gotoolchain

package
v0.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Overview

Package gotoolchain resolves the Go toolchain once, to an absolute path.

Two packages ask it, and they have to agree. internal/gobuildrunner compiles a mutant's tests with it; internal/commandscope asks it which packages those tests compile. A scope resolved by one toolchain and a build made by another would compare answers from two different compilers, and the disagreement would look like a property of the module under test.

Resolving is not tidiness. `exec.Command("go", …)` reads PATH at every call, so a directory an attacker can write to — or prepend — decides which compiler runs: SonarQube's go:S4036, CWE-426. GOROOT is the toolchain that built this binary, so it is preferred; PATH is the fallback for a GOROOT that is not on disk.

It answers empty rather than failing. A caller that cannot build already knows what to do with that — `gobuildrunner` reports that the binary was never built, and a scope that cannot be resolved refuses nothing — and a panic here would turn a missing toolchain into a defect that looks like ditto's.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Path

func Path() string

Path is the absolute path of the `go` binary to run, or empty when none could be found.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL