nginx-c-module-perf

Warn

Audited by Socket on Sep 16, 2026

4 alerts found:

Anomalyx3Security
AnomalyLOW
references/conn-prealloc-pool.md

The fragment presents a legitimate performance optimization, but replacing and destroying an existing nginx connection pool is unsafe unless the caller can guarantee that no prior objects or module state use that pool. This could cause use-after-free or corruption in a real nginx integration. The code shows no evidence of malware, exfiltration, backdoors, or obfuscation. The example should instead configure the pool at connection creation or use a separate module-owned pool, and should account for alignment, ownership, and cleanup semantics.

Confidence: 94%Severity: 62%
AnomalyLOW
references/cache-stampede-lock.md

The fragment is a readable cache single-flight example and shows no evidence of intentional malicious behavior or supply-chain malware. It contains significant correctness and concurrency hazards: shallow storage of ngx_str_t data, possible uninitialized stale responses, lack of fetch-lock recovery, and possible use-after-free if entries can be evicted during the unlocked upstream fetch. The implementation requires explicit shared-memory value copying, entry lifetime protection, initialization, and timeout/recovery handling before production use.

Confidence: 94%Severity: 61%
SecurityMEDIUM
references/lock-rw-pattern.md

The code appears to be a legitimate performance optimization rather than malware. However, the claimed lock-free double-buffering is unsafe without a reader grace-period or equivalent reclamation mechanism, and the unchecked rule count may permit a buffer overflow. It should not be treated as production-safe RCU without validating capacities and adding proper synchronization and memory-ordering guarantees.

Confidence: 97%Severity: 72%
AnomalyLOW
references/log-connection-context.md

The code is intended for request tracing and does not show malicious behavior. However, it incorrectly stores request-scoped state in a connection-wide log object without restoring the original handler/data. This can cause dangling-pointer use-after-free, cross-request context leakage or misattribution, and possibly log injection depending on request ID validation. The implementation should use appropriately scoped logging context, synchronize or isolate per-request state, restore prior log fields, and sanitize log values.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fnginx-c-module-perf%2F@60221fb66370d6631ffc85ad093d131bfe26f60474cddd535af0e351226eb181
Security Audit — socket — nginx-c-module-perf