{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D40","name":"Network Egress Confinement","shortDescription":{"text":"Network Egress Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D40"},{"id":"D41","name":"Kernel \u0026 Syscall Confinement","shortDescription":{"text":"Kernel \u0026 Syscall Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D41"},{"id":"D42","name":"Runtime Threat Enforcement","shortDescription":{"text":"Runtime Threat Enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/D42"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"controlclient.peerChangeDiff (cyclomatic 93): controlclient.peerChangeDiff has cyclomatic complexity 93 (threshold 15). Of this number, 92 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":990}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a9c3941ceff7870e161b296c1c5dbab5e3ceb470418da4cd911b7f663ebfb95"}},{"ruleId":"D1","level":"warning","message":{"text":"main.run (cyclomatic 76): main.run has cyclomatic complexity 76 (threshold 15). Of this number, 64 points are the body\u0027s own statements and 12 belong to 5 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/k8s-proxy.go"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b7e827719f529bb7990e0faf4ddb31c460043692324c9ff00b0e5246e074acb"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runUp (cyclomatic 70): cli.runUp has cyclomatic complexity 70 (threshold 15). Of this number, 38 points are the body\u0027s own statements and 32 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":500}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d64d0e62be68f00daeb7561cafc96944f2b8a7f6e3c7fc565dd08bfa2d99e3a"}},{"ruleId":"D1","level":"warning","message":{"text":"settings.validate (cyclomatic 66): settings.validate has cyclomatic complexity 66 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/settings.go"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"7aa3c4649e0584bb9edf00279812013f48f471b7762c5904c08e56729a0bab51"}},{"ruleId":"D1","level":"warning","message":{"text":"main.genView (cyclomatic 63): main.genView has cyclomatic complexity 63 (threshold 15). Of this number, 60 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/viewer/viewer.go"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e2de09cb5652c59ab1973b02affca7554794f8c5b8f5816a0c84f82d4b27a6c"}},{"ruleId":"D1","level":"warning","message":{"text":"osrouter.configureInterface (cyclomatic 60): osrouter.configureInterface has cyclomatic complexity 60 (threshold 15). Of this number, 53 points are the body\u0027s own statements and 7 belong to 2 function literals inside it that branch. This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"706960d6a2e8b34a0c03ade4c0fd5a7acf8eb1e524aab204c7a97894ce4de346"}},{"ruleId":"D1","level":"warning","message":{"text":"Direct.sendMapRequest (cyclomatic 59): Direct.sendMapRequest has cyclomatic complexity 59 (threshold 15). Of this number, 55 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":1062}}}],"partialFingerprints":{"codehealthFindingId/v1":"73eeea0c31864e2eaaa434903cc553292b4d027fda6537aa9ca2e040c76c23d8"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.setControlClientStatusLocked (cyclomatic 57): LocalBackend.setControlClientStatusLocked has cyclomatic complexity 57 (threshold 15). Of this number, 56 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1824}}}],"partialFingerprints":{"codehealthFindingId/v1":"30b65b9761fd0bd76beeb920756587792ad2ac44e8637c42d54037cb72df8f35"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.GetReport (cyclomatic 57): Client.GetReport has cyclomatic complexity 57 (threshold 15). Of this number, 49 points are the body\u0027s own statements and 8 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":828}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0368e8018a7fc27b72df49cdf1db1fe29de6d7e5acea60e9016f454e1019e61"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 54): main.main has cyclomatic complexity 54 (threshold 15). Most of this is not in the body itself: 10 of the 54 points are its own statements and the rest belongs to 15 function literals inside it that branch (lines 292, 358, 326, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tta/tta.go"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d10719e24071c2dcf5c90e477d20d6223a7379db488d022920a6deb7a4f0b49"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.handleDiscoMessage (cyclomatic 54): Conn.handleDiscoMessage has cyclomatic complexity 54 (threshold 15). Of this number, 53 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":2193}}}],"partialFingerprints":{"codehealthFindingId/v1":"62c6d15d1ed8e298bd813b51ae0521fe1897acece68e665db8d72d11a00f2ace"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.runServeCombined (cyclomatic 53): serveEnv.runServeCombined has cyclomatic complexity 53 (threshold 15). Most of this is not in the body itself: 1 of the 53 points is its own statement and the rest belongs to one function literal inside it that branches (line 376). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":373}}}],"partialFingerprints":{"codehealthFindingId/v1":"5576764c19e060a9802179e163980592a65f3e8ed4077ad6fb6d28a34349b70a"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runStatus (cyclomatic 52): cli.runStatus has cyclomatic complexity 52 (threshold 15). Of this number, 33 points are the body\u0027s own statements and 19 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/status.go"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"160c9939ebf61f1d27e4679a45e7598deeb9c7a25f8df36ee1fec1c4c8093aa4"}},{"ruleId":"D1","level":"warning","message":{"text":"Direct.doLogin (cyclomatic 52): Direct.doLogin has cyclomatic complexity 52 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":663}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfba1339754e66cf8420cfd9b99aa041178ef762d06054e88bbbb7e9e3a050b8"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.startLocked (cyclomatic 51): LocalBackend.startLocked has cyclomatic complexity 51 (threshold 15). Of this number, 49 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3031}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ae162740f920dedd912b1c631c46ef2790822d0d5160f768bf4fd811d269f76"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.createOrGetMapping (cyclomatic 48): Client.createOrGetMapping has cyclomatic complexity 48 (threshold 15). Of this number, 43 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/portmapper.go"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffd15cff894d4e3fd438423162c7247a51c79bbdf9a46778e0f734da80dac289"}},{"ruleId":"D1","level":"warning","message":{"text":"wgengine.NewUserspaceEngine (cyclomatic 48): wgengine.NewUserspaceEngine has cyclomatic complexity 48 (threshold 15). Of this number, 33 points are the body\u0027s own statements and 15 belong to 8 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":303}}}],"partialFingerprints":{"codehealthFindingId/v1":"46eb2e2aef1a3f2c93daae15c1cd2ab08f353a9ec962ec1229b4444e0210bebe"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.setNetMapLocked (cyclomatic 45): LocalBackend.setNetMapLocked has cyclomatic complexity 45 (threshold 15). Of this number, 44 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":7271}}}],"partialFingerprints":{"codehealthFindingId/v1":"a94609b42142f07fb684a1a58da3521a41f8b420f873c783c1a1b8883eafc18b"}},{"ruleId":"D1","level":"warning","message":{"text":"forwarder.forwardWithDestChan (cyclomatic 45): forwarder.forwardWithDestChan has cyclomatic complexity 45 (threshold 15). Of this number, 37 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":1163}}}],"partialFingerprints":{"codehealthFindingId/v1":"d337dbb49994b86c7a92d3b6c171942d904413848ffc1b1644d2fc4c8b50444d"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveMap (cyclomatic 45): Server.serveMap has cyclomatic complexity 45 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1390}}}],"partialFingerprints":{"codehealthFindingId/v1":"496cd637d11a48b1f5a7711e0bd869e6a09f0064d01379257d36251bddbf9ac5"}},{"ruleId":"D1","level":"warning","message":{"text":"internal.Complete (cyclomatic 44): internal.Complete has cyclomatic complexity 44 (threshold 15). Of this number, 34 points are the body\u0027s own statements and 10 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ffcomplete/internal/complete.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b714dc3c68b07da1d1e5a47f9a861a9c86376860aa061b4cc697f9249113d8b"}},{"ruleId":"D1","level":"warning","message":{"text":"main.runTests (cyclomatic 44): main.runTests has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"89cef79c1d27568ede16e94e144257419420f293581c6d12bc6b9de85a7f9e17"}},{"ruleId":"D1","level":"warning","message":{"text":"mapSession.updateStateFromResponse (cyclomatic 44): mapSession.updateStateFromResponse has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":600}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b73744743406c4d59a57983bf1c8283c472dd4e19f563da5a112307dbe86167"}},{"ruleId":"D1","level":"warning","message":{"text":"StatusBuilder.AddPeer (cyclomatic 44): StatusBuilder.AddPeer has cyclomatic complexity 44 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnstate/ipnstate.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0202760e0733029be839edbb523e3659b6daf6d2127fa9f596d8a76e4c1e9e9"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.serveDebugDERPRegion (cyclomatic 44): Handler.serveDebugDERPRegion has cyclomatic complexity 44 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 26 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debugderp.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf5af5a58fe9a3b0697d03dfc23cc8e6ad72f77199d356355661f3ef632442e2"}},{"ruleId":"D1","level":"warning","message":{"text":"safediff.Lines (cyclomatic 44): safediff.Lines has cyclomatic complexity 44 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 13 belong to 3 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/safediff/diff.go"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"26f21f2fd88ff5d36dc217aad18dc56b23e4f5069de2a50772531a201f480df0"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxRouter.setNetfilterModeLocked (cyclomatic 44): linuxRouter.setNetfilterModeLocked has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":745}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d8211f0e326afe6ec262863d6b16d2b4e705e80ac8117f329744af145ec44c8"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runCp (cyclomatic 43): cli.runCp has cyclomatic complexity 43 (threshold 15). Of this number, 36 points are the body\u0027s own statements and 7 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"acfd679915ac9d55efd30b8f41e1e6184b197b8c4dfe30ac5e33a0f17ef0870b"}},{"ruleId":"D1","level":"warning","message":{"text":"main.printMessage (cyclomatic 42): main.printMessage has cyclomatic complexity 42 (threshold 15). Of this number, 26 points are the body\u0027s own statements and 16 belong to 3 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/netlogfmt/main.go"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"49276faf23f7d542fae2a2622a997fa598f07f10ab727dd9fda5f86caf77a00d"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 42): main.main has cyclomatic complexity 42 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"55d5ba506a1066be98eda66a528791b8db1d20ff5c2d5700846f15faaf6c904f"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.connect (cyclomatic 42): Client.connect has cyclomatic complexity 42 (threshold 15). Of this number, 33 points are the body\u0027s own statements and 9 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e89b463505a0096b31b3e0d49bd34c1ffb6db89be7dca7b81460defb78f474f"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 41): main.main has cyclomatic complexity 41 (threshold 15). Of this number, 28 points are the body\u0027s own statements and 13 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/derper.go"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e3da1970c98cb473f0d0fd0845cd85a7366e22ada45fce0edd0b3b28327715d"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.Probe (cyclomatic 41): Client.Probe has cyclomatic complexity 41 (threshold 15). Of this number, 33 points are the body\u0027s own statements and 8 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/portmapper.go"},"region":{"startLine":875}}}],"partialFingerprints":{"codehealthFindingId/v1":"458d720c34ad275b3c07e2dc332dc0f5f69a234c2ffb6b107afc13e8efc0b041"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 40): main.main has cyclomatic complexity 40 (threshold 15). Of this number, 33 points are the body\u0027s own statements and 7 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":922}}}],"partialFingerprints":{"codehealthFindingId/v1":"1333f0d8d469ffc9f2da9649c3be5e61c3c4b95bc0b7f1172e029f2169181a54"}},{"ruleId":"D1","level":"warning","message":{"text":"main.applyProxyClassToStatefulSet (cyclomatic 39): main.applyProxyClassToStatefulSet has cyclomatic complexity 39 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":862}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d0c15bbef5bab469e0e51368fdca46fc67ef8e08c4f4aff6a919fca60f7fbb6"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.UpdateNetmapDelta (cyclomatic 39): LocalBackend.UpdateNetmapDelta has cyclomatic complexity 39 (threshold 15). Of this number, 38 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":2415}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7d51c27532099a1e8fa24532c3ff031018d962c0f4895294926406adc5c772d"}},{"ruleId":"D1","level":"warning","message":{"text":"Prefs.pretty (cyclomatic 39): Prefs.pretty has cyclomatic complexity 39 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":546}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2e57657b7cf5483f9c574000b96ecf926ad1f13ccf093e9e2ed58d1dff0b561"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn25.mapDNSResponse (cyclomatic 38): Conn25.mapDNSResponse has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1148}}}],"partialFingerprints":{"codehealthFindingId/v1":"7599b16ec6e66d90caff5ac2efdd8c979b8991a4ec5bb39e6d7e8e21561f119b"}},{"ruleId":"D1","level":"warning","message":{"text":"Wrapper.filterPacketInboundFromWireGuard (cyclomatic 38): Wrapper.filterPacketInboundFromWireGuard