Summary
Togoder Security scanned the Go package golang.org/x/sys@v0.48.0 on Oct 5, 2026. An AI review of 416 source files produced 2 high, 12 medium, 24 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 38
Feature detection bypass / forced capability enablement
NPS-969DA01E649B
The code unconditionally forces ARM64.HasAES, ARM64.HasPMULL, ARM64.HasSHA1, and ARM64.HasSHA2 to true using 'true ||' short-circuit logic. This means the runtime will report these CPU features as available even on hardware that does not support them. If any downstream code relies on these flags to select hardware-accelerated crypto routines, it could execute unsupported instructions, causing crashes, data corruption, or potentially exploitable misbehavior. This appears to be an intentional weakening of capability detection rather than benign feature reporting.
Tampering with runtime capability reporting
NPS-153EB71683DB
The 'true ||' pattern is used on four separate security-relevant flags (AES, PMULL, SHA1, SHA2), all of which are cryptographic acceleration features. Forcing them enabled is suspicious because it can silently alter which cryptographic implementation is used at runtime, potentially degrading security assumptions or introducing faults in security-sensitive code paths.
Unsafe reflection and pointer manipulation
NPS-C987CBBAB85C
The code uses reflect and unsafe pointers to access and modify unexported fields (lookPathErr) of exec.Cmd. This bypasses Go's type safety and field visibility rules, potentially leading to memory corruption or undefined behavior. While the purpose is to fix a security issue, this technique is fragile and could be exploited if the struct layout changes.
Build-time code execution
NPS-FC9C40E789BD
The file is a build tool (mkall.go) that spawns many external processes (make, gcc, go run, gofmt, mksyscall, mkpost, etc.) via os/exec. While this is legitimate for the Go syscall generator, any third-party package carrying this file should be treated as running arbitrary commands at build time.
Environment variable harvesting
NPS-4A9586DA0E0C
setupEnvironment copies the entire os.Environ() into child process environments and appends GOOS/GOARCH/CC/GORUN. This propagates all host environment variables (potentially including credentials) to spawned commands.
Commands constructed from external paths
NPS-F0276B3D52F9
LinuxDir, GlibcDir, and per-target GNUArch values derived from the targets table are used to build paths and invoke confScript (glibc configure) and make. If a caller supplies a malicious directory or the table were tampered with, arbitrary code is executed at build time.
Unsafe temp directory usage
NPS-8B9FF9F6589B
Uses a hardcoded TempDir = "/tmp" with os.MkdirAll(..., os.ModePerm) (0777) to create world-writable directories (e.g. /tmp/<arch>/include). On a multi-user system this is susceptible to symlink/race attacks and clobbering by other users.
Unsafe memory access via unsafe.Pointer
NPS-DD5763C764DE
The file makes extensive use of unsafe.Pointer for type punning, casting between socket address structures (e.g., SockaddrInet4, SockaddrInet6, SockaddrUnix, SockaddrCAN, etc.) and raw kernel structures. While expected in a syscall wrapper library, incorrect bounds checks or alignment assumptions could lead to memory corruption or information leaks. Examples include casting slices to raw sockaddr structs and using unsafe.Slice to read kernel-populated data (e.g., in anyToSockaddr for AF_UNIX, AF_PPPOX, AF_NFC).
Potential out-of-bounds read
NPS-F613CB4D5591
In anyToSockaddr for AF_UNIX, the code assumes the path is NUL-terminated and reads up to len(pp.Path) without a hard bound check beyond the array size; although the array is fixed-size, a non-NUL-terminated kernel-provided path could cause the loop to read uninitialized bytes. Similar patterns exist in AF_PPPOX and AF_NFC LLCP where kernel-provided lengths are trusted with limited validation.
Privileged operations exposed
NPS-C7907A43D649
The package provides wrappers for privileged syscalls such as ptrace, reboot, mount, swapon, init_module, delete_module, kexec_load, and keyctl. While these are legitimate system calls, exposing them without additional safeguards in a third-party library could facilitate privilege escalation or persistence if misused by downstream code.
shared memory segment size race
NPS-E8489F891EF7
The segment size used to create the slice is retrieved via a separate IPC_STAT call after shmat. If another process modifies the segment size (e.g., via shmctl IPC_RMID or remapping) between shmat and IPC_STAT, the slice length may not match the mapped region, potentially causing out-of-bounds reads/writes.
unsafe pointer usage
NPS-93DC0F97FA4E
The code uses unsafe.Pointer and unsafe.Slice to convert a raw memory address returned by shmat into a Go byte slice. This is an intentional part of the Unix shared memory API and is guarded by build tags for supported platforms, but unsafe usage can lead to memory corruption if the underlying segment size changes or is detached concurrently.
Unsafe memory access
NPS-521D150EF866
Multiple functions use unsafe.Pointer and unsafe.Slice to interpret raw byte buffers returned from queryServiceConfig2. In RecoveryActions, if the buffer is empty or malformed, &b[0] could panic or misinterpret memory. The pointer p.Actions is dereferenced assuming valid structure layout, which could lead to out-of-bounds reads if ActionsCount is corrupted or maliciously set by a service configuration.
Unsafe slice construction from external data
NPS-1C4E6874169C
RecoveryActions uses unsafe.Slice(p.Actions, int(p.ActionsCount)) directly on a pointer and count read from a Windows API response. If the underlying data is untrusted or corrupted, this could allow reading beyond the returned buffer. This is a potential memory safety issue.
System information gathering via sysctl
NPS-F1189D0919A4
The code calls sysctlbyname to query Darwin kernel parameters (likely for CPU feature detection). This is a standard, non-malicious use of sysctl in the Go runtime/internal/cpu package for platform detection.
Use of unsafe pointer conversions
NPS-F79ED139E31B
Uses unsafe.Pointer for syscall argument marshalling, which is typical for low-level syscall wrappers in the Go standard library and runtime. No obfuscation or malicious intent.
Spawns processes
NPS-780502E427A1
The package is a wrapper around os/exec and its primary function is to spawn external processes. The Command and CommandContext functions return exec.Cmd objects ready to run external commands. This is a normal but powerful capability that could be misused if the package is compromised or if input is not properly sanitized.
Filesystem writes outside package scope
NPS-AB2B234754E2
Writes generated outputs (zsysnum_*, zsyscall_*, ztypes_*, zerrors_*, zptrace_*, z*_linux.go) directly into the current working directory via os.Create, and also creates/removes files under /tmp.
Environment variable reliance
NPS-6E57792EF9BD
Reads GOOS, GOARCH_TARGET, GOARCH, GOLANG_SYS_BUILD, and CC environment variables and hard-fails unless GOLANG_SYS_BUILD=docker and CC is set. This is expected for a controlled build tool, but demonstrates environment-driven behavior.
Dynamic process invocation
NPS-8464A311E452
The CC value is used as the executable name for os/exec without validation. If an attacker can set CC in the build environment, arbitrary binaries could be executed during generation. However, this script is a legitimate Go source-tree generator (mksysnum), runs only with the 'ignore' build tag, and requires an explicit 'go run' invocation.
