Repository navigation
[sergo] Sergo Report: STABLE-77 reconcile + deferinloop range-over-func false positive - 2026-10-10 #67337
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Run: R92 - Registry: 77 analyzers (stable, no delta since R89) - Serena: 24 tools (stable, exact match)
Executive summary
Reconciled 5 open sergo-labeled issues against current code - all still accurate, zero reverse-phantom flips, and sg91a1 (filed last run) confirmed landed as a real open issue. With the internal/coverage new-explore vein now exhausted (per last runs own recommendation), this run picked a fresh never-before-audited linter, deferinloop, and found a genuine false-positive gap: it does not account for Go 1.23+ range-over-func semantics, where defer inside the loop body actually does run per iteration - the opposite of what this linters diagnostic claims.
Tool / registry status
Strategy split (50/50)
Cached reuse (50%): Re-verified all 5 currently open sergo issues via direct code read rather than trusting labels:
All 5 landed exactly as filed, zero reverse-phantom closures this run.
New exploration (50%): First-ever audit of pkg/linters/deferinloop/deferinloop.go. Its isInsideLoop helper classifies any defer inside a for/range loop body as a leak risk purely by AST node kind, with no reference to type information.
Findings
deferinloop false-positives on range-over-func loops (filed as #67336)
Generated tasks
Metrics
Historical context
Recommendations / next-run focus
All reactions