has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":1097}}}],"partialFingerprints":{"codehealthFindingId/v1":"1feb0b4262ca4fd616742fa101f0ca546eb216bc3292f869aabe506b38ffbd11"}},{"ruleId":"D1","level":"warning","message":{"text":"s4u.startProcessInternal (cyclomatic 38): s4u.startProcessInternal has cyclomatic complexity 38 (threshold 15). Of this number, 36 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/s4u/s4u_windows.go"},"region":{"startLine":364}}}],"partialFingerprints":{"codehealthFindingId/v1":"6683c97c107c7d7bf31c2b91d7ec960d4de24e458f8b76759ba6c7cfd51ac6b8"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.formatDNSStatusText (cyclomatic 37): cli.formatDNSStatusText has cyclomatic complexity 37 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-status.go"},"region":{"startLine":190}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e59b116c260da6518132dceeb5285896ff744d7834fcb2a5729ca6baedf11b5"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runSet (cyclomatic 37): cli.runSet has cyclomatic complexity 37 (threshold 15). Of this number, 35 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/set.go"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a4262d0dacf616a186eb2666682877b097f279ea4123a2bab816938c83e6399"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.runServeSetConfig (cyclomatic 37): serveEnv.runServeSetConfig has cyclomatic complexity 37 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":854}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fc4441a7a8b54bace3b400787d098a3f7fdb5483a71292d025de7c7a7454431"}},{"ruleId":"D1","level":"warning","message":{"text":"ProxyGroupReconciler.ensureConfigSecretsCreated (cyclomatic 36): ProxyGroupReconciler.ensureConfigSecretsCreated has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":761}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b4ac74d38059da98c134ba779426688da4ee4c28fa59a0ba399bd53f8d82717"}},{"ruleId":"D1","level":"warning","message":{"text":"HAServiceReconciler.maybeProvision (cyclomatic 36): HAServiceReconciler.maybeProvision has cyclomatic complexity 36 (threshold 15). Of this number, 35 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a206ead8bfb13e09bdd3931ba182354bbc6728e5373e440b26007df164030e7"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 36): main.main has cyclomatic complexity 36 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":738}}}],"partialFingerprints":{"codehealthFindingId/v1":"66811416550205436a344ee18ba7752fa8104ed0968e18421c4fbb0d0fd5722a"}},{"ruleId":"D1","level":"warning","message":{"text":"Options.init (cyclomatic 36): Options.init has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab3ca7d8a43636ea785dd3224127e311e6dfcfe3edbfca5bf775f34d2719d49c"}},{"ruleId":"D1","level":"warning","message":{"text":"nlConn.Receive (cyclomatic 36): nlConn.Receive has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon_linux.go"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"2211a12ba7108b2446804e161b74602ee9441123628d0a33599b8789d34aa7bf"}},{"ruleId":"D1","level":"warning","message":{"text":"prober.derpProbeBandwidthTUN (cyclomatic 36): prober.derpProbeBandwidthTUN has cyclomatic complexity 36 (threshold 15). Most of this is not in the body itself: 15 of the 36 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 958, 1011, 1083, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":898}}}],"partialFingerprints":{"codehealthFindingId/v1":"21353335ba767d0c9aacada62e82edf557c28724a1e88cb88ced9330532cb6a0"}},{"ruleId":"D1","level":"warning","message":{"text":"main.runMTSServer (cyclomatic 36): main.runMTSServer has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/mts/mts.go"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"971fb3d71c528e19f20b1a89df6f1550233d51b2d5177474f0542c2c78e1b748"}},{"ruleId":"D1","level":"warning","message":{"text":"Tracker.updateBuiltinWarnablesLocked (cyclomatic 35): Tracker.updateBuiltinWarnablesLocked has cyclomatic complexity 35 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"health/health.go"},"region":{"startLine":1104}}}],"partialFingerprints":{"codehealthFindingId/v1":"94570e657b22c0b474f896bef41ca9c5d5a782ea1c98246a9df0011419686427"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.notifyForSessionLocked (cyclomatic 35): LocalBackend.notifyForSessionLocked has cyclomatic complexity 35 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":4134}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ed4f16e739993b1487a41f0acf7e40feeb048a89f418e5dae99af444ef764bd"}},{"ruleId":"D1","level":"warning","message":{"text":"AUM.StaticValidate (cyclomatic 35): AUM.StaticValidate has cyclomatic complexity 35 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/aum.go"},"region":{"startLine":159}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2756af937c73d96914f49b09a55f03bfcfb49209036052d2c5aa662ef7a335f"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.start (cyclomatic 35): Server.start has cyclomatic complexity 35 (threshold 15). Of this number, 29 points are the body\u0027s own statements and 6 belong to 4 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":767}}}],"partialFingerprints":{"codehealthFindingId/v1":"c48cbf4010e70b8520bda7889ccabbe5081aa7246a5611c5d9713e87ab46668c"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveRegister (cyclomatic 35): Server.serveRegister has cyclomatic complexity 35 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":953}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e3c99a60d5f384fa315c190393b0a3fa7dfbce2086f4d9ff25ee93389f8ef64"}},{"ruleId":"D1","level":"warning","message":{"text":"Env.Start (cyclomatic 35): Env.Start has cyclomatic complexity 35 (threshold 15). Of this number, 20 points are the body\u0027s own statements and 15 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":633}}}],"partialFingerprints":{"codehealthFindingId/v1":"2abbe28e322707631c054c7ec208586843e6b87527d54177e08c5803ffac65fd"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxRouter.Set (cyclomatic 35): linuxRouter.Set has cyclomatic complexity 35 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":436}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc7cd9076d005c0f1b286d0712c4494e7835a46e67c8d9d041fad193d722c3f4"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.dnsConfigForNetmap (cyclomatic 34): ipnlocal.dnsConfigForNetmap has cyclomatic complexity 34 (threshold 15). Of this number, 29 points are the body\u0027s own statements and 5 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1444}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f19fa607bef003b9f8191645c57e66a568998159c9d8abb43ecf299bb6c9bcf"}},{"ruleId":"D1","level":"warning","message":{"text":"Reconciler.validate (cyclomatic 34): Reconciler.validate has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/proxyclass/proxyclass.go"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6fb2e4c6729c9ee7c090ea725c662499abbc04c68c27da68a32008de5176d98"}},{"ruleId":"D1","level":"warning","message":{"text":"tlsdial.Config (cyclomatic 34): tlsdial.Config has cyclomatic complexity 34 (threshold 15). Most of this is not in the body itself: 8 of the 34 points are its own statements and the rest belongs to one function literal inside it that branches (line 115). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tlsdial/tlsdial.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ea7d49eaf1e7da66687afcc877a4f592678d566d1521788d1cbec0884009118"}},{"ruleId":"D1","level":"warning","message":{"text":"varz.writePromExpVar (cyclomatic 34): varz.writePromExpVar has cyclomatic complexity 34 (threshold 15). Of this number, 27 points are the body\u0027s own statements and 7 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/varz/varz.go"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"212749cd2d61d0449261132e4f6dd9e7bd163b4ab1074eb8bad8e15c1840c3bb"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.prefValue (cyclomatic 33): cli.prefValue has cyclomatic complexity 33 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/get.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"898a8804163fe408887804a5cd5450f4c37ec0781e872c5171cc0aeba95fd298"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.runServeGetConfig (cyclomatic 33): serveEnv.runServeGetConfig has cyclomatic complexity 33 (threshold 15). Most of this is not in the body itself: 14 of the 33 points are its own statements and the rest belongs to one function literal inside it that branches (line 680). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":661}}}],"partialFingerprints":{"codehealthFindingId/v1":"bafe29ad8cd8f4d27e88962dcaea4d2303cf6261224c31533b320c77b6405be7"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 33): main.main has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"b19298fc19db0a921404017e81d5f02a36a0e6b7d9e994fd7d0cfb8a8a480ba0"}},{"ruleId":"D1","level":"warning","message":{"text":"ConfigVAlpha.ToPrefs (cyclomatic 33): ConfigVAlpha.ToPrefs has cyclomatic complexity 33 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/conf.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"aec901be21b35dfb0c24a38210e8fb66812bcf11bdf5e2a3a27c0774489d2ee7"}},{"ruleId":"D1","level":"warning","message":{"text":"Mutation.Commit (cyclomatic 33): Mutation.Commit has cyclomatic complexity 33 (threshold 15). Of this number, 30 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":511}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2b4a28e7e2806f12c7da6b3f7345f64a20f619341a74881c0447319ceee248b"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 33): main.main has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/listpkgs/listpkgs.go"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"098fed25dffe77ac6a6d9dc5913628cbf3c3805ba2127272dcd7bbee90f45481"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.shouldProcessInbound (cyclomatic 33): Impl.shouldProcessInbound has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1209}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbfc19de5dd8db6ca2ea2a6f685fd32211caf0e2f8de502f4360cbc2443c75c2"}},{"ruleId":"D1","level":"warning","message":{"text":"Menu.rebuildExitNodeMenu (cyclomatic 32): Menu.rebuildExitNodeMenu has cyclomatic complexity 32 (threshold 15). Of this number, 30 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":604}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4cf4f9a4ab6e6c50d8326bbe8c0b9ea9d5dc5d1e3a9dfafcc4109039b613126"}},{"ruleId":"D1","level":"warning","message":{"text":"main.runReconcilers (cyclomatic 32): main.runReconcilers has cyclomatic complexity 32 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"5aa92ff1be214572b23bb7804f63c096f8b41084cf74bac703c797b362dd21ab"}},{"ruleId":"D1","level":"warning","message":{"text":"connector.handleDNS (cyclomatic 32): connector.handleDNS has cyclomatic complexity 32 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/natc/natc.go"},"region":{"startLine":351}}}],"partialFingerprints":{"codehealthFindingId/v1":"65a4bdd2c73049d66677e9d506727fe8599b25984817a029197f8ec96a1feb7a"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.suggestExitNodeUsingDERP (cyclomatic 32): ipnlocal.suggestExitNodeUsingDERP has cyclomatic complexity 32 (threshold 15). Of this number, 27 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":8821}}}],"partialFingerprints":{"codehealthFindingId/v1":"e02c662743c5a1ae5ad225355cc0a4f10c6ab2d920348ee97f13e73b683b79b8"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.WatchNotificationsAs (cyclomatic 32): LocalBackend.WatchNotificationsAs has cyclomatic complexity 32 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3723}}}],"partialFingerprints":{"codehealthFindingId/v1":"56ecc0c923bfc10a41dd75e8b0d3afbd20a75dd6d517be2c5883bc6e38d38b37"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.serveDebug (cyclomatic 32): Handler.serveDebug has cyclomatic complexity 32 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"f608aff0659ea03d53c39effc5792e5a205dad88e93e0811b73a0f77a5e3a40c"}},{"ruleId":"D1","level":"warning","message":{"text":"network.acceptTCP (cyclomatic 32): network.acceptTCP has cyclomatic complexity 32 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":391}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8cc0e203eee17d6dae2d567b432f61c019df0722c284b000f5a51c158d9ea66"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.determineEndpoints (cyclomatic 32): Conn.determineEndpoints has cyclomatic complexity 32 (threshold 15). Of this number, 28 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1284}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b390bba72512373a56ae0cc8b6a6ec3a5b4bc7631ce6688ebc36152a9d2c3d5"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runCert (cyclomatic 31): cli.runCert has cyclomatic complexity 31 (threshold 15). Of this number, 25 points are the body\u0027s own statements and 6 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cert.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"57105b24752fc663bc9d2be2e5c6b37a5b02c91475d55c9de959f6f516dcb530"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.isLegacyInvocation (cyclomatic 31): cli.isLegacyInvocation has cyclomatic complexity 31 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d6a7dab9c859783ae74e61468803debfcb2075e342dad2f366f6a221bdcf968"}},{"ruleId":"D1","level":"warning","message":{"text":"ServiceReconciler.maybeProvision (cyclomatic 30): ServiceReconciler.maybeProvision has cyclomatic complexity 30 (threshold 15). Of this number, 29 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc.go"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec3fa7e679655dc76ca660034d77d9789a7b4cd80d9b41d9c90105e48e4e3c63"}},{"ruleId":"D1","level":"warning","message":{"text":"jsontags.run (cyclomatic 30): jsontags.run has cyclomatic complexity 30 (threshold 15). Most of this is not in the body itself: 1 of the 30 points is its own statement and the rest belongs to one function literal inside it that branches (line 30). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vet/jsontags/analyzer.