[sergo] Sergo Report: REGISTRY-43to67-resync+cached-not-enforced-audit(cgo.yml-diff)+newexplore-closed-issue-reconciliation - 2026-08-31 #57341
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Sergo - Serena Go Expert. A newer discussion is available at Discussion #57607. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive summary
Registry check: 67/67 analyzers registered and documented (
pkg/linters/registry.govspkg/linters/doc.goheader) — no doc-sync drift. Since the last logged run (R60, 2026-07-08) the registry grew from 43 → 67 analyzers across untracked intervening runs; this run re-synced the baseline rather than treating the jump as a single new delta.Filed 2 new issues, both concrete, evidence-backed gaps in currently un-enforced linters (not yet wired into
cgo.ymlLINTER_FLAGS), found by reconciling closed-issue titles against the actual code instead of trusting closure status.Tool inventory
No Serena tool-surface change (still 23 tools, same params/gotchas as prior runs).
Strategy: 50/50 split
cgo.yml's nativeLINTER_FLAGSlist to rebuild the not-yet-enforced set (12 names), then reconciled every closed sergo issue title touching those linters against current source — the proven "closed ≠ landed" reconciliation pattern from prior runs.sprintferrdot,stringsconcatloop,excessivefuncparams,largefunc, andhardcodedfilepath— five not-enforced linters with no or thin recent audit coverage — cross-checked against their test fixtures for uncovered edge cases.Findings
7 evidence items collected (2 filed as issues, 5 reconciled as already-fixed or too-minor)
sprintferrdot— verb-set bug unfixed despite closed sprintferrdot precision: verb handling {s,v} is wrong in both directions — %#v false positive, %q/%x/%X false negative #40434.parseSimpleFormatVerbs(sprintferrdot.go:142) discards the#flag without recording it, so%#vis indistinguishable from%v→ false positive (flags.Error()under%#vas redundant when it isn't:%#vinvokesGoStringer, notError()). Separately, the accepted-verb check (sprintferrdot.go:75) excludesq/x/X, which thefmtpackage's error-interface special case also covers → false negative. No test fixture exists for any of these forms. Filed.stringsconcatloop— self-referential=form misses map/selector accumulators.selfReferentialConcatLHS(stringsconcatloop.go:117-134), added to close stringsconcatloop: ADD_ASSIGN-only matcher lets contributors bypass the lint rule withx = x + y— already happening in open P [Content truncated due to length] #49046'sx = x + ygap, requires a bare*ast.Identon both sides.m[k] = m[k] + vandobj.Field = obj.Field + vsilently pass, even though the sibling+=path already handles arbitrary expression shapes. No prod instances found (grep sweptpkg/**/*.go), so latent. Filed.writebytestring's sg60a1 bug (isStringType matching named types for an exact-string API) is confirmed fixed —buildStringExprnow wrapsstring(...)via a correctisExactString(Basic-kind check).stringbytesroundtrip'sisExactString(closed stringbytesroundtrip: isExactString is a no-op alias of isStringType — latent risk of the sg60a1 (writebytestring) bug class #54718, alleged "no-op alias") is confirmed fixed — nowisStringType(types.Unalias(t)), correctly distinguishing named types from the predeclaredstring.excessivefuncparams's old test-file gap (Threshold linters: excessivefuncparams lints test files (every sibling FuncDecl linter skips them); largefunc & excessivefuncpar [Content truncated due to length] #40734) is confirmed fixed —filecheck.ShouldSkipFilenamenow wrapsIsTestFile.largefuncre-audited for thedouble_traversal_dupbug class (nodeFilter over bothFuncDecl+FuncLit) — clean: each node gets its own span via the inspector's single pass, no manual recursion.hardcodedfilepath'senclosingCallIsLogPrintonly checks the nearest enclosing call, missing cases where a path literal is nested inside a non-log call (e.g.fmt.Sprintf) that is itself passed to a log call — real but purely cosmetic (only suppresses an informational message suffix, not the diagnostic itself), so not filed as an issue this run.Generated tasks (2)
Issues filed
Both labeled
sergo, both self-contained with file:line evidence, repro snippets, recommendation, and validation checklist. No duplicates skipped this run — reconciliation confirmed the two open pre-existing sergo issues (#56533 errorfwrapv, #55932 contextcancelnotdeferred/wasm) are unrelated to this run's targets.Metrics
pkg/wasn't possible in this sandbox, see below)Historical context
Known limitation this run
Could not execute
go run ./cmd/linters ... ./pkg/...to get live production-violation counts for the audited linters — the sandbox requires interactive approval for that command shape and none was available in this unattended run. Findings above are based on static code reading plus targetedgrepsweeps, not a live lint pass. Recommend a follow-up run (or CI artifact review) to get exact violation counts forsprintferrdot/stringsconcatloopbefore wiring either intoLINTER_FLAGS.Next-run focus (R62)
manualpathconcat,packagelevelmutableslicemap,seenmapbool— heavily audited historically but may have residual narrow-pattern gaps in the same family as sg61a2.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
All reactions