Command execution via os/exec
NPS-E07106D5A00D
The script invokes an external compiler (CC environment variable) via exec.Command(cc, args...).Output(). The command name comes from the CC environment variable and is executed with arguments from os.Args. This is standard for a code generator that preprocesses kernel headers, but an attacker controlling the environment (CC, GOOS, GOARCH, GOLANG_SYS_BUILD) could influence process execution. This file is guarded by '//go:build ignore' so it is not compiled into the unix package and is only run explicitly by the Go build system.
code generation tool
NPS-8C3A4974F7EB
This is the standard Go source file mksyscall_aix_ppc64.go from the golang.org/x/sys repository. It is a build-time code generator that reads syscall prototypes from input files and writes generated Go source files (zsyscall_aix_ppc64.go, zsyscall_aix_ppc64_gc.go, zsyscall_aix_ppc64_gccgo.go) to the local working directory. The //go:build ignore tag prevents it from being compiled as part of the package.
file system write
NPS-55E6D3D6E1A2
The program writes generated source files into the current working directory via os.WriteFile. This is expected behavior for a code generator and operates only on relative filenames within the current directory, not outside package scope.
external input parsing
NPS-EEBEAD0F941E
The program reads file paths from command-line arguments and parses //sys directives. Input is trusted local source files supplied by the developer; there is no network input, no shell execution, and no interpolation of input into shell commands.
process execution
NPS-F92338DB8292
The program uses os/exec to run /bin/cat, gofmt, and read a fixed system file. This is expected for a code generator and is not malicious.
file system manipulation
NPS-3241E641CFD7
The program creates and writes generated Go/asm files (zsyscall, zsymaddr, zsysnum) in the working directory. No files outside the package scope are modified.
build-time code generation
NPS-9F91FA0DA8DE
This file has //go:build ignore and is only run manually as a generator. It does not execute at import, build, or install time.
Network fetch
NPS-AF7E99D7C949
fetchFile performs HTTP GET requests to arbitrary URLs provided via command-line arguments. While this is for legitimate syscall table generation from official sources, it could be abused if the script were invoked with a malicious URL.
File system access
NPS-6C601BB8F4B6
readFile opens a file specified by os.Args[1], which is outside the package scope and controlled entirely by whoever invokes the tool. Not malicious in itself but an attacker-controlled input path.
Main entry point / top-level execution
NPS-AF425C4C0C6B
Contains a main() function guarded by //go:build ignore, so it does not execute at import time. Only runs when explicitly invoked via go run. This is normal for a code generator.
Environment variable access
NPS-9AED79389B87
Reads GOOS_TARGET, GOOS, GOARCH_TARGET, GOARCH environment variables. This is standard for Go cross-compilation tooling and not credential harvesting.
Race condition in KeyctlString
NPS-C6E79BB1B7C2
KeyctlString loops to dynamically size a buffer based on the kernel-reported length. If an attacker can modify the key data between the sizing and reading syscalls (TOCTOU), it could lead to returning a truncated or mismatched string, though not directly exploitable for memory corruption.
No malicious patterns detected
NPS-9663B61F1762
No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, cryptocurrency mining, backdoor installation, reverse shells, suspicious network requests, or unauthorized file system manipulation were found. The code is part of the official Go x/sys/unix package and follows standard syscall wrapper patterns.
memory management concern
NPS-91C612AF5981
C.CString allocations for path strings are not freed with C.free, causing a memory leak per call. This is a code quality issue rather than a security vulnerability, and is a known artifact of mksyscall-generated code.
CGO dynamic linking
NPS-A78FF3FDA255
The file uses //go:cgo_import_dynamic and //go:linkname directives to bind to AIX libc functions. These are standard mechanisms for Go's syscall package on AIX and are not malicious, but they do involve dynamic linking to system libraries.
Unsafe pointer usage
NPS-77A12D8FC4BC
The file uses unsafe.Pointer conversions to pass function pointers to syscall6 and rawSyscall6. This is standard in Go generated syscall wrappers and is not indicative of malicious intent.
DLL preloading risk (documented)
NPS-4CD77D41529E
LoadDLL and NewLazyDLL accept relative paths and are documented to be subject to DLL preloading attacks. This is a known Windows API behavior, and the code explicitly warns users to use NewLazySystemDLL or LoadLibraryEx for safe loading of system DLLs.
Potential out-of-bounds slice
NPS-C1FD16E3D4DA
In SetRecoveryActions, after building a slice 'actions', &actions[0] is taken without checking if len(actions) > 0. Although RecoveryActions nil check handles nil, an empty non-nil slice would cause an index out of range panic at runtime. This is a robustness issue but not directly malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cpu/cpu_darwin_arm64.go | critical | The file contains suspicious unconditional forcing of ARM64 cryptographic feature flags to true, which tampers with CPU capability detection and could cause unsupported instruction execution or cryptographic misbehavior. |
| execabs/execabs.go | medium | The execabs package is a legitimate security-focused wrapper around os/exec that safely enforces absolute path resolution, but its use of unsafe pointer manipulation and process spawning warrants cautious review. |
| unix/linux/mkall.go | medium | This is the legitimate Go x/sys linux/mkall.go build tool that deliberately spawns compilers and make, but its unsafe /tmp/0777 usage, propagation of the full host environment to child processes, and build-time execution of external scripts warrant caution if encountered outside the official Go repository. |
| unix/linux/mksysnum.go | medium | This is a legitimate Go syscall-number generator that spawns an external compiler from the CC environment variable, but it is not part of the compiled package and contains no malicious exfiltration, credential harvesting, backdoors, or obfuscated payloads. |
| unix/mksysnum.go | medium | Legitimate Go code generator for syscall tables with benign network/file access limited to explicit command-line inputs and no malicious patterns, though arbitrary URL/path inputs carry minimal risk. |
| unix/syscall_linux.go | medium | The code is the standard Go x/sys/unix syscall wrapper with expected unsafe memory operations and privileged syscall exposure, but no malicious patterns were identified. |
| unix/sysvshm_unix.go | medium | This is a standard Go x/sys/unix wrapper for SysV shared memory that uses unsafe pointers and performs a separate IPC_STAT call, which are expected but carry inherent memory-safety risks; no malicious behavior such as exfiltration, process spawning, or backdoor installation was found. |
| windows/svc/mgr/recovery.go | medium | The code contains unsafe pointer and slice usage typical of Windows system administration APIs, with potential memory safety risks when handling untrusted service configuration data, but no direct malicious patterns such as exfiltration, backdoors, or code execution. |
| cpu/byteorder.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu.go | safe | No malicious patterns detected; this is the standard Go CPU feature detection package with no data exfiltration, obfuscation, or suspicious behavior. |
| cpu/cpu_aix.go | safe | This is a standard Go CPU feature detection file for AIX that only queries system configuration and sets capability flags with no network, filesystem, process, or obfuscation concerns. |
| cpu/cpu_arm.go | safe | No malicious patterns detected; the code only defines CPU feature constants and registers feature detection options for ARM processors. |
| cpu/cpu_arm64.go | safe | This is a legitimate Go standard library CPU feature detection file for ARM64 with no malicious patterns detected. |
| cpu/cpu_darwin_arm64_other.go | safe | No malicious patterns detected; the file only sets ARM64 CPU feature flags at init time using safe, static assignments with no network, filesystem, or process activity. |
| cpu/cpu_darwin_x86.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gc_arm64.go | safe | No malicious patterns detected |
| cpu/cpu_gc_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gc_s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gc_x86.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gccgo_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gccgo_s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_gccgo_x86.go | safe | No malicious patterns detected; the file contains only standard Go runtime CPU feature detection via gccgo extern declarations. |