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"62fed56699154196da133be3fa700dc1cc1e2ba14ff7402536f8a9c1ca5e8078"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.recvTimeout (cyclomatic 30): Client.recvTimeout has cyclomatic complexity 30 (threshold 15). Of this number, 29 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derp_client.go"},"region":{"startLine":499}}}],"partialFingerprints":{"codehealthFindingId/v1":"f526a752edb94c34aefe0dc5279e01fe0429fcf75a9e80f3dd229194a77bb77f"}},{"ruleId":"D1","level":"warning","message":{"text":"logpolicy.tryFixLogStateLocation (cyclomatic 30): logpolicy.tryFixLogStateLocation has cyclomatic complexity 30 (threshold 15). Of this number, 23 points are the body\u0027s own statements and 7 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"f27a2faf0ee2dc198ac00e7072cba73e7e42d7ba51703423d23939120546a680"}},{"ruleId":"D1","level":"warning","message":{"text":"resolver.handleExitNodeDNSQueryWithNetPkg (cyclomatic 30): resolver.handleExitNodeDNSQueryWithNetPkg has cyclomatic complexity 30 (threshold 15). Of this number, 27 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3b14b8bf3f17738749a4adf20e99507a919c59c08315c20b022136f3c8e62c5"}},{"ruleId":"D1","level":"warning","message":{"text":"netcheck.makeProbePlan (cyclomatic 30): netcheck.makeProbePlan has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"a318576cf101da39ba218845b8b8be7e851fd13b48349c73274fd457f892c775"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.acceptTCP (cyclomatic 30): Impl.acceptTCP has cyclomatic complexity 30 (threshold 15). Of this number, 22 points are the body\u0027s own statements and 8 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1512}}}],"partialFingerprints":{"codehealthFindingId/v1":"38dd34587a2a0d1548eb28a6e887eeb99858114a78194627e199f79a21ced3c9"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.checkForAccidentalSettingReverts (cyclomatic 29): cli.checkForAccidentalSettingReverts has cyclomatic complexity 29 (threshold 15). Of this number, 26 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":1010}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7280dfe7dc5979269f508935afa4830fe4c737f17996da8ce49000de545a789"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.prefsToFlags (cyclomatic 29): cli.prefsToFlags has cyclomatic complexity 29 (threshold 15). Most of this is not in the body itself: 1 of the 29 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 1147, 1136). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":1133}}}],"partialFingerprints":{"codehealthFindingId/v1":"df6ff0a9d5923038747d82dd92bd141801dc9cd3e8dfa25ccc829e0ef5d245f3"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.messageForPort (cyclomatic 29): serveEnv.messageForPort has cyclomatic complexity 29 (threshold 15). Of this number, 26 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1045}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dd31e445889cff1081200c994a70099a717fdd72efb6a986d5a222e7cd7cbfc"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.routerConfigLocked (cyclomatic 29): LocalBackend.routerConfigLocked has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6514}}}],"partialFingerprints":{"codehealthFindingId/v1":"65fd6f6aa42f138e937ec7e8ffa5064f5e5e320e5f670fff90168d1b46452584"}},{"ruleId":"D1","level":"warning","message":{"text":"Manager.compileConfig (cyclomatic 29): Manager.compileConfig has cyclomatic complexity 29 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager.go"},"region":{"startLine":306}}}],"partialFingerprints":{"codehealthFindingId/v1":"26a0025f89a7fd29bda103f8533e520695e4e4a62716679b06ccbbcbb6bef6f8"}},{"ruleId":"D1","level":"warning","message":{"text":"State.InterfaceDiff (cyclomatic 29): State.InterfaceDiff has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e3145330143002489fa440473dde438f2acedd60e75ea28a3906e795b2df176"}},{"ruleId":"D1","level":"warning","message":{"text":"sshSession.startNewRecording (cyclomatic 29): sshSession.startNewRecording has cyclomatic complexity 29 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":1405}}}],"partialFingerprints":{"codehealthFindingId/v1":"86b6a384a0fb1e26d32298faba0a8e71228171397299a2b16d262a8cfa60a422"}},{"ruleId":"D1","level":"warning","message":{"text":"main.autoflagsForTest (cyclomatic 29): main.autoflagsForTest has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/gocross/autoflags.go"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e405d7e075d698591320ea2d9b987a593fb1902478b20a26a5377322676f734"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.sendDiscoMessage (cyclomatic 29): Conn.sendDiscoMessage has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1969}}}],"partialFingerprints":{"codehealthFindingId/v1":"d859a467cd902098a2c91001504808339aec49856423a50b1872a5aaa1967364"}},{"ruleId":"D1","level":"warning","message":{"text":"userspaceEngine.Reconfig (cyclomatic 29): userspaceEngine.Reconfig has cyclomatic complexity 29 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":809}}}],"partialFingerprints":{"codehealthFindingId/v1":"abfc06f3f52d05e914dbf73945357270a0a1f557f18d27e56dcfceb1338e280d"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveAPIAuth (cyclomatic 28): Server.serveAPIAuth has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":654}}}],"partialFingerprints":{"codehealthFindingId/v1":"32359502114b42735d55d5db6b6e3ed6af359190d7a0a76eb2829540802b30a3"}},{"ruleId":"D1","level":"warning","message":{"text":"tailscaleSTSReconciler.provisionSecrets (cyclomatic 28): tailscaleSTSReconciler.provisionSecrets has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"c35b61178682f1a91a6e33cd58b68934e120d12098665d38ab8330f10942c217"}},{"ruleId":"D1","level":"warning","message":{"text":"main.measureICMPRTT (cyclomatic 28): main.measureICMPRTT has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp_linux.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c8a284d8996dc775e9a2e176e0a18287263c5b741678ea2525f3bf0fd5ead26"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runPing (cyclomatic 28): cli.runPing has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ping.go"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"84d46a1dd04c911440a95b88e8b3b8c11f39284cc9b24a5d294cf64de8c584a3"}},{"ruleId":"D1","level":"warning","message":{"text":"mapSession.updatePeersStateFromResponse (cyclomatic 28): mapSession.updatePeersStateFromResponse has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":782}}}],"partialFingerprints":{"codehealthFindingId/v1":"67cf479510f74d266bcb9a83b10ef5012a096714d3faec664b9e8a09690a7fef"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.dialNode (cyclomatic 28): Client.dialNode has cyclomatic complexity 28 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 14 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":737}}}],"partialFingerprints":{"codehealthFindingId/v1":"8dc8e578ba6e85d02e4fa0cda7a12630fe153011fc735e8a31b246a96b5867df"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.RunWatchConnectionLoop (cyclomatic 28): Client.RunWatchConnectionLoop has cyclomatic complexity 28 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 7 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/mesh_client.go"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae1a6f13932e17e4bd1ae83cacb597922d9d3452397fcc8840531459f03307ae"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.NewLocalBackend (cyclomatic 28): ipnlocal.NewLocalBackend has cyclomatic complexity 28 (threshold 15). Of this number, 27 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":543}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d5546b70003f3b4ac675ace71ce449bc4e3bd551597e1b2888b7430ba7ae903"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 27): main.main has cyclomatic complexity 27 (threshold 15). Of this number, 23 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/cigocacher/cigocacher.go"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c7002ed8a8f26627a8a08248f439bb45dc34df033126f59873ca8e671300c03"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runTS2021 (cyclomatic 27): cli.runTS2021 has cyclomatic complexity 27 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":1043}}}],"partialFingerprints":{"codehealthFindingId/v1":"63ffd0d5ba9469e1e3289d8b8cb58e9216393fe01df34d1e09b37191cf7ca843"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runIP (cyclomatic 27): cli.runIP has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ip.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"79a229a3b1dc3d31ac723c7ca3e53513a5eb89f259291dbc4392bd671c803275"}},{"ruleId":"D1","level":"warning","message":{"text":"idpServer.serveToken (cyclomatic 27): idpServer.serveToken has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":844}}}],"partialFingerprints":{"codehealthFindingId/v1":"7093fe6de6e526a829406ac621d478404fbcaf15eb47b83d166df39ed2e03e16"}},{"ruleId":"D1","level":"warning","message":{"text":"controlclient.NewDirect (cyclomatic 27): controlclient.NewDirect has cyclomatic complexity 27 (threshold 15). Of this number, 22 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":301}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebc85cabb513bfb4d2b2d6eb633fa39757a041f2aa134fdab8e455c02199e553"}},{"ruleId":"D1","level":"warning","message":{"text":"debugportmapper.serveDebugPortmap (cyclomatic 27): debugportmapper.serveDebugPortmap has cyclomatic complexity 27 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/debugportmapper/debugportmapper.go"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"2210b9c8dee71183754ad4c7ba8ad0be1c63d792714fb89fa9f28a463fb3bf2f"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.validateServeConfigUpdate (cyclomatic 27): ipnlocal.validateServeConfigUpdate has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":1737}}}],"partialFingerprints":{"codehealthFindingId/v1":"9626105bb62bb159bf37d08dae7f4cf540146e4fa9a81d637048f5a67f0bb0de"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.nodeAddrPort (cyclomatic 27): Client.nodeAddrPort has cyclomatic complexity 27 (threshold 15). Of this number, 24 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1654}}}],"partialFingerprints":{"codehealthFindingId/v1":"07fc1a3f03daee89b34a820f1f4788e1782366ccf70dcde091709928ffbb9c6b"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.runDerpReader (cyclomatic 27): Conn.runDerpReader has cyclomatic complexity 27 (threshold 15). Of this number, 26 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":533}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c0526168c49444cf75f2907ebf53a9674e269aad58461e588e4b4c2e237faf0"}},{"ruleId":"D1","level":"warning","message":{"text":"Updater.getUpdateFunction (cyclomatic 26): Updater.getUpdateFunction has cyclomatic complexity 26 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cccd0c33077b65121b8ec7d9d61a7c3cd5a7e797f45f219e466c904ae47c873"}},{"ruleId":"D1","level":"warning","message":{"text":"main.watchKeyboardForConsole (cyclomatic 26): main.watchKeyboardForConsole has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":330}}}],"partialFingerprints":{"codehealthFindingId/v1":"19781f203ef5ea0161b0b019857893ca3b7b37d4d3220e2da7cd1a15c4f70f45"}},{"ruleId":"D1","level":"warning","message":{"text":"IngressReconciler.maybeProvision (cyclomatic 26): IngressReconciler.maybeProvision has cyclomatic complexity 26 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":135}}}],"partialFingerprints":{"codehealthFindingId/v1":"70a359bd415caa802c2721abe2980ba5285a72a55c53b620b868894f19e65177"}},{"ruleId":"D1","level":"warning","message":{"text":"ProxyGroupReconciler.maybeProvision (cyclomatic 26): ProxyGroupReconciler.maybeProvision has cyclomatic complexity 26 (threshold 15). Of this number, 24 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"0039e8844a4506515eae27475c3c4c7704edfb85f6389677dfb5af94dc363ae8"}},{"ruleId":"D1","level":"warning","message":{"text":"Dialer.tryURLUpgrade (cyclomatic 26): Dialer.tryURLUpgrade has cyclomatic complexity 26 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 8 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client.go"},"region":{"startLine":405}}}],"partialFingerprints":{"codehealthFindingId/v1":"47e8d0a28e200a9ea96c99231369ef240b18e959e9698f90eea34548561f04ea"}},{"ruleId":"D1","level":"warning","message":{"text":"extension.issueACMECert (cyclomatic 26): extension.issueACMECert has cyclomatic complexity 26 (threshold 15). Of this number, 24 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/acme/cert.go"},"region":{"startLine":456}}}],"partialFingerprints":{"codehealthFindingId/v1":"143af1b4aae3ea102461d686b5c380d57dd13e662bbcb0f2fb8ba92930a070c8"}},{"ruleId":"D1","level":"warning","message":{"text":"hostinfo.linuxVersionMeta (cyclomatic 26): hostinfo.linuxVersionMeta has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"hostinfo/hostinfo_linux.go"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"89641f08532f2bc39cb40aec630c860c2e99a8304e040d6d6c9105ab78dc70a8"}},{"ruleId":"D1","level":"warning","message":{"text":"sshSession.run (cyclomatic 26): sshSession.run has cyclomatic complexity 26 (threshold 15). Of this number, 22 points are the body\u0027s own statements and 4 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":1006}}}],"partialFingerprints":{"codehealthFindingId/v1":"77fa664981553fbcb122b7a5d5ebde09ca556ecc1fadbb517e6628745f4a4833"}},{"ruleId":"D1","level":"warning","message":{"text":"network.HandleEthernetPacketForRouter (cyclomatic 26): network.HandleEthernetPacketForRouter has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1862}}}],"partialFingerprints":{"codehealthFindingId/v1":"1462508b40dec5cbfc2e8067393d9be3afa96a833fc36492086f12e990efd1d3"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.initFromConfig (cyclomatic 26): Server.initFromConfig has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/conf.go"},"region":{"startLine":476}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0b7b7e9a4aaa54b991996003256a4fc0dda6def101961318f660b06c88210d6"}},{"ruleId":"D1","level":"warning","message":{"text":"Menu.rebuild (cyclomatic 25): Menu.rebuild has cyclomatic complexity 25 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c11005bd9c59cda272ef25ce1cca81cf92d87851796dfa86fd62601c0e89db7"}},{"ruleId":"D1","level":"warning","message":{"text":"main.gen (cyclomatic 25): main.gen has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/cloner/cloner.go"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"37e42b4732184df818d745603e43402d9e575acd0c61b23b43793417a2dc1076"}},{"ruleId":"D1","level":"warning","message":{"text":"main.watchServeConfigChanges (cyclomatic 25): main.watchServeConfigChanges has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/serve.