install.go safe No malicious patterns detected
windows/svc/example/main.go safe No malicious patterns detected; this is a legitimate Go example for Windows service management from the golang.org/x/sys package.
windows/svc/example/manage.go safe No malicious patterns detected; the code is a standard Go example for managing Windows services using the official golang.org/x/sys package.
windows/svc/example/service.go safe This is a standard, benign example service from the official golang.org/x/sys module with no malicious patterns detected.
windows/svc/mgr/config.go safe No malicious patterns detected
windows/svc/mgr/mgr.go safe This is the standard Go x/sys/windows/svc/mgr package which manages Windows services; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell spawning were detected.
windows/svc/mgr/service.go safe This is legitimate Go standard library code for Windows service management, with no malicious patterns detected.
windows/svc/security.go safe No malicious patterns detected; the code is legitimate Windows service detection logic from the Go standard library's x/sys/windows package.
windows/svc/service.go safe This is a legitimate, standard library Windows service wrapper from golang.org/x/sys with no malicious patterns detected.
windows/syscall.go safe No malicious patterns detected; the code is a standard part of the Go x/sys/windows package providing safe syscall helpers.
windows/syscall_windows.go safe This is the standard Go x/sys/windows syscall binding file with no malicious patterns detected.
windows/types_windows_386.go safe Cleared by Jev triage; no further analysis needed
windows/types_windows_amd64.go safe Cleared by Jev triage; no further analysis needed
windows/types_windows_arm.go safe Cleared by Jev triage; no further analysis needed
windows/types_windows_arm64.go safe Cleared by Jev triage; no further analysis needed
windows/zknownfolderids_windows.go safe No malicious patterns detected; the file only defines static KNOWNFOLDERID GUID constants generated by a build script.

Frequently asked questions

Is golang.org/x/sys safe to use?

golang.org/x/sys@v0.48.0 has 2 high, 12 medium, 24 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does golang.org/x/sys contain malware?

The latest scan of golang.org/x/sys (v0.48.0) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was golang.org/x/sys checked?

Togoder Security downloaded the published Go package and had an AI model read its 416 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan golang.org/x/sys together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/sys@v0.48.0, cost nothing.

Related security reports