| cpu/cpu_linux.go | safe | No malicious patterns detected |
| cpu/cpu_linux_arm.go | safe | No malicious patterns detected |
| cpu/cpu_linux_arm64.go | safe | No malicious patterns detected |
Show 391 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| cpu/cpu_linux_loong64.go | safe | No malicious patterns detected |
| cpu/cpu_linux_mips64x.go | safe | No malicious patterns detected |
| cpu/cpu_linux_noinit.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_linux_ppc64x.go | safe | No malicious patterns detected |
| cpu/cpu_linux_riscv64.go | safe | No malicious patterns detected; the code performs legitimate RISC-V CPU feature detection via the riscv_hwprobe syscall and HWCAP, with no network, filesystem, process, or dynamic execution activity. |
| cpu/cpu_linux_s390x.go | safe | No malicious patterns detected; this is standard Go CPU feature detection code for s390x using HWCAP bitmask checks. |
| cpu/cpu_loong64.go | safe | No malicious patterns detected in the Go CPU feature detection file for LoongArch64; it contains only standard hardware capability checks with no network, filesystem, or process manipulation. |
| cpu/cpu_mips64x.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_mipsx.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_netbsd_amd64.go | safe | This is standard Go standard library CPU feature detection code for NetBSD/amd64 that disables AVX features due to a known OS signal-handling bug, with no malicious patterns detected. |
| cpu/cpu_netbsd_arm64.go | safe | This is a standard Go runtime CPU feature detection file for NetBSD/arm64 that uses sysctl system calls to read hardware capabilities, with no malicious patterns detected. |
| cpu/cpu_openbsd_arm64.go | safe | No malicious patterns detected; code is standard Go standard library CPU feature detection for OpenBSD/arm64 using sysctl. |
| cpu/cpu_other_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_other_arm64.go | safe | No malicious patterns detected |
| cpu/cpu_other_mips64x.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_other_ppc64x.go | safe | No malicious patterns detected |
| cpu/cpu_other_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_other_x86.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_ppc64x.go | safe | This is a standard Go runtime internal CPU feature detection file for ppc64/ppc64le architectures with no malicious patterns. |
| cpu/cpu_riscv64.go | safe | No malicious patterns detected |
| cpu/cpu_s390x.go | safe | No malicious patterns detected |
| cpu/cpu_sparc64.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_wasm.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/cpu_windows.go | safe | Standard Go standard library CPU feature detection code with no malicious patterns detected |
| cpu/cpu_windows_arm64.go | safe | This is a legitimate Go standard library CPU feature detection file for Windows ARM64 with no malicious patterns. |
| cpu/cpu_x86.go | safe | This is a standard Go standard library CPU feature detection file that uses CPUID instructions to identify x86 processor capabilities, with no malicious patterns. |
| cpu/cpu_zos.go | safe | No malicious patterns detected |
| cpu/cpu_zos_s390x.go | safe | No malicious patterns detected |
| cpu/endian_big.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/endian_little.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/hwcap_linux.go | safe | This is standard Go standard library code that reads CPU hardware capabilities from /proc/self/auxv with no malicious patterns detected |
| cpu/parse.go | safe | Cleared by Jev triage; no further analysis needed |
| cpu/proc_cpuinfo_linux.go | safe | The code reads /proc/cpuinfo on Linux ARM64 to detect CPU features and contains no malicious patterns; it is a legitimate part of the Go standard library. |
| cpu/runtime_auxv.go | safe | No malicious patterns detected |
| cpu/runtime_auxv_go121.go | safe | No malicious patterns detected; this is a standard Go internal CPU feature detection file using linkname to access runtime auxiliary vector. |
| cpu/syscall_aix_gccgo.go | safe | The file contains a standard syscall wrapper for AIX/gccgo without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or network activity. |
| cpu/syscall_aix_ppc64_gc.go | safe | This is a legitimate, minimal Go runtime file from the standard library that makes a dynamic syscall to getsystemcfg on AIX for CPU feature detection, with no malicious patterns present. |
| cpu/syscall_darwin_arm64_gc.go | safe | The file is a legitimate Go runtime/internal/cpu helper for Darwin arm64 that makes sysctl calls for CPU feature detection; no malicious patterns were found. |
| cpu/syscall_darwin_x86_gc.go | safe | No malicious patterns detected; the code contains legitimate Darwin sysctl system call wrappers for CPU detection with no exfiltration, obfuscation, or suspicious behavior. |
| cpu/zcpu_windows.go | safe | No malicious patterns detected; code is a standard Go generated file accessing kernel32.dll for CPU feature detection on Windows. |
| execabs/execabs_go118.go | safe | No malicious patterns detected |
| execabs/execabs_go119.go | safe | No malicious patterns detected; the file contains only small helper functions wrapping standard library error checks for Go 1.19 compatibility. |
| plan9/const_plan9.go | safe | Cleared by Jev triage; no further analysis needed |
| plan9/dir_plan9.go | safe | Cleared by Jev triage; no further analysis needed |
| plan9/env_plan9.go | safe | No malicious patterns detected |
| plan9/errors_plan9.go | safe | This file contains only standard Plan 9 OS constant definitions and statically initialized error variables; no malicious patterns, dynamic code, network activity, or filesystem/process manipulation were detected. |
| plan9/mksyscall.go | safe | This is a legitimate Go code generation tool from the standard library that parses syscall declarations and generates system call wrapper code, with no malicious patterns detected. |
| plan9/pwd_plan9.go | safe | No malicious patterns detected; this is a minimal, legitimate Plan 9 syscall wrapper from the Go standard library. |
| plan9/race.go | safe | No malicious patterns detected; this is a standard Go standard library race detector support file for Plan 9, containing only runtime race instrumentation wrappers. |
| plan9/race0.go | safe | No malicious patterns detected |
| plan9/str.go | safe | Cleared by Jev triage; no further analysis needed |
| plan9/syscall.go | safe | No malicious patterns detected; this is standard Go x/sys Plan 9 system call support code from the Go project. |
| plan9/syscall_plan9.go | safe | No malicious patterns detected; the file contains standard Plan 9 system call bindings from the Go standard library. |
| plan9/zsyscall_plan9_386.go | safe | This is a standard Go generated syscall wrapper file for Plan 9 386 architecture, containing only legitimate system call bindings and unsafe pointer usage typical of the Go standard library, with no malicious patterns detected. |
| plan9/zsyscall_plan9_amd64.go | safe | No malicious patterns detected; this is standard auto-generated Go syscall wrapper code for Plan 9 amd64. |
| plan9/zsyscall_plan9_arm.go | safe | This is a standard Go syscall binding file for Plan 9 ARM, generated by mksyscall, containing only low-level OS syscall wrappers with no malicious patterns. |
| plan9/zsysnum_plan9.go | safe | No malicious patterns detected; the file only contains constant syscall number definitions for Plan 9. |
| unix/affinity_linux.go | safe | No malicious patterns detected; this is a standard Go syscall wrapper for Linux CPU affinity operations with no network, filesystem, or process execution behavior. |
| unix/aliases.go | safe | No malicious patterns detected |
| unix/auxv.go | safe | No malicious patterns detected |
| unix/auxv_unsupported.go | safe | This is a standard Go standard library compatibility stub that returns ENOTSUP on unsupported build configurations, with no malicious patterns detected. |
| unix/bluetooth_linux.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/bpxsvc_zos.go | safe | This is legitimate z/OS-specific system call wrapper code from the Go standard library, with no malicious patterns detected. |
| unix/cap_freebsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/constants.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_aix_ppc.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_aix_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_darwin.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_dragonfly.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_freebsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_linux.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_netbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_openbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dev_zos.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/dirent.go | safe | No malicious patterns detected in this standard Go syscall directory parsing code. |