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"c52f5637c1b411ad0403037b19dabf06d86c65584714d49f8d2f881e580d4192"}},{"ruleId":"D1","level":"warning","message":{"text":"egressPodsReconciler.Reconcile (cyclomatic 25): egressPodsReconciler.Reconcile has cyclomatic complexity 25 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 10 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-pod-readiness.go"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c814bd8bd1d82abca4a69f45b0d9a8d4c035eda6548d98aabcf183c5f5abd49"}},{"ruleId":"D1","level":"warning","message":{"text":"egressSvcsReconciler.provision (cyclomatic 25): egressSvcsReconciler.provision has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services.go"},"region":{"startLine":280}}}],"partialFingerprints":{"codehealthFindingId/v1":"24207d7a2aa6fca72ad3321747a11af2d8a461116286d0f1ba510cbceca6ee70"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 25): main.main has cyclomatic complexity 25 (threshold 15). Of this number, 24 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/natc/natc.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"9391a011b4e2358d2d4597d1f7a9e58a4aa83c2205c5ec0d9aba78cefa284707"}},{"ruleId":"D1","level":"warning","message":{"text":"taildrop.handlePeerPutWithBackend (cyclomatic 25): taildrop.handlePeerPutWithBackend has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/peerapi.go"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9f7feeed347e9a2e0daffb08ed42f36849a857af92313171e9af1099b7e87c3"}},{"ruleId":"D1","level":"warning","message":{"text":"resolvedManager.run (cyclomatic 25): resolvedManager.run has cyclomatic complexity 25 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolved.go"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d0cc07732c921d8bad2ac74cc0040df4ff13faf65f6297693a0e57a89a92111"}},{"ruleId":"D1","level":"warning","message":{"text":"resolver.marshalResponse (cyclomatic 25): resolver.marshalResponse has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":1200}}}],"partialFingerprints":{"codehealthFindingId/v1":"261208455c96486e6ceb8805ee3b14fa5b05202f4cdac4362b850ab21c28d9cc"}},{"ruleId":"D1","level":"warning","message":{"text":"Resolver.resolveLocal (cyclomatic 25): Resolver.resolveLocal has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":722}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c0970c64161c32b2d0048930cc1dde0474a62cb72bd70274bf405f1d4e753f3"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.addReportHistoryAndSetPreferredDERP (cyclomatic 25): Client.addReportHistoryAndSetPreferredDERP has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1415}}}],"partialFingerprints":{"codehealthFindingId/v1":"72cb571df60069e6518abcb91c452e4eb9fae99fbb1a52a4b1ea86e575b8b5dd"}},{"ruleId":"D1","level":"warning","message":{"text":"tgzTarget.Build (cyclomatic 25): tgzTarget.Build has cyclomatic complexity 25 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"release/dist/unixpkgs/pkgs.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc2add3b59c11c89c4ef4a76e6998270bd9c8c60c317cd4ba549d714bf957874"}},{"ruleId":"D1","level":"warning","message":{"text":"conn.clientAuth (cyclomatic 25): conn.clientAuth has cyclomatic complexity 25 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"629b376dc7bd790d2f808710130c5590dc775c1d8436bd469a139163285252f9"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.MapResponse (cyclomatic 25): Server.MapResponse has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1630}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc1d8e3eef0deec67b2b58763b89ce4c5a8b597e085424097f59b5cfb8b1bf6d"}},{"ruleId":"D1","level":"warning","message":{"text":"network.HandleEthernetPacket (cyclomatic 25): network.HandleEthernetPacket has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1572}}}],"partialFingerprints":{"codehealthFindingId/v1":"c53eba381148aa0c05626a1ec6e21982a7f1fc30dfb389893b320f01e784685a"}},{"ruleId":"D1","level":"warning","message":{"text":"endpoint.send (cyclomatic 25): endpoint.send has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1046}}}],"partialFingerprints":{"codehealthFindingId/v1":"762b40a8859000f32ce57eea29080fa1b30f5c838724c606d6d293c8b3a28fbb"}},{"ruleId":"D1","level":"warning","message":{"text":"relayManager.runLoop (cyclomatic 25): relayManager.runLoop has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ed0ff56aa8f67fe55bdd118fdf03faab1b4cbbf66b80db93658de6d61e5650a"}},{"ruleId":"D1","level":"warning","message":{"text":"AppConnector.ObserveDNSResponse (cyclomatic 24): AppConnector.ObserveDNSResponse has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"appc/observe.go"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9aac06118d427d58194a259716328e7aadaa24b12d1086a9fec68367790b340"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveAPI (cyclomatic 24): Server.serveAPI has cyclomatic complexity 24 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":583}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a95af483f80de347fd88af676caff6c7512512bf74c20dafd199ebc8becdc11"}},{"ruleId":"D1","level":"warning","message":{"text":"main.mustFormatFile (cyclomatic 24): main.mustFormatFile has cyclomatic complexity 24 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/jsonimports/format.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc97f8d431c968cb93f8970797a9a0c55bb778032d6f24ce6bd52392d35acff9"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.runServe (cyclomatic 24): serveEnv.runServe has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"860ff7b8d054141eb3b460a108e90315be007cd6ac7d0f95a6da07b6318def42"}},{"ruleId":"D1","level":"warning","message":{"text":"main.getLocalBackend (cyclomatic 24): main.getLocalBackend has cyclomatic complexity 24 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":652}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d396f785ec75748591f4e2b2088537091046f87de695e64ee41c746dd06d18d"}},{"ruleId":"D1","level":"warning","message":{"text":"lowerell.run (cyclomatic 24): lowerell.run has cyclomatic complexity 24 (threshold 15). Most of this is not in the body itself: 2 of the 24 points are its own statements and the rest belongs to one function literal inside it that branches (line 65). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vet/lowerell/analyzer.go"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"657194607d33be3cec44a32adab7092345f558138242cf4a70c33a7f128eeda2"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.updateStatusLocked (cyclomatic 24): LocalBackend.updateStatusLocked has cyclomatic complexity 24 (threshold 15). Most of this is not in the body itself: 7 of the 24 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1471, 1525). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1468}}}],"partialFingerprints":{"codehealthFindingId/v1":"33edea2e28038b1867960cc93fc4b0832ee50a87f9cba91fa190b3429fb45206"}},{"ruleId":"D1","level":"warning","message":{"text":"nmManager.trySet (cyclomatic 24): nmManager.trySet has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nm.go"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ccbc3d37fc3dd0916838ebf19b0ec25b33a3b0e73eecf9b6ce5a243c6bfd518"}},{"ruleId":"D1","level":"warning","message":{"text":"nmManager.GetBaseConfig (cyclomatic 24): nmManager.GetBaseConfig has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nm.go"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebab1118de1ac85c695d946847274099e8155782f756e69b97a4f3cc2b1e2d24"}},{"ruleId":"D1","level":"warning","message":{"text":"netns.controlC (cyclomatic 24): netns.controlC has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_windows.go"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"c17fc78087d512005d305e2beb8274b3d2adc72356d356fca9169ec91e64de41"}},{"ruleId":"D1","level":"warning","message":{"text":"derpProber.probeMapFn (cyclomatic 24): derpProber.probeMapFn has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"3116b048be1c0951248e41fadea915439827e10405d4de24de85944b11a41801"}},{"ruleId":"D1","level":"warning","message":{"text":"tailssh.getSSHUsernames (cyclomatic 24): tailssh.getSSHUsernames has cyclomatic complexity 24 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/c2n.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea99c8234b4f5a617bcd840a15e0d84eb4ac8853e1fde4bac8f4071c5930f6e2"}},{"ruleId":"D1","level":"warning","message":{"text":"sshSession.newIncubatorCommand (cyclomatic 24): sshSession.newIncubatorCommand has cyclomatic complexity 24 (threshold 15). Of this number, 22 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"15dc9f013117ad5375be399101cae928a72eddce86af6482f010ce6f9a84dd57"}},{"ruleId":"D1","level":"warning","message":{"text":"State.applyVerifiedAUM (cyclomatic 24): State.applyVerifiedAUM has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/state.go"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"30abf59db0ff61c2360e6b3ae2573d15cf1e74947a75713319c95ef57d2e5f11"}},{"ruleId":"D1","level":"warning","message":{"text":"userspaceBSDRouter.Set (cyclomatic 24): userspaceBSDRouter.Set has cyclomatic complexity 24 (threshold 15). Of this number, 23 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_userspace_bsd.go"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"222ae602f06f790cb4e07c98f156a1193d8ab404c79f3500adf51089f7093334"}},{"ruleId":"D1","level":"warning","message":{"text":"egressSvcsReadinessReconciler.Reconcile (cyclomatic 23): egressSvcsReadinessReconciler.Reconcile has cyclomatic complexity 23 (threshold 15). Of this number, 22 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services-readiness.go"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"50fdf46eddbf2ce5dbf2e6bea055a09aafe8a4c419fcc28cb78b8e8cfc9fa247"}},{"ruleId":"D1","level":"warning","message":{"text":"main.handleWebSocket (cyclomatic 23): main.handleWebSocket has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 11 of the 23 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 291, 271, 234, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vnet/vnet-main.go"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ea2f14e8191897fc9a36efc3b908de0c970daa6f2768c02b8c3904f1f3adc92"}},{"ruleId":"D1","level":"warning","message":{"text":"Dialer.dialHostOpt (cyclomatic 23): Dialer.dialHostOpt has cyclomatic complexity 23 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client.go"},"region":{"startLine":239}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5631d7b5e8f67b365aa1eb77d5a980812849e3626bf5810306bb9c1fe3ace57"}},{"ruleId":"D1","level":"warning","message":{"text":"conffile.loadConfigV0 (cyclomatic 23): conffile.loadConfigV0 has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/conffile/serveconf.go"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce411ce39e63b73fef7dc7265950ecf86c0fcd1ae09e5cc1f2985a6b4e3b4278"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.setPrefsLocked (cyclomatic 23): LocalBackend.setPrefsLocked has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":5495}}}],"partialFingerprints":{"codehealthFindingId/v1":"866d759f19cbad5cd63fca7f2d9134044f8b5cdb7cdb9a9531131ae061871e60"}},{"ruleId":"D1","level":"warning","message":{"text":"localapi.init (cyclomatic 23): localapi.init has cyclomatic complexity 23 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fd7d6d55eefe8832adafd766e9c5de223bd1af787380ed20d7ef61fbd1955d3"}},{"ruleId":"D1","level":"warning","message":{"text":"Reconciler.createOrUpdate (cyclomatic 23): Reconciler.createOrUpdate has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/peerrelay/peerrelay.go"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"2309ca337b99d82e7fc2ec7f98a7e4b7be6d5b8adefbf187d972e9d408b11ab3"}},{"ruleId":"D1","level":"warning","message":{"text":"Table.Delete (cyclomatic 23): Table.Delete has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/art/table.go"},"region":{"startLine":318}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f1a91a10ebb094bb0b13916f9ebf87852bca0484f8bc4a316bf5911ba1ab260"}},{"ruleId":"D1","level":"warning","message":{"text":"dns.dnsMode (cyclomatic 23): dns.dnsMode has cyclomatic complexity 23 (threshold 15). Of this number, 20 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_linux.go"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"99c780fc370f6d402238c598b2f2520ad355e3cd942c439a7dbbd5bee9178d90"}},{"ruleId":"D1","level":"warning","message":{"text":"routetable.Get (cyclomatic 23): routetable.Get has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routetable/routetable_linux.go"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b89fa6f7136c4b34495809d6cf2f77254b51dc4c6c3294145a1ca3df6e0b897"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.addrDiscoveryLoop (cyclomatic 23): Server.addrDiscoveryLoop has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 5 of the 23 points are its own statements and the rest belongs to one function literal inside it that branches (line 463). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":458}}}],"partialFingerprints":{"codehealthFindingId/v1":"14a65e1956db0da671963ee99545b6b169ea93a11c9101686e2a7eb7eb8ae81f"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.UpdateNetstackIPs (cyclomatic 23): Impl.UpdateNetstackIPs has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":705}}}],"partialFingerprints":{"codehealthFindingId/v1":"97f99e9d08bf79969d7b6a840f05aa5aee53c9256d2a44e5b394ec1168eaf8f9"}},{"ruleId":"D1","level":"warning","message":{"text":"KubeAPIServerTSServiceReconciler.maybeProvision (cyclomatic 22): KubeAPIServerTSServiceReconciler.maybeProvision has cyclomatic complexity 22 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/api-server-proxy-pg.go"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0643cfd031490d1a6cfc8d6519ac5b1f9bcd32f67198df390dad9b29a3e1579"}},{"ruleId":"D1","level":"warning","message":{"text":"main.probeNodes (cyclomatic 22): main.probeNodes has cyclomatic complexity 22 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":580}}}],"partialFingerprints":{"codehealthFindingId/v1":"47c97b7d395d48d2356cae4e3e0c44a73d45ccc6d3eb38731f85640c687b1f4b"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.RunWithContext (cyclomatic 22): cli.RunWithContext has cyclomatic complexity 22 (threshold 15). Of this number, 20 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cli.go"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7cd0e223b707921e1a464044577f05c976f5123c343fa31a1238eed78185b9a"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.updatePrefs (cyclomatic 22): cli.updatePrefs has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":428}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cb67b8a78fffd1f146b849e3e53321366ae9b88ab7c00eb42186fe59610408c"}},{"ruleId":"D1","level":"warning","message":{"text":"extension.installHooks (cyclomatic 22): extension.installHooks has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 5 of the 22 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 163, 268, 191, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab2177e9a89900b08d08dd51f3262e1766d11148e5d58a0558dea3b6851704a2"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.applyPrefsToHostinfoLocked (cyclomatic 22): LocalBackend.applyPrefsToHostinfoLocked has cyclomatic complexity 22 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6636}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4a5332364d18b6df98652e63988c9ad76509d584f5e4778c1cf16e6bdd93812"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.nextStateLocked (cyclomatic 22): LocalBackend.nextStateLocked has cyclomatic complexity 22 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6846}}}],"partialFingerprints":{"codehealthFindingId/v1":"029d72695d94bb73bee698a5bfeaa8dd6d8584ef52b19fcd69b89961fddba510"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.serveShares (cyclomatic 22): Handler.serveShares has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi_drive.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"71f27231becd8a5a6c52519424c8342a23217e1c58f3af41fc1caad65f37e1ca"}},{"ruleId":"D1","level":"warning","message":{"text":"ChangeDelta.isInterestingInterfaceChange (cyclomatic 22): ChangeDelta.isInterestingInterfaceChange has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon.go"},"region":{"startLine":271}}}],"partialFingerprints":{"codehealthFindingId/v1":"9da299651013d45a4cd0fc995fd9f7808f0f5fa2466ddb9e41d4f09d6cae685b"}},{"ruleId":"D1","level":"warning","message":{"text":"netns.getInterfaceIndex (cyclomatic 22): netns.getInterfaceIndex has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 9 of the 22 points are its own statements and the rest belongs to one function literal inside it that branches (line 59). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_darwin.go"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2270498aa85ac71456b23eaaa8f49ee3a7fae7b45175d769f1d62c21ace3ece"}},{"ruleId":"D1","level":"warning","message":{"text":"netutil.CheckIPForwarding (cyclomatic 22): netutil.CheckIPForwarding has cyclomatic complexity 22 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netutil/ip_forward.go"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b19378bdc1db578071842a906b5c1b9e4543f617ef766f6c8a14fcaff6fc425"}},{"ruleId":"D1","level":"warning","message":{"text":"RouteManager.applyDirty (cyclomatic 22): RouteManager.applyDirty has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":909}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c9eb3f9307945b9835804f9a4597b6cd3cf7dd120e85464469d9e21b8ec39f7"}},{"ruleId":"D1","level":"warning","message":{"text":"tstun.diagnoseLinuxTUNFailure (cyclomatic 22): tstun.diagnoseLinuxTUNFailure has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/tun_linux.go"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"1223a415b3d35405646c47f96893a30c8948e2f220ffb14116122ad2a146cc45"}},{"ruleId":"D1","level":"warning","message":{"text":"tka.markAncestorIntersectionAUMs (cyclomatic 22): tka.markAncestorIntersectionAUMs has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tailchonk.go"},"region":{"startLine":800}}}],"partialFingerprints":{"codehealthFindingId/v1":"1610d087b3cd99531efb51a5ae6deeb1e40a8f84904d1d226d5ea330e350648e"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.ListenService (cyclomatic 22): Server.ListenService has cyclomatic complexity 22 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":1835}}}],"partialFingerprints":{"codehealthFindingId/v1":"68c61db74252b1f917c5753cd3c2f99aa3587679e9423d0df2e4b4aceafcfac3"}},{"ruleId":"D1","level":"warning","message":{"text":"Env.startTailMacVM (cyclomatic 22): Env.startTailMacVM has cyclomatic complexity 22 (threshold 15). Of this number, 13 points are the body\u0027s own statements and 9 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/tailmac.go"},"region":{"startLine":547}}}],"partialFingerprints":{"codehealthFindingId/v1":"a572c3a2c55b93a2e0146079f78adfd91977cd694bdf5ea480904848f4276087"}},{"ruleId":"D1","level":"warning","message":{"text":"Env.AddNode (cyclomatic 22): Env.AddNode has cyclomatic complexity 22 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":457}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bb8dad40ae5961f87a9e26b6985d1d5f16a66d3ac9f50b993315e715077cd86"}},{"ruleId":"D1","level":"warning","message":{"text":"network.handleUDPPacketForRouter (cyclomatic 22): network.handleUDPPacketForRouter has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1997}}}],"partialFingerprints":{"codehealthFindingId/v1":"aaff4850f1ff49308201e8d0e47d27c1c0f207950275e56d22c14db9efce660b"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxfw.printMatchInfo (cyclomatic 22): linuxfw.printMatchInfo has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"2124281f6a58a7d2072041a112484b88087828f51c31e12666547a064a8c19e1"}},{"ruleId":"D1","level":"warning","message":{"text":"magicsock.betterAddr (cyclomatic 22): magicsock.betterAddr has cyclomatic complexity 22 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1848}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e84db532f13ef1ce2458fb3d87ab6ce2c67f295e64e54af05a168f45813c0d0"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveGetNodeData (cyclomatic 21): Server.serveGetNodeData has cyclomatic complexity 21 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":876}}}],"partialFingerprints":{"codehealthFindingId/v1":"b30eb1a21c6b931f2cb9e975140582d866fc60ba2a55d69cae439ab20fdaa10e"}},{"ruleId":"D1","level":"warning","message":{"text":"main.updatesForCfg (cyclomatic 21): main.updatesForCfg has cyclomatic complexity 21 (threshold 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"7451189edf099d5fa449e321c4484977a7148aca036b6c97e89b45554b6d0596"}},{"ruleId":"D1","level":"warning","message":{"text":"egressProxy.syncEgressConfigs (cyclomatic 21): egressProxy.syncEgressConfigs has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"13363d241579564b175159c6d093eac9f23ce78ec16ed6bc6539046e06d6c2e1"}},{"ruleId":"D1","level":"warning","message":{"text":"main.initTSNet (cyclomatic 21): main.initTSNet has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fe1623fa87481040ffe9460ae8e636b597fb8c5c1e24b7a15e62863283cf7fb"}},{"ruleId":"D1","level":"warning","message":{"text":"HAServiceReconciler.maybeUpdateAdvertiseServicesConfig (cyclomatic 21): HAServiceReconciler.maybeUpdateAdvertiseServicesConfig has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":637}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ba7b82cbe606e7c3d89762272b4fe78c72722830b563a12fae8cbd76f1946fd"}},{"ruleId":"D1","level":"warning","message":{"text":"proxy.serve (cyclomatic 21): proxy.serve has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/pgproxy/pgproxy.go"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"687d47b7a16c0af70a955a316435389bdc7d2845450c4995f7cb99d7b8cefda8"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runConfigureSynologyCert (cyclomatic 21): cli.runConfigureSynologyCert has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-synology-cert.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"05d5b6baf91dff1b62c15f7a77e33d5fa5e1933f1760d01c9b74dd10fe33af78"}},{"ruleId":"D1","level":"warning","message":{"text":"main.run (cyclomatic 21): main.run has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":430}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e984e7e737d3ce139e129e2407c0e823d895948d28bcae429c8e5bb527348ff"}},{"ruleId":"D1","level":"warning","message":{"text":"idpServer.authorize (cyclomatic 21): idpServer.authorize has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":427}}}],"partialFingerprints":{"codehealthFindingId/v1":"babd04b12caa5eb128dd4283f361062d6ac09062268a30aada15f23f4c8b691e"}},{"ruleId":"D1","level":"warning","message":{"text":"main.runMap (cyclomatic 21): main.runMap has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsp/tsp.go"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"154d72b6c1007810ccc81624425d5205ac9f6dbc84ce46f08bc68699e90bc12c"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 21): main.main has cyclomatic complexity 21 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vnet/vnet-main.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1da6f8bcd9f06661646a4f3c7e94fb6e6ddd52c3fe54ba1aa6abc7244f44542"}},{"ruleId":"D1","level":"warning","message":{"text":"controlbase.Server (cyclomatic 21): controlbase.Server has cyclomatic complexity 21 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlbase/handshake.go"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5d1bd2d126162f4af58129007be1422e343933f0aee0e59d15f2729af6a50ee"}},{"ruleId":"D1","level":"warning","message":{"text":"tapDevice.handleDHCPRequest (cyclomatic 21): tapDevice.handleDHCPRequest has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/tap/tap_linux.go"},"region":{"startLine":204}}}],"partialFingerprints":{"codehealthFindingId/v1":"076af466e5ef12ae1af45f019b70c74c01571f25461bc6b85dafec13609f66bc"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.updateFilterLocked (cyclomatic 21): LocalBackend.updateFilterLocked has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3358}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ed3e42ec119db2fdd306b34ff7f07837f1638ab269042283adb45f76d206661"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.tkaSyncIfNeeded (cyclomatic 21): LocalBackend.tkaSyncIfNeeded has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":349}}}],"partialFingerprints":{"codehealthFindingId/v1":"31c2a22e4adec2a49bffd74008f2fefcd7e1c72cf6656f33bf8e3b1181520d9b"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.TailnetLockModify (cyclomatic 21): LocalBackend.TailnetLockModify has cyclomatic complexity 21 (threshold 15). Of this number, 20 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":890}}}],"partialFingerprints":{"codehealthFindingId/v1":"80fc30e5f41f57e024f26904d827ecfa1322fa9b4c5c115d44f3ff4272a8fc43"}},{"ruleId":"D1","level":"warning","message":{"text":"resolvedManager.setConfigOverDBus (cyclomatic 21): resolvedManager.setConfigOverDBus has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolved.go"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6935e8e4c5d25664f768c1bd59b6bb246c1214843917782f47ad81e43c92eb2"}},{"ruleId":"D1","level":"warning","message":{"text":"forwarder.send (cyclomatic 21): forwarder.send has cyclomatic complexity 21 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 7 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":627}}}],"partialFingerprints":{"codehealthFindingId/v1":"785276b9788048eb86597870b125d4d0609ad3f0c3e68d56d6daa18fb6ce58b7"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.LocalAddresses (cyclomatic 21): netmon.LocalAddresses has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"e50b42f08e3496c073ee158e5ed1135690a6138f33114225f0f80cd7bcd9b7ff"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.getState (cyclomatic 21): netmon.getState has cyclomatic complexity 21 (threshold 15). Of this number, 11 points are the body\u0027s own statements and 10 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":591}}}],"partialFingerprints":{"codehealthFindingId/v1":"b70dabe76e077f8d1c6b788a3c4eb981eb1e9fb202b89092451e0e976e20d8ac"}},{"ruleId":"D1","level":"warning","message":{"text":"prober.runDerpProbeQueuingDelayContinously (cyclomatic 21): prober.runDerpProbeQueuingDelayContinously has cyclomatic complexity 21 (threshold 15). Most of this is not in the body itself: 5 of the 21 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 488, 456, 433). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":411}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b4f916cd45c10ea3c2be53e45f7d0b7a4049046f2b966d943e855e2579a4bed"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.ListenFunnel (cyclomatic 21): Server.ListenFunnel has cyclomatic complexity 21 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":1474}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bc33d21d2b4ba607f52e65f032676f439c364a7d18558f40cffe6333225fea8"}},{"ruleId":"D1","level":"warning","message":{"text":"Machine.ListenPacket (cyclomatic 21): Machine.ListenPacket has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/natlab.go"},"region":{"startLine":628}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3f761bc1fa9504fee81b49be8467ed27956d9a51e0175251d5da43e5e49c304"}},{"ruleId":"D1","level":"warning","message":{"text":"fakeACMEServer.ServeHTTP (cyclomatic 21): fakeACMEServer.ServeHTTP has cyclomatic complexity 21 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/fake_acme.go"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"609174e950e6d72f9ef6aa1c0263e65c67cdcba0f2c1bdcae2f13c8af46d56cb"}},{"ruleId":"D1","level":"warning","message":{"text":"jsonx.MakeInterfaceCoders (cyclomatic 21): jsonx.MakeInterfaceCoders has cyclomatic complexity 21 (threshold 15). Most of this is not in the body itself: 6 of the 21 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 133, 109). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/jsonx/json.go"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"4090a786821a89fd6769641079eda04e79fd665ff61988346dd823c82f43ac53"}},{"ruleId":"D1","level":"warning","message":{"text":"source.keyToEnvVarName (cyclomatic 21): source.keyToEnvVarName has cyclomatic complexity 21 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 6 belong to 4 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/env_policy_store.go"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1e375bc5d20f37f0e1ec3d477b5c723f83c288584579198d3c2b1f4b9773ebc"}},{"ruleId":"D1","level":"warning","message":{"text":"filter.MatchesFromFilterRules (cyclomatic 21): filter.MatchesFromFilterRules has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/tailcfg.