| unix/endian_big.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/endian_little.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/env_unix.go | safe | No malicious patterns detected |
| unix/fcntl.go | safe | No malicious patterns detected |
| unix/fcntl_darwin.go | safe | No malicious patterns detected |
| unix/fcntl_linux_32bit.go | safe | No malicious patterns detected |
| unix/fdset.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/gccgo.go | safe | No malicious patterns detected; this is a standard Go syscall wrapper for gccgo with build constraints for non-AIX/non-Hurd Unix systems. |
| unix/gccgo_linux_amd64.go | safe | No malicious patterns detected |
| unix/ifreq_linux.go | safe | No malicious patterns detected; the code is a legitimate low-level unsafe wrapper for Linux interface requests from the Go standard library. |
| unix/internal/mkmerge/mkmerge.go | safe | This is a legitimate Go source file from the Go standard library's internal tooling; it performs AST-based source merging with no network, credential, execution, or obfuscation concerns. |
| unix/ioctl_linux.go | safe | No malicious patterns detected; the code is a standard Go library ioctl wrapper with no exfiltration, obfuscation, or backdoor behavior. |
| unix/ioctl_signed.go | safe | No malicious patterns detected; the file contains standard Go ioctl wrapper functions for AIX and Solaris with no exfiltration, execution, or suspicious behavior. |
| unix/ioctl_unsigned.go | safe | The file is a standard part of the Go x/sys/unix package providing ioctl wrappers with no malicious patterns, network activity, or code execution. |
| unix/ioctl_zos.go | safe | This is a standard Go standard library ioctl wrapper file for z/OS; no malicious patterns, network activity, credential access, or dynamic code execution present. |
| unix/mkasm.go | safe | This is a standard Go code generation tool from the Go standard library that creates assembly trampolines; it performs only local file reading and writing with no malicious patterns. |
| unix/mkpost.go | safe | This is a legitimate Go source file from the standard library's golang.org/x/sys repository; it is a build-time code generation helper that performs regex-based transformations on cgo output and contains no malicious patterns. |
| unix/mksyscall.go | safe | No malicious patterns detected; this is a legitimate Go code generator for system call wrappers in the golang.org/x/sys repository. |
| unix/mksyscall_aix_ppc.go | safe | This is a legitimate Go code generation tool from the official golang.org/x/sys repository that reads syscall prototypes and generates wrapper code, with no malicious patterns detected. |
| unix/mksyscall_aix_ppc64.go | safe | This is the legitimate Go x/sys code generator for AIX syscall wrappers; it only performs local file reads/writes and contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, or shell execution. |
| unix/mksyscall_solaris.go | safe | This is a standard Go code generator from the golang.org/x/sys repository that produces syscall wrappers for Solaris; no malicious patterns, network activity, credential access, or obfuscation were detected. |
| unix/mksyscall_zos_s390x.go | safe | Standard Go syscall code generator for z/OS s390x that only reads a fixed system file and writes generated source files; no malicious patterns detected. |
| unix/mksysctl_openbsd.go | safe | No malicious patterns detected; this is a standard Go code generator that parses OpenBSD header files to produce sysctl MIB definitions. |
| unix/mmap_nomremap.go | safe | No malicious patterns detected; this is a standard Go standard-library source file defining an mmapper initialization for memory mapping utilities. |
| unix/mremap.go | safe | No malicious patterns detected; the code is a legitimate low-level memory mapping utility from the Go standard library's unix package. |
| unix/pagesize_unix.go | safe | No malicious patterns detected |
| unix/pledge_openbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ptrace_darwin.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ptrace_ios.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/race.go | safe | No malicious patterns detected |
| unix/race0.go | safe | This is a standard Go standard library race detector stub file with no malicious patterns; all functions are empty no-ops and no network, filesystem, process, or dynamic code execution is present. |
| unix/readdirent_getdents.go | safe | No malicious patterns detected |
| unix/readdirent_getdirentries.go | safe | This is a standard Go standard library wrapper for the getdirentries syscall on darwin/zos with no malicious patterns detected. |
| unix/readv_unix.go | safe | No malicious patterns detected; the code is a standard part of the Go standard library for vectored I/O operations. |
| unix/sockcmsg_dragonfly.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/sockcmsg_linux.go | safe | No malicious patterns detected |
| unix/sockcmsg_unix.go | safe | No malicious patterns detected; this is standard Go standard-library code for socket control message parsing. |
| unix/sockcmsg_unix_other.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/sockcmsg_zos.go | safe | No malicious patterns detected; this is a legitimate Go standard library syscall helper for encoding and parsing socket control messages (Unix credentials, packet info) on z/OS. |
| unix/syscall.go | safe | No malicious patterns detected |
| unix/syscall_aix.go | safe | No malicious patterns detected; this is a standard Go syscall wrapper file for AIX from the golang.org/x/sys/unix package. |
| unix/syscall_aix_ppc.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_aix_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_bsd.go | safe | This is a standard Go syscall wrapper file for BSD systems from the official golang.org/x/sys/unix package, containing only legitimate system call bindings and socket address conversion routines with no malicious patterns. |
| unix/syscall_darwin.go | safe | No malicious patterns detected; this is standard Go syscall wrapper code for Darwin with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| unix/syscall_darwin_amd64.go | safe | No malicious patterns detected |
| unix/syscall_darwin_arm64.go | safe | This is a standard Go syscall compatibility file with only type conversion helpers and syscall declarations; no malicious patterns were detected. |
| unix/syscall_darwin_libSystem.go | safe | This is a standard Go standard library file that declares low-level syscall functions and uses go:linkname to link them to runtime implementations, with no malicious patterns detected. |
| unix/syscall_dragonfly.go | safe | No malicious patterns detected |
| unix/syscall_dragonfly_amd64.go | safe | This is a legitimate Go standard library/x/sys file containing low-level DragonFly BSD system call wrappers and type conversion helpers with no malicious patterns. |
| unix/syscall_freebsd.go | safe | No malicious patterns detected; this is standard Go FreeBSD syscall wrapper code from the official golang.org/x/sys repository. |
| unix/syscall_freebsd_386.go | safe | No malicious patterns detected; the code is a standard part of the Go x/sys/unix package with platform-specific syscall helpers. |
| unix/syscall_freebsd_amd64.go | safe | No malicious patterns detected |
| unix/syscall_freebsd_arm.go | safe | No malicious patterns detected |
| unix/syscall_freebsd_arm64.go | safe | No malicious patterns detected; generated syscall wrapper code for FreeBSD arm64 with no external I/O, credential access, or code execution. |
| unix/syscall_freebsd_riscv64.go | safe | No malicious patterns detected; this is standard Go low-level syscall glue code for FreeBSD/riscv64 with no network, file, process, or obfuscation activity. |
| unix/syscall_hurd.go | safe | No malicious patterns detected; the code is a standard Go syscall wrapper for ioctl on Hurd with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| unix/syscall_hurd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_illumos.go | safe | No malicious patterns detected |
| unix/syscall_linux_386.go | safe | This is a standard Go standard library syscall wrapper file for Linux 386 with no malicious patterns, obfuscation, network exfiltration, or install-time execution. |
| unix/syscall_linux_alarm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_linux_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_linux_amd64_gc.go | safe | No malicious patterns detected |
| unix/syscall_linux_arm.go | safe | No malicious patterns detected; this is a standard Go syscall wrapper for Linux ARM with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| unix/syscall_linux_arm64.go | safe | This is a standard Go unix syscall wrapper file for Linux on arm64 with no malicious patterns, no network exfiltration, no credential harvesting, no obfuscated code execution, and no install-time hooks. |
| unix/syscall_linux_gc.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_linux_gc_386.go | safe | No malicious patterns detected |
| unix/syscall_linux_gc_arm.go | safe | No malicious patterns detected |
| unix/syscall_linux_gccgo_386.go | safe | This is standard Go syscall wrapper code for Linux 386 gccgo architecture with no malicious patterns detected. |
| unix/syscall_linux_gccgo_arm.go | safe | Legitimate Go standard library low-level syscall wrapper for _llseek with no malicious patterns |
| unix/syscall_linux_loong64.go | safe | No malicious patterns detected; this is standard Go syscall wrapper code for Linux on the loong64 architecture. |
| unix/syscall_linux_mips64x.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_linux_mipsx.go | safe | Standard Go syscall wrappers for Linux MIPS architectures with no malicious patterns detected |
| unix/syscall_linux_ppc.go | safe | No malicious patterns detected |
| unix/syscall_linux_ppc64x.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_linux_riscv64.go | safe | This is a legitimate portion of the Go standard library's syscall bindings for Linux riscv64, containing only standard syscall wrappers and helper functions with no malicious patterns. |
| unix/syscall_linux_s390x.go | safe | No malicious patterns detected; the file contains standard Linux s390x syscall wrappers from the Go x/sys/unix package. |
| unix/syscall_linux_sparc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_netbsd.go | safe | This is the standard Go x/sys/unix package file for NetBSD syscall bindings; no malicious patterns, exfiltration, backdoors, or suspicious behavior detected. |
| unix/syscall_netbsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_netbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_netbsd_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_netbsd_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd.go | safe | No malicious patterns detected; this is standard Go x/sys/unix OpenBSD syscall wrapper code with only expected system call bindings and data conversions. |
| unix/syscall_openbsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_libc.go | safe | No malicious patterns detected; the file only declares low-level syscall wrappers via linkname for OpenBSD runtime integration. |
| unix/syscall_openbsd_mips64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_openbsd_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_solaris.go | safe | No malicious patterns detected; this is a standard Go standard library syscall wrapper file with no exfiltration, obfuscation, or backdoor behavior. |
| unix/syscall_solaris_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/syscall_unix.go | safe | No malicious patterns detected |
| unix/syscall_unix_gc.go | safe | No malicious patterns detected |
| unix/syscall_unix_gc_ppc64x.go | safe | No malicious patterns detected; the file contains standard syscall wrappers for ppc64/ppc64le Linux with no network, file, process, or obfuscation behavior. |
| unix/syscall_zos_s390x.go | safe | This is a standard Go syscall implementation for z/OS s390x; the init() function only reads environment variables for optional tracing configuration and does not exhibit any malicious patterns. |
| unix/sysvshm_linux.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/sysvshm_unix_other.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/timestruct.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/types_aix.go | safe | No malicious patterns detected; this is a standard Go cgo -godefs type definition file for AIX platform bindings with only C type mappings and constants. |
| unix/types_darwin.go | safe | This is a standard Go cgo godefs type definition file from the golang.org/x/sys/unix package containing only platform type mappings with no executable logic or malicious patterns. |
| unix/types_dragonfly.go | safe | This is a standard Go cgo -godefs type definition file for DragonFly BSD, containing only C struct mappings and constants with no executable or malicious code. |
| unix/types_freebsd.go | safe | This is a standard Go cgo godefs type definition file from the golang.org/x/sys/unix package with no malicious patterns, network activity, credential access, or code execution. |
| unix/types_netbsd.go | safe | No malicious patterns detected; this is a standard Go cgo -godefs type definition file for NetBSD system structures from the golang.org/x/sys/unix package. |
| unix/types_openbsd.go | safe | No malicious patterns detected |
| unix/types_solaris.go | safe | This is a standard Go cgo type definition file for Solaris with no executable code, network calls, or malicious patterns. |
| unix/unveil_openbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/vgetrandom_linux.go | safe | No malicious patterns detected; the file is a standard Go runtime linkname declaration for the vgetrandom syscall wrapper in the unix package. |
| unix/vgetrandom_unsupported.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/xattr_bsd.go | safe | This is standard Go standard library code for BSD extended attribute syscalls; no malicious patterns detected. |
| unix/zerrors_aix_ppc.go | safe | No malicious patterns detected; this is a standard generated Go constants file for AIX syscall definitions with no executable code, network activity, or file system access. |
| unix/zerrors_aix_ppc64.go | safe | No malicious patterns detected |
| unix/zerrors_darwin_amd64.go | safe | No malicious patterns detected |
| unix/zerrors_darwin_arm64.go | safe | No malicious patterns detected in this auto-generated Go constants file, which contains only standard Darwin syscall, error, and signal numeric definitions. |
| unix/zerrors_dragonfly_amd64.go | safe | No malicious patterns detected; this is a generated Go constants file for DragonFly BSD system calls and error/signal definitions. |
| unix/zerrors_freebsd_386.go | safe | This is an auto-generated Go constants file containing only syscall constants, error tables, and signal definitions for FreeBSD/386 with no executable logic or malicious patterns. |
| unix/zerrors_freebsd_amd64.go | safe | Code contains only Go constant definitions and lookup tables for FreeBSD error and signal codes; no malicious patterns detected. |
| unix/zerrors_freebsd_arm.go | safe | This is a standard Go-generated file containing FreeBSD ARM system constants, error codes, and signal definitions with no executable logic or malicious patterns. |
| unix/zerrors_freebsd_arm64.go | safe | No malicious patterns detected; the file is a generated constants definition for FreeBSD arm64 system calls and error codes. |
| unix/zerrors_freebsd_riscv64.go | safe | No malicious patterns detected; this is a standard Go generated file containing FreeBSD riscv64 system constants, error codes, and signal definitions for the golang.org/x/sys/unix package. |
| unix/zerrors_linux_386.go | safe | No malicious patterns detected |
| unix/zerrors_linux_amd64.go | safe | This is an auto-generated Go constants file from the golang.org/x/sys/unix package containing only Linux syscall, errno, signal, and ioctl constant definitions with no executable code or malicious patterns. |
| unix/zerrors_linux_arm.go | safe | This is a standard auto-generated Go constant file for Linux ARM syscall definitions, containing only compile-time constants and static data tables with no executable code or security-relevant behavior. |
| unix/zerrors_linux_arm64.go | safe | No malicious patterns detected; this is a standard Go-generated constants file containing Linux arm64 ioctl, error, and signal definitions from the golang.org/x/sys/unix package. |
| unix/zerrors_linux_loong64.go | safe | No malicious patterns detected |
| unix/zerrors_linux_mips.go | safe | No malicious patterns detected |
| unix/zerrors_linux_mips64.go | safe | This is a standard auto-generated Go file defining Linux ioctl constants, error numbers, and signal numbers for mips64 architectures; no malicious patterns detected. |
| unix/zerrors_linux_mips64le.go | safe | This is an auto-generated Go file containing only constant definitions for Linux MIPS64LE syscall/ioctl values, with no executable code, network activity, or suspicious patterns. |
| unix/zerrors_linux_mipsle.go | safe | No malicious patterns detected; this is an auto-generated Go constants file defining Linux syscall/ioctl/error/signal values for mipsle architecture. |
| unix/zerrors_linux_ppc.go | safe | No malicious patterns detected; this file contains only generated Go constants for Linux/PPC syscall and terminal definitions with no executable logic. |