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed4586a44bf24d342b63e62541971861bc2e3654dd2165bac57e9209c8f59e63"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.derpWriteChanForRegion (cyclomatic 21): Conn.derpWriteChanForRegion has cyclomatic complexity 21 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"121351a62201123648e194b734d510ec1b359d763cfb766ed6903f88d173aaf9"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.updateNodes (cyclomatic 21): Conn.updateNodes has cyclomatic complexity 21 (threshold 15). Of this number, 20 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3089}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7142509ef69515314b08ca5a2c0fd1433b84bf68aa0cac33e23c595c583c89e"}},{"ruleId":"D1","level":"warning","message":{"text":"main.installIngressForwardingRuleForDNSTarget (cyclomatic 20): main.installIngressForwardingRuleForDNSTarget has cyclomatic complexity 20 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/forwarding.go"},"region":{"startLine":193}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e7b2257682127e27afc734a641ff9945fe97e0ccf7b4e0be7335e2aa47a45e0"}},{"ruleId":"D1","level":"warning","message":{"text":"ProxyGroupReconciler.validate (cyclomatic 20): ProxyGroupReconciler.validate has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e3ea8be3d844c9b21da23498cb9789084aaf8169386502201784d5ec060f761"}},{"ruleId":"D1","level":"warning","message":{"text":"tailscaleSTSReconciler.reconcileSTS (cyclomatic 20): tailscaleSTSReconciler.reconcileSTS has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":637}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1ee1601f9e17161874c35bfcf680941349b08920bf1851f46df899de94aecb6"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runPVEAppliance (cyclomatic 20): cli.runPVEAppliance has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-pve-appliance.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d262c96f13352b64ee8fdbfe942a96a00c909ca4ba785011a54696750af5b82"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.getTargetStableID (cyclomatic 20): cli.getTargetStableID has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":440}}}],"partialFingerprints":{"codehealthFindingId/v1":"4643faf401082db1cd361c15a87336ef6b2b4b8dceb1d6968d55f1754e065bab"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.printTailnetLockStatus (cyclomatic 20): cli.printTailnetLockStatus has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c86695203e836fbea324bd3840cd7d4585c2ce1659e7574e4473f0db157538a"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.prefsFromUpArgs (cyclomatic 20): cli.prefsFromUpArgs has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":299}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3c609106f764f97a1ddefcfdcfb69842622f41e9de40a33e4ce5889c0b80ca7"}},{"ruleId":"D1","level":"warning","message":{"text":"main.startIPNServer (cyclomatic 20): main.startIPNServer has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 9 of the 20 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 601, 573). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":554}}}],"partialFingerprints":{"codehealthFindingId/v1":"578a19c7d136d47bb6e15265ca760f1d46703e5347577b6068f64115815661ba"}},{"ruleId":"D1","level":"warning","message":{"text":"ipn.CheckFunnelPort (cyclomatic 20): ipn.CheckFunnelPort has cyclomatic complexity 20 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":667}}}],"partialFingerprints":{"codehealthFindingId/v1":"1076abd15f6cf50d3726f48f64c8f3551e630128cf3930d0049954afb69bdb36"}},{"ruleId":"D1","level":"warning","message":{"text":"ipn.ExpandProxyTargetValue (cyclomatic 20): ipn.ExpandProxyTargetValue has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":761}}}],"partialFingerprints":{"codehealthFindingId/v1":"c98123c42e0cc06b656d3978f3bf1198ddc704c18a01c488173f36ee5a8300c3"}},{"ruleId":"D1","level":"warning","message":{"text":"Cache.Load (cyclomatic 20): Cache.Load has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/netmapcache/netmapcache.go"},"region":{"startLine":323}}}],"partialFingerprints":{"codehealthFindingId/v1":"97151eb2e2b5f385c35ae71c43950cee707035ce30cbc80d277eddad506cc878"}},{"ruleId":"D1","level":"warning","message":{"text":"profileManager.setProfilePrefs (cyclomatic 20): profileManager.setProfilePrefs has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/profiles.go"},"region":{"startLine":411}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f2f1a77c6be2bb286a642bd3079341dab9f3026902bf8687d745a33888cdbab"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.serveBugReport (cyclomatic 20): Handler.serveBugReport has cyclomatic complexity 20 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7baae47044085bb21f4b2eb6bb1b9a7a8cbca68a4952ef4249bc889e2634fe0"}},{"ruleId":"D1","level":"warning","message":{"text":"Table.Insert (cyclomatic 20): Table.Insert has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/art/table.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"85d3142cd564b188ea6fc939306317c30113de18289aa1ed740d8fb023fef638"}},{"ruleId":"D1","level":"warning","message":{"text":"State.String (cyclomatic 20): State.String has cyclomatic complexity 20 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":297}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7d813ba6b8e264dbdc3f1124c5aa161667fc5d041d71c032625acd1cfbc7636"}},{"ruleId":"D1","level":"warning","message":{"text":"Parsed.decode4 (cyclomatic 20): Parsed.decode4 has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"661c55e0cf6dfaa5394608f272456c65c05643392370f0514e875cb0f60b9bf6"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 20): main.main has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/gocross/gocross.go"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"75dcdb9488fb0a964e54fd942057593c640e3d3c58429c41008755c2e6d3898b"}},{"ruleId":"D1","level":"warning","message":{"text":"cloudenv.getCloud (cyclomatic 20): cloudenv.getCloud has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/cloudenv/cloudenv.go"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f1f5da13271997426ad5b458a9bdca1c243c989522ee21ff1965457d36ea5da"}},{"ruleId":"D1","level":"warning","message":{"text":"osdiag.getRegSubKey (cyclomatic 20): osdiag.getRegSubKey has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/osdiag/osdiag_windows.go"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"15607818cf29a410cc9b4774ffeb46f37e7009130c06710f85dee12bf1b666c9"}},{"ruleId":"D1","level":"warning","message":{"text":"endpoint.startDiscoPingLocked (cyclomatic 20): endpoint.startDiscoPingLocked has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1293}}}],"partialFingerprints":{"codehealthFindingId/v1":"33333ccfb1e637c5abb11a183e357a2f83018cd2347f7830239962900374c4c2"}},{"ruleId":"D1","level":"warning","message":{"text":"relayManager.handshakeServerEndpoint (cyclomatic 20): relayManager.handshakeServerEndpoint has cyclomatic complexity 20 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":875}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e9a42e1a3699c1902b3cde516e52436f6aa48461e453d5233b37bd82b2f5dcc"}},{"ruleId":"D1","level":"warning","message":{"text":"windowsManager.setPrimaryDNS (cyclomatic 20): windowsManager.setPrimaryDNS has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":287}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9d4c79ffdfb87c7bfa6692ca3f50362d78ee243ee7ade8fed4fd0e920a6545c"}},{"ruleId":"D1","level":"warning","message":{"text":"macOSImpl.addProcesses (cyclomatic 20): macOSImpl.addProcesses has cyclomatic complexity 20 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/portlist_macos.go"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6683c3d82851c065eae69575deb99e72df66581401992c578fae156e75af802"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.tailscaleUp (cyclomatic 19): Server.tailscaleUp has cyclomatic complexity 19 (threshold 15). Of this number, 13 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":1136}}}],"partialFingerprints":{"codehealthFindingId/v1":"562c81a53a9b983ab2db884c309c51bad8b0a996853ec1b15ab0014f9847cf2b"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 19): main.main has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/featuretags/featuretags.go"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"88a33cc38747f4bb529e6bd6e71e35243e7115d17750f3a7720e1ec31dfe8c34"}},{"ruleId":"D1","level":"warning","message":{"text":"main.getCredentials (cyclomatic 19): main.getCredentials has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 1 of the 19 points is its own statement and the rest belongs to one function literal inside it that branches (line 230). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/gitops-pusher/gitops-pusher.go"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"c364bde7b468461bdd97f4f64a3e2caec73dc9595e9e66be9a08f84ee3ad2c65"}},{"ruleId":"D1","level":"warning","message":{"text":"main.main (cyclomatic 19): main.main has cyclomatic complexity 19 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/generate/main.go"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"560944658d91026f405e786298de9ecce59357e0073b0a7746bc821e3cfb4be4"}},{"ruleId":"D1","level":"warning","message":{"text":"ProxyGroupReconciler.findStaticEndpoints (cyclomatic 19): ProxyGroupReconciler.findStaticEndpoints has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":1068}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa1cb612bb8a095ff3db5303ec9fc84287ce636a371ef7fee73c887219dcf098"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runSSH (cyclomatic 19): cli.runSSH has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ssh.go"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"d690f5ee800934622e8d783c7c36549f2f53b1d42b98d2f5f147498ca64783d5"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runWeb (cyclomatic 19): cli.runWeb has cyclomatic complexity 19 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/web.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbecfc8dd7dfed03de5147b2aab97d9416e54eb13a4d76ec8d579161047acde9"}},{"ruleId":"D1","level":"warning","message":{"text":"sclient.sendLoop (cyclomatic 19): sclient.sendLoop has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":2001}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ea7cfeda40ad749336c5a71e71d6866f3b71dbf2b5f28d5cf242ee7e279a83c"}},{"ruleId":"D1","level":"warning","message":{"text":"manager.PutFile (cyclomatic 19): manager.PutFile has cyclomatic complexity 19 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/send.go"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"29debf1439af228dbd405b6d468ad3306267e78c444fdfa4f1201ab75d8340ad"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.authReconfigLocked (cyclomatic 19): LocalBackend.authReconfigLocked has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6051}}}],"partialFingerprints":{"codehealthFindingId/v1":"b45479ad67b913769e0896e6c812e3268485897875d53b04009f6c9148ce400a"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.initPeerAPIListenerLocked (cyclomatic 19): LocalBackend.initPeerAPIListenerLocked has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6378}}}],"partialFingerprints":{"codehealthFindingId/v1":"94b384bc53165c3eb556a8c2e19e9b9d2d4ef145f21da7e1131fdaa5a75e82c5"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.setServeConfigLocked (cyclomatic 19): LocalBackend.setServeConfigLocked has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e827aba0a2125014e3939e47ad42adb4ab18e8241eee6fd47f175e1978c48bd"}},{"ruleId":"D1","level":"warning","message":{"text":"peerAPIHandler.ServeHTTP (cyclomatic 19): peerAPIHandler.ServeHTTP has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":358}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ab869f6b0a0aa67ef5eed776d8a0ae1c2aceeadf0472f3aad0093e386212a1f"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.runHTTPOnlyChecks (cyclomatic 19): Client.runHTTPOnlyChecks has cyclomatic complexity 19 (threshold 15). Of this number, 13 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1068}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa88b51cc56960538118ebfb1f38586bffd51f0f1b2aaff40332ba17dd2ce9b1"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.likelyHomeRouterIPLinux (cyclomatic 19): netmon.likelyHomeRouterIPLinux has cyclomatic complexity 19 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_linux.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f84ae0cb17944d339bf1732eccf612be49c79232c5911d50cb83624bdb3f607"}},{"ruleId":"D1","level":"warning","message":{"text":"netns.interfaceIndexFor (cyclomatic 19): netns.interfaceIndexFor has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_darwin.go"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f12823faf3e75a91ebc8d4af1876f2c63b9a2a9f1b96a51f6ce8f81266306c3"}},{"ruleId":"D1","level":"warning","message":{"text":"netx.RaceDial (cyclomatic 19): netx.RaceDial has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 9 of the 19 points are its own statements and the rest belongs to one function literal inside it that branches (line 45). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netx/racedial.go"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"23008967d49b001dc5024a0a0784a10d303dcf1592d0e13904938d6b84cb0de7"}},{"ruleId":"D1","level":"warning","message":{"text":"portmapper.selectBestService (cyclomatic 19): portmapper.selectBestService has cyclomatic complexity 19 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/upnp.go"},"region":{"startLine":296}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c6e3106dfc249258ebd3431ea1f92cd11c27db59e306ddfdd92d4ff5f0f9b52"}},{"ruleId":"D1","level":"warning","message":{"text":"Wrapper.filterPacketOutboundToWireGuard (cyclomatic 19): Wrapper.filterPacketOutboundToWireGuard has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":745}}}],"partialFingerprints":{"codehealthFindingId/v1":"5178859022133107a51e9ed1a1eb99875f4b063e4192bc2a1a7a6bb05f90e88e"}},{"ruleId":"D1","level":"warning","message":{"text":"serverEndpoint.handleDiscoControlMsg (cyclomatic 19): serverEndpoint.handleDiscoControlMsg has cyclomatic complexity 19 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"f450eaf4e60b634eb93ad73f076096ab3fcf4e805f7ac4bf71a2a0e8385d35be"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxImpl.parseProcNetFile (cyclomatic 19): linuxImpl.parseProcNetFile has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/portlist_linux.