| unix/zerrors_linux_ppc64.go | safe | No malicious patterns detected; the file is a standard Go-generated constants definition for Linux ppc64 system errors, signals, and ioctl values from the golang.org/x/sys/unix package. |
| unix/zerrors_linux_ppc64le.go | safe | No malicious patterns detected; this is an auto-generated Go constants file for Linux ppc64le syscall/ioctl definitions. |
| unix/zerrors_linux_riscv64.go | safe | No malicious patterns detected |
| unix/zerrors_linux_s390x.go | safe | No malicious patterns detected; this is a generated Go file containing only Linux system constants for the s390x architecture. |
| unix/zerrors_linux_sparc64.go | safe | No malicious patterns detected; this is a standard Go generated constants file for Linux sparc64 syscall definitions with no executable code or suspicious behavior. |
| unix/zerrors_netbsd_386.go | safe | This is a standard Go generated file containing only constant definitions for NetBSD 386 syscall constants and no executable code or malicious patterns. |
| unix/zerrors_netbsd_amd64.go | safe | No malicious patterns detected |
| unix/zerrors_netbsd_arm.go | safe | This is an auto-generated Go constants file for NetBSD ARM syscalls, containing only platform-specific constant definitions with no executable or malicious code. |
| unix/zerrors_netbsd_arm64.go | safe | No malicious patterns detected |
| unix/zerrors_openbsd_386.go | safe | No malicious patterns detected; this is a standard auto-generated Go constants file for OpenBSD 386 syscall definitions. |
| unix/zerrors_openbsd_amd64.go | safe | This is an auto-generated Go file containing only OpenBSD amd64 system call constants, error codes, and signal definitions with no executable code or malicious patterns. |
| unix/zerrors_openbsd_arm.go | safe | No malicious patterns detected; this is a standard Go generated constants file for OpenBSD ARM syscall definitions. |
| unix/zerrors_openbsd_arm64.go | safe | This is an auto-generated Go constant definition file for OpenBSD arm64 syscall values with no executable logic or malicious patterns. |
| unix/zerrors_openbsd_mips64.go | safe | Generated Go constants file containing only system call, error, and signal definitions for OpenBSD mips64 with no executable or malicious code |
| unix/zerrors_openbsd_ppc64.go | safe | This is an auto-generated Go constants file from the golang.org/x/sys/unix package containing only platform-specific syscall constants, error codes, and signal tables for OpenBSD on ppc64, with no executable code or malicious patterns. |
| unix/zerrors_openbsd_riscv64.go | safe | This file contains only standard OpenBSD riscv64 system call constants, error codes, and signal definitions auto-generated by cgo; no malicious patterns detected. |
| unix/zerrors_solaris_amd64.go | safe | No malicious patterns detected; the file contains only generated constant definitions, error tables, and signal tables with no executable logic or external interactions. |
| unix/zerrors_zos_s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zptrace_armnn_linux.go | safe | This is a standard generated Go wrapper file for Linux ptrace register access on ARM/ARM64 with no malicious patterns detected. |
| unix/zptrace_linux_arm64.go | safe | No malicious patterns detected; the code is a standard ptrace register getter/setter using unsafe pointers for legitimate syscall data transfer. |
| unix/zptrace_mipsnn_linux.go | safe | No malicious patterns detected; the file contains only standard generated ptrace register access helpers for MIPS/MIPS64 in x/sys/unix. |
| unix/zptrace_mipsnnle_linux.go | safe | This is a machine-generated Go wrapper for ptrace syscalls on MIPS architectures with no malicious patterns detected. |
| unix/zptrace_x86_linux.go | safe | This generated Go file contains only standard ptrace register definitions and wrappers for 386/amd64, with no malicious patterns, network activity, or code execution. |
| unix/zsyscall_aix_ppc.go | safe | This is a standard Go syscall binding file generated by mksyscall for AIX/ppc; it contains only thin cgo wrappers around native system calls with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor code. |
| unix/zsyscall_aix_ppc64.go | safe | This is a standard auto-generated Go syscall wrapper file for AIX/ppc64 with no malicious patterns, exfiltration, or dynamic code execution. |
| unix/zsyscall_aix_ppc64_gc.go | safe | This is a standard Go generated syscall wrapper for AIX ppc64; no malicious patterns were detected. |
| unix/zsyscall_aix_ppc64_gccgo.go | safe | No malicious patterns detected; this is a standard Go syscall wrapper file generated by the Go toolchain for AIX/PowerPC64/gccgo builds. |
| unix/zsyscall_darwin_amd64.go | safe | This is a standard Go-generated syscall wrapper file for macOS (darwin/amd64) from the golang.org/x/sys/unix package, containing only legitimate libc bindings with no malicious patterns. |
| unix/zsyscall_darwin_arm64.go | safe | This is a standard Go-generated syscall binding file for darwin/arm64 from the golang.org/x/sys/unix package, containing only legitimate libc wrappers with no malicious patterns. |
| unix/zsyscall_dragonfly_amd64.go | safe | This is an auto-generated syscall wrapper file from the golang.org/x/sys/unix package for DragonFly BSD/amd64; it contains only standard low-level syscall bindings with no malicious patterns such as exfiltration, obfuscation, backdoors, or install-time execution. |
| unix/zsyscall_freebsd_386.go | safe | This is a standard Go-generated syscall wrapper file for FreeBSD 386 from golang.org/x/sys/unix with no malicious patterns, no network exfiltration, no obfuscation, no install-time hooks, and no credential harvesting. |
| unix/zsyscall_freebsd_amd64.go | safe | This is a standard Go-generated syscall wrapper file for FreeBSD/amd64 containing only low-level system call bindings with no malicious patterns. |
| unix/zsyscall_freebsd_arm.go | safe | This is a standard Go-generated syscall wrapper file for FreeBSD/ARM from the golang.org/x/sys/unix package with no malicious patterns, no network activity, no obfuscation, and no dynamic code execution. |
| unix/zsyscall_freebsd_arm64.go | safe | No malicious patterns detected; this is a standard machine-generated Go syscall binding file for FreeBSD arm64 from the golang.org/x/sys/unix package. |
| unix/zsyscall_freebsd_riscv64.go | safe | This is a standard Go-generated syscall wrapper file for FreeBSD/riscv64 from the golang.org/x/sys/unix package; it contains only routine system call bindings with no malicious patterns, obfuscation, network exfiltration, or dynamic code execution. |
| unix/zsyscall_illumos_amd64.go | safe | This is a standard Go syscall wrapper file generated for illumos/amd64, containing only legitimate libc dynamic import bindings for readv, preadv, writev, pwritev, and accept4 with no malicious patterns. |
| unix/zsyscall_linux.go | safe | This is a standard machine-generated Go syscall wrapper file from golang.org/x/sys/unix containing only direct syscall bindings with no malicious patterns. |
| unix/zsyscall_linux_386.go | safe | This is auto-generated Go syscall wrapper code for Linux 386, containing only standard low-level system call bindings with no malicious patterns. |
| unix/zsyscall_linux_amd64.go | safe | This is a standard Go syscall wrapper file from golang.org/x/sys/unix containing legitimate low-level Linux syscall bindings with no malicious patterns. |
| unix/zsyscall_linux_arm.go | safe | This is a standard, auto-generated Go syscall wrapper file for Linux ARM from the golang.org/x/sys/unix package with no malicious patterns detected. |
| unix/zsyscall_linux_arm64.go | safe | This is a standard Go syscall wrapper file generated by mksyscall.go for linux/arm64; no malicious patterns, network calls, process spawning, or obfuscation were detected. |
| unix/zsyscall_linux_loong64.go | safe | No malicious patterns detected; this is a standard generated syscall wrapper file for Linux loong64 from the golang.org/x/sys/unix package. |
| unix/zsyscall_linux_mips.go | safe | This is an auto-generated Go syscall wrapper file for Linux MIPS architecture from the golang.org/x/sys/unix package containing only standard libc syscall bindings with no malicious patterns. |
| unix/zsyscall_linux_mips64.go | safe | This is a standard Go syscall wrapper file auto-generated by mksyscall for linux/mips64, containing only thin wrappers around kernel syscalls with no malicious patterns. |
| unix/zsyscall_linux_mips64le.go | safe | This is a standard auto-generated Go syscall binding file for Linux mips64le architecture containing no malicious patterns. |
| unix/zsyscall_linux_mipsle.go | safe | This is a standard Go-generated syscall wrapper file for Linux/MIPSLE with no malicious patterns. |
| unix/zsyscall_linux_ppc.go | safe | This is a standard Go syscall wrapper file generated by mksyscall for Linux/ppc, containing only low-level system call bindings with no malicious patterns. |
| unix/zsyscall_linux_ppc64.go | safe | No malicious patterns detected in this auto-generated Go syscall wrapper file for linux/ppc64, which contains only standard syscall bindings. |
| unix/zsyscall_linux_ppc64le.go | safe | This is a standard generated Go syscall wrapper file for Linux ppc64le from the golang.org/x/sys/unix package, containing only direct system call bindings with no malicious patterns. |
| unix/zsyscall_linux_riscv64.go | safe | This is an auto-generated Go syscall wrapper file for linux/riscv64 from the golang.org/x/sys/unix package containing standard libc syscall bindings with no malicious patterns. |
| unix/zsyscall_linux_s390x.go | safe | This is a standard Go-generated syscall wrapper file for linux/s390x from the golang.org/x/sys/unix package, containing only direct kernel syscall bindings with no malicious patterns. |
| unix/zsyscall_linux_sparc64.go | safe | This is a standard Go generated syscall wrapper file for Linux on SPARC64 architecture, containing only legitimate low-level syscall bindings with no malicious patterns. |
| unix/zsyscall_netbsd_386.go | safe | This is a standard Go generated syscall wrapper file for NetBSD 386 from golang.org/x/sys/unix, containing only legitimate OS system call bindings with no malicious patterns. |
| unix/zsyscall_netbsd_amd64.go | safe | Generated Go syscall bindings for NetBSD/amd64 wrapping standard low-level system calls with no malicious patterns detected. |
| unix/zsyscall_netbsd_arm.go | safe | Generated Go syscall bindings for NetBSD/ARM contain only standard libc wrapper calls with no malicious patterns. |
| unix/zsyscall_netbsd_arm64.go | safe | This is a standard Go syscall wrapper file generated by mksyscall.go for NetBSD arm64; it contains only legitimate low-level system call bindings with no malicious patterns. |
| unix/zsyscall_openbsd_386.go | safe | This is a standard auto-generated Go syscall binding file for OpenBSD/386 that only provides thin wrappers around libc functions with no malicious patterns. |
| unix/zsyscall_openbsd_amd64.go | safe | Auto-generated Go syscall bindings for OpenBSD with no malicious patterns detected |
| unix/zsyscall_openbsd_arm.go | safe | This is a standard Go generated syscall binding file for OpenBSD/ARM that only wraps libc functions via cgo trampolines with no malicious patterns. |
| unix/zsyscall_openbsd_arm64.go | safe | No malicious patterns detected; this is a standard auto-generated Go syscall binding file for OpenBSD on arm64 dynamically linking to libc. |
| unix/zsyscall_openbsd_mips64.go | safe | This is a standard Go-generated syscall wrapper file for OpenBSD/mips64 from the golang.org/x/sys/unix package, containing only libc syscall trampolines and no malicious patterns. |
| unix/zsyscall_openbsd_ppc64.go | safe | No malicious patterns detected; this is a standard Go generated syscall wrapper for OpenBSD/ppc64 with only C library trampoline definitions and direct syscall invocations. |
| unix/zsyscall_openbsd_riscv64.go | safe | This is a standard Go generated syscall wrapper file for OpenBSD/riscv64 from golang.org/x/sys/unix; it contains only legitimate libc bindings with no malicious patterns. |
| unix/zsyscall_solaris_amd64.go | safe | This is a standard Go generated syscall binding file for Solaris/amd64 from golang.org/x/sys/unix; it contains only libc dynamic import declarations and syscall wrappers with no network, persistence, obfuscation, or credential-harvesting behavior. |
| unix/zsyscall_zos_s390x.go | safe | This is a standard auto-generated Go syscall wrapper file for z/OS s390x, containing only legitimate OS system call bindings with no malicious patterns. |
| unix/zsysctl_openbsd_386.go | safe | No malicious patterns detected in this auto-generated Go file defining OpenBSD sysctl MIB mappings. |
| unix/zsysctl_openbsd_amd64.go | safe | This file is an auto-generated static lookup table of OpenBSD sysctl MIB entries with no executable code, network access, file system operations, or suspicious patterns. |
| unix/zsysctl_openbsd_arm.go | safe | No malicious patterns detected; this is a generated Go table mapping OpenBSD sysctl names to MIB OIDs. |
| unix/zsysctl_openbsd_arm64.go | safe | This is a generated Go file containing only static sysctl MIB name-to-OID mapping data for OpenBSD/arm64 with no executable code or malicious patterns. |
| unix/zsysctl_openbsd_mips64.go | safe | This is a generated Go file containing only a static lookup table of sysctl MIB entries for OpenBSD on mips64, with no executable logic, network activity, or malicious patterns. |
| unix/zsysctl_openbsd_ppc64.go | safe | This is a generated Go file containing only a static lookup table of sysctl MIB entries for OpenBSD ppc64, with no executable code, network activity, file access, or other malicious patterns. |
| unix/zsysctl_openbsd_riscv64.go | safe | No malicious patterns detected; file contains a static table of OpenBSD sysctl MIB mappings for riscv64 with no executable logic, network activity, filesystem access, or process spawning. |
| unix/zsysnum_darwin_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_darwin_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_dragonfly_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_freebsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_freebsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_freebsd_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_freebsd_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_freebsd_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_loong64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_mips.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_mips64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_mips64le.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_mipsle.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_ppc.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_ppc64le.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_linux_sparc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_netbsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_netbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_netbsd_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_netbsd_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_mips64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/zsysnum_openbsd_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_aix_ppc.go | safe | This is a generated Go type definition file for AIX on PPC containing only struct layouts, constants, and type aliases, with no executable logic or malicious patterns. |
| unix/ztypes_aix_ppc64.go | safe | No malicious patterns detected; this is a standard Go-generated type definition file for AIX ppc64 syscall/struct bindings. |
| unix/ztypes_darwin_amd64.go | safe | No malicious patterns detected; this is a standard Go generated file containing only type definitions, constants, and struct layouts for Darwin/amd64 system calls. |
| unix/ztypes_darwin_arm64.go | safe | No malicious patterns detected; the file contains only generated Go type definitions and constants for Darwin arm64 system interfaces. |
| unix/ztypes_dragonfly_amd64.go | safe | No malicious patterns detected; this is an auto-generated Go struct definition file for DragonFly BSD system types from the golang.org/x/sys/unix package, containing only type declarations and constants with no executable code, network activity, or filesystem manipulation. |
| unix/ztypes_freebsd_386.go | safe | This is an auto-generated Go type definition file for FreeBSD 386 system structures, containing only constant declarations and struct type definitions with no executable code or malicious patterns. |
| unix/ztypes_freebsd_amd64.go | safe | No malicious patterns detected; this is an auto-generated Go type definition file for FreeBSD syscall structures with no executable code or suspicious behavior. |
| unix/ztypes_freebsd_arm.go | safe | No malicious patterns detected |
| unix/ztypes_freebsd_arm64.go | safe | No malicious patterns detected; the file is a standard Go generated type definition for FreeBSD arm64, containing only constants, structs, and type aliases with no executable code or network/file system operations. |
| unix/ztypes_freebsd_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_linux_386.go | safe | No malicious patterns detected; this is an auto-generated Go type definition file for Linux 386 syscall structures. |
| unix/ztypes_linux_amd64.go | safe | No malicious patterns detected; this is a standard Go generated type definition file for Linux amd64 syscalls. |
| unix/ztypes_linux_arm.go | safe | This is an auto-generated Go type definition file for Linux ARM system structures with no executable code or malicious patterns. |
| unix/ztypes_linux_arm64.go | safe | This file contains only Go type definitions and constants for Linux arm64 syscall structures, with no executable code, network operations, or malicious patterns. |