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"a69f77cfb624529417d5a935113d89a3103181abb0bed1e4247ce67d2be03670"}},{"ruleId":"D1","level":"warning","message":{"text":"tailssh.doDropPrivileges (cyclomatic 19): tailssh.doDropPrivileges has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":766}}}],"partialFingerprints":{"codehealthFindingId/v1":"94ca275bd8954a45a2a2f3ea7d6cbacc48c9a7c7e4ecb8600252dccb778d52ad"}},{"ruleId":"D1","level":"warning","message":{"text":"sshSession.startWithPTY (cyclomatic 19): sshSession.startWithPTY has cyclomatic complexity 19 (threshold 15). Of this number, 10 points are the body\u0027s own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":1025}}}],"partialFingerprints":{"codehealthFindingId/v1":"c182a4310bd94f126f71cc58a0649012384058378a144676a9d356b965c9b775"}},{"ruleId":"D1","level":"warning","message":{"text":"State.staticValidateCheckpoint (cyclomatic 19): State.staticValidateCheckpoint has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/state.go"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"a19ba6b7172c579378f4c544a0214448dde309cd4b26dc4f80e2a255d2ea0ac6"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.ServeUnixConn (cyclomatic 19): Server.ServeUnixConn has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1332}}}],"partialFingerprints":{"codehealthFindingId/v1":"5528cbe428d04951f9c58dd2c358159afe4f5ee52ca71fbcfe418081bed04c0a"}},{"ruleId":"D1","level":"warning","message":{"text":"varz.prometheusMetric (cyclomatic 19): varz.prometheusMetric has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 9 of the 19 points are its own statements and the rest belongs to one function literal inside it that branches (line 132). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/varz/varz.go"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"117059f1c5a35dbe7fffb1011cc26d57a4737afc8d2a795504621722cebbee5e"}},{"ruleId":"D1","level":"warning","message":{"text":"geo.MakePoint (cyclomatic 19): geo.MakePoint has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/geo/point.go"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4e92a7541b076760a483d68d977d1baa6e23df304fcce9267331cf66f8a762d"}},{"ruleId":"D1","level":"warning","message":{"text":"winutil.makeLogEntry (cyclomatic 19): winutil.makeLogEntry has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/svcdiag_windows.go"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc175ca6d46d08232383bdb7c1a35a41231f94aa551eaa5f12359a29dd88fcf8"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.handlePingLocked (cyclomatic 19): Conn.handlePingLocked has cyclomatic complexity 19 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":2539}}}],"partialFingerprints":{"codehealthFindingId/v1":"78e92fedfbbf8eaa21a28bde4beb11f16204ba0900ba9724be486e740e769fab"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.bindSocket (cyclomatic 19): Conn.bindSocket has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3711}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e047f3724d5903883bc0a97232d7e1d6dc9096db4bc27dbaa9870f052c96bda"}},{"ruleId":"D1","level":"warning","message":{"text":"gro.RXChecksumOffload (cyclomatic 19): gro.RXChecksumOffload has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/gro/gro.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"cca7b4f039d39d71d31331fd2de24a6774610de75efcc3c666619481f9deff09"}},{"ruleId":"D1","level":"warning","message":{"text":"netstack.Create (cyclomatic 19): netstack.Create has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"8363062a0984d26799e6aebc369fd70e2e78987ff223a04c9442da172250bfb2"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.handleLocalPackets (cyclomatic 19): Impl.handleLocalPackets has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":842}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddb16aabd45757aa88c00757f5e342aed6adbd5012777a61edf57c0a8d71fb3e"}},{"ruleId":"D1","level":"warning","message":{"text":"lsaSession.logonAs (cyclomatic 19): lsaSession.logonAs has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/s4u/lsa_windows.go"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2e36acb32a86de8b865114bf2671c6a4c4b21b37291c2c9bb577b4238d1faee"}},{"ruleId":"D1","level":"warning","message":{"text":"main.certProviderByCertMode (cyclomatic 18): main.certProviderByCertMode has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/cert.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"85e06ee6a9267292b7276fff2c320686c02e5c640462ffa7cb114435eb8c750e"}},{"ruleId":"D1","level":"warning","message":{"text":"nameserver.resetRecords (cyclomatic 18): nameserver.resetRecords has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-nameserver/main.go"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc87fb38f1b6cfa6b95ea350f29cdea7de13cd9843094eb3df7ddc951b19baa7"}},{"ruleId":"D1","level":"warning","message":{"text":"main.handlersForIngress (cyclomatic 18): main.handlersForIngress has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 6 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 325). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdd10267e6fc7440c0ee36d2cefe69e73722126f363be95d297585b4be281c04"}},{"ruleId":"D1","level":"warning","message":{"text":"NameserverReconciler.Reconcile (cyclomatic 18): NameserverReconciler.Reconcile has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/nameserver.go"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"b220e3010528c516ba6f2516233193f674c523e6de85cd1189929134ab499cc9"}},{"ruleId":"D1","level":"warning","message":{"text":"RecorderReconciler.maybeProvision (cyclomatic 18): RecorderReconciler.maybeProvision has cyclomatic complexity 18 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"6065e6255af5e94e3620817c0019aec49876dbb97f53db6a74439985bd919dbf"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runTailnetLockRemove (cyclomatic 18): cli.runTailnetLockRemove has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":334}}}],"partialFingerprints":{"codehealthFindingId/v1":"83c67be0cee50d3b070fa1d3e862523f07b74f74e1f8dec9d0ec633ed94fa1eb"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runTailnetLockRevokeKeys (cyclomatic 18): cli.runTailnetLockRevokeKeys has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":832}}}],"partialFingerprints":{"codehealthFindingId/v1":"7aac87d0d5f11bdf520d1c049a1c18d4a72063232fa19734187c2b64669fbbc3"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runWait (cyclomatic 18): cli.runWait has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/wait.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"aed6310170fb89ffb86442e1ef9acc2b2cf8116622a26832beb39b23f081f19d"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.enableFeatureInteractive (cyclomatic 18): serveEnv.enableFeatureInteractive has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":793}}}],"partialFingerprints":{"codehealthFindingId/v1":"ded34f8ba7175361540ea7141f688c9c8a7f23c8e125d6fe95bdace3c6a68f38"}},{"ruleId":"D1","level":"warning","message":{"text":"main.getFieldComments (cyclomatic 18): main.getFieldComments has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/viewer/viewer.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"f26d683875dc188d7550f52114dcb38ad02e230cc5cbc289453585193cc423bb"}},{"ruleId":"D1","level":"warning","message":{"text":"Client.dialNodeUsingProxy (cyclomatic 18): Client.dialNodeUsingProxy has cyclomatic complexity 18 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":847}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9b38b76c5108b9edeb5bc2a36e16468fa3bb8f2133d918bd88f0c3f10972896"}},{"ruleId":"D1","level":"warning","message":{"text":"sclient.run (cyclomatic 18): sclient.run has cyclomatic complexity 18 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":1093}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b44d8c3706e4bbc16d912529e6580f81c3374215a9dda092e1ef197e1d67590"}},{"ruleId":"D1","level":"warning","message":{"text":"netLogger.Reconfig (cyclomatic 18): netLogger.Reconfig has cyclomatic complexity 18 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/netlog/netlog.go"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"74bcc978ffd96761ac1d076a1e2948c3e1db9d198ae28bd9c74761f93e286388"}},{"ruleId":"D1","level":"warning","message":{"text":"RouterTracker.watchIPNBus (cyclomatic 18): RouterTracker.watchIPNBus has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to one function literal inside it that branches (line 179). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/routecheck/routertracker.go"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"707497fe51af95cfc28286f7ee52dffdd68dc7e71bfb07620317e4b3c3e90df5"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.suggestExitNodeUsingTrafficSteering (cyclomatic 18): ipnlocal.suggestExitNodeUsingTrafficSteering has cyclomatic complexity 18 (threshold 15). Of this number, 9 points are the body\u0027s own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":8958}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c71ad58337021f3c4082671cf08d87396041a4f302fac72cc9204dc6c47e745"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.enterStateLocked (cyclomatic 18): LocalBackend.enterStateLocked has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6739}}}],"partialFingerprints":{"codehealthFindingId/v1":"b33712cddd97f2b7d6a18857876fd4e97c92ba54e660a17a4195cd93470d943d"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.probeLocks (cyclomatic 18): LocalBackend.probeLocks has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/watchdog.go"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"36585f73149165ccaf4d12e298dc2f8dad48d367c6b9d53b0d8fd688e93fc789"}},{"ruleId":"D1","level":"warning","message":{"text":"nodeBackend.UpdateNetmapDelta (cyclomatic 18): nodeBackend.UpdateNetmapDelta has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1084}}}],"partialFingerprints":{"codehealthFindingId/v1":"3204d8b1c5a2d6c297321325e19d7e87e801bce047cccf413a3d5bc211cfaabe"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.serveHTTP (cyclomatic 18): Server.serveHTTP has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnserver/server.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc096789d49c0b4d071f430bcd83a3bbe9a034fae372202cc6c0723e8cb5e0a7"}},{"ruleId":"D1","level":"warning","message":{"text":"proxyclass.validateNodePortRanges (cyclomatic 18): proxyclass.validateNodePortRanges has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/proxyclass/proxyclass.go"},"region":{"startLine":414}}}],"partialFingerprints":{"codehealthFindingId/v1":"abb8a5ac6138fc73085b66e6d13b4c9fa65bbd17a7fb47872175f8e4b37bf49a"}},{"ruleId":"D1","level":"warning","message":{"text":"filch.New (cyclomatic 18): filch.New has cyclomatic complexity 18 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/filch/filch.go"},"region":{"startLine":423}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ab31f6d6329283a01403c37c559bb4027996dd6fb76c5f1d93e700e84fcdd37"}},{"ruleId":"D1","level":"warning","message":{"text":"Logger.appendMetadata (cyclomatic 18): Logger.appendMetadata has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":813}}}],"partialFingerprints":{"codehealthFindingId/v1":"bed24022d09403f6f9b69d307cc85d1971edbfdecbe50842c7b46872ab9b4bb8"}},{"ruleId":"D1","level":"warning","message":{"text":"forwarder.sendUDP (cyclomatic 18): forwarder.sendUDP has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":787}}}],"partialFingerprints":{"codehealthFindingId/v1":"661b7fc8190f88a45c8fa9f64abdb75c1f023047ab474ceeab8416bfb1a514ec"}},{"ruleId":"D1","level":"warning","message":{"text":"Resolver.LookupIP (cyclomatic 18): Resolver.LookupIP has cyclomatic complexity 18 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnscache/dnscache.go"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"90e8b126e64b5e317de512fe58d3e454fee1e38cb9c2ce4b4103b4f1fd75f20e"}},{"ruleId":"D1","level":"warning","message":{"text":"Resolver.lookupIP (cyclomatic 18): Resolver.lookupIP has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnscache/dnscache.go"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ff8334163064046e4ff16360a3d932bc349adbb27c907b24146c116b4ce95df"}},{"ruleId":"D1","level":"warning","message":{"text":"dnsfallback.lookup (cyclomatic 18): dnsfallback.lookup has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnsfallback/dnsfallback.go"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"307c25e45f466898493b47af13aa776b568f64acbdef106d892b2ed52a86f78c"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.NewChangeDelta (cyclomatic 18): netmon.NewChangeDelta has cyclomatic complexity 18 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon.go"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"0165022e35e6bf2e5b9ab467ae072bd75edd47c13f9a366818926c37e8b6769a"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.isDefaultGateway (cyclomatic 18): netmon.isDefaultGateway has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_bsd.go"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5576a72e47a1020fb326d6221364195df4086bcb946e540c246c36e7d9dfb17"}},{"ruleId":"D1","level":"warning","message":{"text":"State.Equal (cyclomatic 18): State.Equal has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b6443cc31051d837c70dd59d74ea41d2d9fdfb5e15539dd98f3712ba81fb63b"}},{"ruleId":"D1","level":"warning","message":{"text":"tstun.New (cyclomatic 18): tstun.New has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/tun.go"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b705230f6835c5fc9e32d4f28c77b3efb7f5f391b33fe9a9d6e0da04debf0ac"}},{"ruleId":"D1","level":"warning","message":{"text":"chonktest.RunCompactableChonkTests (cyclomatic 18): chonktest.RunCompactableChonkTests has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 258, 214, 170, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/chonktest/chonktest.go"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"1de63488cd6c48092a9d6c2c8bb4bc74e22e8cadf3ed52931ac0a63809a96ae8"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.RunInstance (cyclomatic 18): Server.RunInstance has cyclomatic complexity 18 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/mts/mts.go"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfa4d81fcee1acd4be0eed4af323f3e55c4deb644322bbbbea8dc599e89fbfef"}},{"ruleId":"D1","level":"warning","message":{"text":"vnet.newVIP (cyclomatic 18): vnet.newVIP has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vip.