| unix/ztypes_linux_loong64.go | safe | No malicious patterns detected |
| unix/ztypes_linux_mips.go | safe | This is a generated Go types file containing only architecture-specific struct, constant, and type definitions for Linux/mips with no executable logic or malicious patterns. |
| unix/ztypes_linux_mips64.go | safe | No malicious patterns detected |
| unix/ztypes_linux_mips64le.go | safe | No malicious patterns detected; this is an auto-generated Go type definition file for Linux mips64le syscall structures and constants. |
| unix/ztypes_linux_mipsle.go | safe | No malicious patterns detected in the generated Go type definitions. |
| unix/ztypes_linux_ppc.go | safe | No malicious patterns detected; this is a generated Go type definition file for Linux ppc syscall constants and structures. |
| unix/ztypes_linux_ppc64.go | safe | No malicious patterns detected |
| unix/ztypes_linux_ppc64le.go | safe | This is an auto-generated Go type definitions file for the golang.org/x/sys/unix package containing only constants and struct layouts with no executable code or malicious patterns. |
| unix/ztypes_linux_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_linux_s390x.go | safe | Generated Go type definitions for Linux s390x syscall bindings; contains no executable logic, network activity, or malicious patterns. |
| unix/ztypes_linux_sparc64.go | safe | This is a generated Go type definition file for Linux SPARC64 system structures with no executable code, no I/O operations, and no malicious patterns. |
| unix/ztypes_netbsd_386.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_netbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_netbsd_arm.go | safe | No malicious patterns detected |
| unix/ztypes_netbsd_arm64.go | safe | No malicious patterns detected; this is a generated Go type definition file for NetBSD on ARM64 with only constant and struct declarations. |
| unix/ztypes_openbsd_386.go | safe | No malicious patterns detected; the file contains only generated Go type and constant definitions for OpenBSD system interfaces. |
| unix/ztypes_openbsd_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_openbsd_arm.go | safe | This is an auto-generated Go type definition file for OpenBSD ARM syscall structures with no executable code or malicious patterns. |
| unix/ztypes_openbsd_arm64.go | safe | No malicious patterns detected; this is a standard Go generated type definitions file for OpenBSD arm64 with no executable code, network access, filesystem manipulation, or obfuscation. |
| unix/ztypes_openbsd_mips64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_openbsd_ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_openbsd_riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| unix/ztypes_solaris_amd64.go | safe | No malicious patterns detected |
| unix/ztypes_zos_s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/aliases.go | safe | No malicious patterns detected |
| windows/dll_windows.go | safe | This is a standard Go standard library file for Windows DLL handling; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors, though it correctly documents inherent DLL preloading risks. |
| windows/env_windows.go | safe | No malicious patterns detected; this is legitimate Go standard library Windows environment variable handling code. |
| windows/eventlog.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/exec_windows.go | safe | No malicious patterns detected |
| windows/memory_windows.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/mksyscall.go | safe | This is a standard Go code generation directive file from the official golang.org/x/sys repository with no malicious patterns detected. |
| windows/mkwinsyscall/mkwinsyscall.go | safe | No malicious patterns detected; this is the standard Go mkwinsyscall code generator that parses //sys comments and emits Windows syscall wrappers without any network, credential, or obfuscation behavior. |
| windows/race.go | safe | No malicious patterns detected |
| windows/race0.go | safe | No malicious patterns detected; this is a legitimate Go standard library race detector stub file with empty no-op functions under the windows && !race build constraint. |
| windows/registry/key.go | safe | No malicious patterns detected; this is legitimate Go standard library Windows registry access code. |
| windows/registry/mksyscall.go | safe | No malicious patterns detected in this build-tagged Go generate file that only invokes the standard mkwinsyscall tool for registry syscall generation. |
| windows/registry/syscall.go | safe | This is a standard Go standard-library Windows registry syscall binding file with no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| windows/registry/value.go | safe | This is a standard Go standard library Windows registry access file with no malicious patterns detected |
| windows/registry/zsyscall_windows.go | safe | No malicious patterns detected; file contains standard Go-generated syscall bindings for Windows registry operations from golang.org/x/sys/windows. |
| windows/security_windows.go | safe | No malicious patterns detected; this is a standard Go standard library Windows security API binding. |
| windows/service.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/setupapi_windows.go | safe | No malicious patterns detected; code is a legitimate Go wrapper for Windows SetupAPI/CfgMgr32 functions with no exfiltration, credential harvesting, obfuscation, or other security concerns. |
| windows/str.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/svc/debug/log.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/svc/debug/service.go | safe | This is a standard Go standard library debug helper for running Windows services on console; no malicious patterns detected. |
| windows/svc/eventlog/install.go | safe | This is a legitimate Go standard library file for Windows event log registry management with no malicious patterns. |
| windows/svc/eventlog/log.go | safe | No malicious patterns detected |
| windows/svc/example/beep.go | safe | No malicious patterns detected; the code only calls the Windows MessageBeep API via syscall, which is benign. |
| windows/svc/example/install.go | safe | No malicious patterns detected |
| windows/svc/example/main.go | safe | No malicious patterns detected; this is a legitimate Go example for Windows service management from the golang.org/x/sys package. |
| windows/svc/example/manage.go | safe | No malicious patterns detected; the code is a standard Go example for managing Windows services using the official golang.org/x/sys package. |
| windows/svc/example/service.go | safe | This is a standard, benign example service from the official golang.org/x/sys module with no malicious patterns detected. |
| windows/svc/mgr/config.go | safe | No malicious patterns detected |
| windows/svc/mgr/mgr.go | safe | This is the standard Go x/sys/windows/svc/mgr package which manages Windows services; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell spawning were detected. |
| windows/svc/mgr/service.go | safe | This is legitimate Go standard library code for Windows service management, with no malicious patterns detected. |
| windows/svc/security.go | safe | No malicious patterns detected; the code is legitimate Windows service detection logic from the Go standard library's x/sys/windows package. |
| windows/svc/service.go | safe | This is a legitimate, standard library Windows service wrapper from golang.org/x/sys with no malicious patterns detected. |
| windows/syscall.go | safe | No malicious patterns detected; the code is a standard part of the Go x/sys/windows package providing safe syscall helpers. |
| windows/syscall_windows.go | safe | This is the standard Go x/sys/windows syscall binding file with no malicious patterns detected. |
| windows/types_windows_386.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/types_windows_amd64.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/types_windows_arm.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/types_windows_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| windows/zknownfolderids_windows.go | safe | No malicious patterns detected; the file only defines static KNOWNFOLDERID GUID constants generated by a build script. |
Frequently asked questions
Is golang.org/x/sys safe to use?
golang.org/x/sys@v0.48.0 has 2 high, 12 medium, 24 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does golang.org/x/sys contain malware?
The latest scan of golang.org/x/sys (v0.48.0) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was golang.org/x/sys checked?
Togoder Security downloaded the published Go package and had an AI model read its 416 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan golang.org/x/sys together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/sys@v0.48.0, cost nothing.