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"306b8a0eba02b1e9a3f3e79677941c62a57867a6e0812da369c40bbee37ba549"}},{"ruleId":"D1","level":"warning","message":{"text":"vnet.mkPacket (cyclomatic 18): vnet.mkPacket has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":3037}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f64935f49a635884430b8778f05a41758c857570916c3abec0cf32f0b6a5172"}},{"ruleId":"D1","level":"warning","message":{"text":"errorHandler.handleError (cyclomatic 18): errorHandler.handleError has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/tsweb.go"},"region":{"startLine":781}}}],"partialFingerprints":{"codehealthFindingId/v1":"15b8016f18aac22fbdade13a6940c109eb59818d328b020d32ac8eddd9aef6d2"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxfw.DebugNetfilter (cyclomatic 18): linuxfw.DebugNetfilter has cyclomatic complexity 18 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"bacb0e25af25f2eee183e6145ee46cdec2919ab3c71a56aab6e7dddc7c6ca31d"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.mkReceiveFunc (cyclomatic 18): Conn.mkReceiveFunc has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to one function literal inside it that branches (line 1751). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1747}}}],"partialFingerprints":{"codehealthFindingId/v1":"27d139d209dfe960ca84543b4b1861a230f71d748defd5edae0e3f94a64b8c86"}},{"ruleId":"D1","level":"warning","message":{"text":"Logger.addNewVirtConnLocked (cyclomatic 18): Logger.addNewVirtConnLocked has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netlog/netlog.go"},"region":{"startLine":261}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1a029f3bc002240f5740a18fca291c6c38897f005d128877208d17afdf4bb87"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.forwardTCP (cyclomatic 18): Impl.forwardTCP has cyclomatic complexity 18 (threshold 15). Of this number, 9 points are the body\u0027s own statements and 9 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1714}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e8ab0cc810bcbcf241c7dac04fa13d4c85fa166b13abe9f5022c719b9ca3f45"}},{"ruleId":"D1","level":"warning","message":{"text":"osrouter.monitorDefaultRoutes (cyclomatic 18): osrouter.monitorDefaultRoutes has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 3 of the 18 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 48, 101). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e452b88a9e79c2dc178ddfebe78207a27509c5a132a3ccac1d4f38c367336aa"}},{"ruleId":"D1","level":"warning","message":{"text":"firewallTweaker.doSet (cyclomatic 18): firewallTweaker.doSet has cyclomatic complexity 18 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_windows.go"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"732dee274d0488601eefa78763f1a9f93044f8994b4f952aa58ec521032b3a28"}},{"ruleId":"D1","level":"warning","message":{"text":"ipCertManager.obtainCert (cyclomatic 17): ipCertManager.obtainCert has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/ipcert.go"},"region":{"startLine":380}}}],"partialFingerprints":{"codehealthFindingId/v1":"689fc37a8906b36743c1955deb2470418ede470577291bf5355d95cb3a5e0815"}},{"ruleId":"D1","level":"warning","message":{"text":"ConnectorReconciler.maybeProvisionConnector (cyclomatic 17): ConnectorReconciler.maybeProvisionConnector has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/connector.go"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"f59bc3004e9d45a53574817e6059994b182ff78259d9bed9fa44810fdae5a917"}},{"ruleId":"D1","level":"warning","message":{"text":"egressEpsReconciler.Reconcile (cyclomatic 17): egressEpsReconciler.Reconcile has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-eps.go"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b84dfffc25408a8221c8e4e59e4496376d6ac12a0e5f9389697dede9df7c282"}},{"ruleId":"D1","level":"warning","message":{"text":"configLoader.watchConfigFileChanges (cyclomatic 17): configLoader.watchConfigFileChanges has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/internal/config/config.go"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdfe5293b161730d35ea912c8147d286d9994867cfa00d5d5d730939ed3d2975"}},{"ruleId":"D1","level":"warning","message":{"text":"main.newConnAndMeasureFn (cyclomatic 17): main.newConnAndMeasureFn has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"94186b43dc095e5c010cbf5697fdec1555bf76b90f5de9f6e3ba45be5d26b6ea"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runWatchIPN (cyclomatic 17): cli.runWatchIPN has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":664}}}],"partialFingerprints":{"codehealthFindingId/v1":"dcb8bf3a3ab0e96311c3749c807d68793c99c4ae69f1ca4cedfcf3d21ab9e277"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runNetcheck (cyclomatic 17): cli.runNetcheck has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/netcheck.go"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ef029535dc34accabe98ff38317d08921bcb71b9b0e692aa654fbffbd217fd6"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.printNetCheckReport (cyclomatic 17): cli.printNetCheckReport has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/netcheck.go"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"895d544bade488af1c60e955b5872fdcfb4e6713d84247088914b753f6a3ea84"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runTailnetLockInit (cyclomatic 17): cli.runTailnetLockInit has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"947ad53136504bfdf4a0891e1e13c7d10c55be900f3d1725ac734c7463990a8c"}},{"ruleId":"D1","level":"warning","message":{"text":"main.runOneTest (cyclomatic 17): main.runOneTest has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"647424182a507e10456f6b231f20def57cbaf29be518ff8385d49a1280d91549"}},{"ruleId":"D1","level":"warning","message":{"text":"Auto.authRoutine (cyclomatic 17): Auto.authRoutine has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/auto.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"478faba36b13034d5cb335e62cb9192927a2d1a3dff6aab63112980f1459f9b5"}},{"ruleId":"D1","level":"warning","message":{"text":"ts2021.NewClient (cyclomatic 17): ts2021.NewClient has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/ts2021/client.go"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"10a6cd766c525ddc10d525929483af974f9c14c8b483351a4217bc133a041de4"}},{"ruleId":"D1","level":"warning","message":{"text":"clientupdate.findCmdTailscale (cyclomatic 17): clientupdate.findCmdTailscale has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/clientupdate/clientupdate.go"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b139c1ccffc886399c664f3754031d471f609cd58e078659dab298c5e5de9b8"}},{"ruleId":"D1","level":"warning","message":{"text":"conn25.configFromNodeView (cyclomatic 17): conn25.configFromNodeView has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"81f00ed69fb72069d9c2713bfb5837be5189e5875c111acdb790cfc51cf07e3a"}},{"ruleId":"D1","level":"warning","message":{"text":"ipn.exitNodeIPOfArg (cyclomatic 17): ipn.exitNodeIPOfArg has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":885}}}],"partialFingerprints":{"codehealthFindingId/v1":"456bf3bf6dacf33b6985a0c5a951cb84a573a43eb17a1e845dfb8729d105117d"}},{"ruleId":"D1","level":"warning","message":{"text":"Notify.String (cyclomatic 17): Notify.String has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/backend.go"},"region":{"startLine":548}}}],"partialFingerprints":{"codehealthFindingId/v1":"1409d2920471103ba1bebd6ada3a8431d49090f4aa1c494aef4b565b12c66a29"}},{"ruleId":"D1","level":"warning","message":{"text":"ipnlocal.writePrettyDNSReply (cyclomatic 17): ipnlocal.writePrettyDNSReply has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":876}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ff85fa111d81af08eb6dbaa05678a98abc2be71dc7ac6230910f8a8a7d9b1c7"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.TCPHandlerForDst (cyclomatic 17): LocalBackend.TCPHandlerForDst has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/netstack.go"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b687f7c5b6d48aec760770c29e9e27d2adcb4e30ce809671a460d198c4b6787"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.tkaFilterNetmapLocked (cyclomatic 17): LocalBackend.tkaFilterNetmapLocked has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":181}}}],"partialFingerprints":{"codehealthFindingId/v1":"27a1bab095b09c9671a1e91aa80a2732a9e8edd99ee54cbda25f53477b0a642a"}},{"ruleId":"D1","level":"warning","message":{"text":"Status.WriteHTML (cyclomatic 17): Status.WriteHTML has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnstate/ipnstate.go"},"region":{"startLine":586}}}],"partialFingerprints":{"codehealthFindingId/v1":"c91b6a4372fd087b37cd5eb78d46bd67572fd605c09fd413fc7d1e1319edd54e"}},{"ruleId":"D1","level":"warning","message":{"text":"store.maybeMigrateLocalStateFile (cyclomatic 17): store.maybeMigrateLocalStateFile has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/stores.go"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"91b7d2525e4eddd8d28c888591b456f3739bfb2aa5b6d9146a95320f612da371"}},{"ruleId":"D1","level":"warning","message":{"text":"conn.processFrames (cyclomatic 17): conn.processFrames has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/ws/conn.go"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"db283dddc03f4e891de2876bce305dcdec1cfdbe077515b5c6343f1025908f7b"}},{"ruleId":"D1","level":"warning","message":{"text":"logpolicy.LogsDir (cyclomatic 17): logpolicy.LogsDir has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"380c0ef5751404e37b2849f77bb70f58ed050afe26523cd532c6fcebb648f935"}},{"ruleId":"D1","level":"warning","message":{"text":"logtail.UploadLogs (cyclomatic 17): logtail.UploadLogs has cyclomatic complexity 17 (threshold 15). Of this number, 12 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5ae25f773838e1a2b0e40d9a872ac5db29d7cde03f42daa8c1addcb5ea0fe98"}},{"ruleId":"D1","level":"warning","message":{"text":"Filch.TryReadLine (cyclomatic 17): Filch.TryReadLine has cyclomatic complexity 17 (threshold 15). Of this number, 12 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/filch/filch.go"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4db55068d62d7baf9cc08980f6e6bf91adf55bf960db35837303a2e19cadec9"}},{"ruleId":"D1","level":"warning","message":{"text":"Logger.appendTextOrJSONLocked (cyclomatic 17): Logger.appendTextOrJSONLocked has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 8 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 921). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":910}}}],"partialFingerprints":{"codehealthFindingId/v1":"badaa89bceb0d411212fa4657f4820e9a7be0dbcd3091e29265ad82b972dd3df"}},{"ruleId":"D1","level":"warning","message":{"text":"linuxBatchingConn.coalesceMessages (cyclomatic 17): linuxBatchingConn.coalesceMessages has cyclomatic complexity 17 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/batching/conn_linux.go"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7972c5df761330cd0ee51a02ab22135e1af8ecdce9375e0dd0c3238875c7f5b"}},{"ruleId":"D1","level":"warning","message":{"text":"netmon.likelyHomeRouterIPWindows (cyclomatic 17): netmon.likelyHomeRouterIPWindows has cyclomatic complexity 17 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_windows.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f99448937a076d828d6b584331da2cdb0d974d7abdf44af720b7be8d62a1f43"}},{"ruleId":"D1","level":"warning","message":{"text":"netutil.CalcAdvertiseRoutes (cyclomatic 17): netutil.CalcAdvertiseRoutes has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netutil/routes.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"55754b8b7a5a7259504c5622456cf0b25e34c032960726e3bccaee52e96ed731"}},{"ruleId":"D1","level":"warning","message":{"text":"NodeKeySignature.verifySignature (cyclomatic 17): NodeKeySignature.verifySignature has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/sig.go"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"46734f667a71891bb4b9e9b53cd2b76ebbd8cc23fe8d69bde23c14a52f8d5977"}},{"ruleId":"D1","level":"warning","message":{"text":"main.run (cyclomatic 17): main.run has cyclomatic complexity 17 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/updateflakes/updateflakes.go"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"00d0b4a0328baf9776e60f39cf58014cf947973f9ed426231023138ee2af2169"}},{"ruleId":"D1","level":"warning","message":{"text":"DepChecker.Check (cyclomatic 17): DepChecker.Check has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/deptest/deptest.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"d01896528e56b856aa64f69ff2a3b2536ddd8f5e328b2cc6ec21c1bbe5eca045"}},{"ruleId":"D1","level":"warning","message":{"text":"vmtest.ensureImage (cyclomatic 17): vmtest.ensureImage has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/images.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3c36c2ce28e5782017591e8cd314a09fed483aecabb7e19c07fec2530d911c0"}},{"ruleId":"D1","level":"warning","message":{"text":"vmtest.ensureVersionBinaries (cyclomatic 17): vmtest.ensureVersionBinaries has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/version.go"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"66c05a8d118a144cbcdf847dd1baeff64578ae08bd444340b53913306d0897a3"}},{"ruleId":"D1","level":"warning","message":{"text":"Server.createDNSResponse (cyclomatic 17): Server.createDNSResponse has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2526}}}],"partialFingerprints":{"codehealthFindingId/v1":"6da77db82dbc4519701f39854cabd3145854418cb4e13efcb9b2b3c2e97d4d78"}},{"ruleId":"D1","level":"warning","message":{"text":"logHandler.ServeHTTP (cyclomatic 17): logHandler.ServeHTTP has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 7 of the 17 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 554, 531, 578). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/tsweb.go"},"region":{"startLine":498}}}],"partialFingerprints":{"codehealthFindingId/v1":"86ba19a547aa9877351c72f523e95e800db99c3844b3e5ce82e50f58d4f0ff90"}},{"ruleId":"D1","level":"warning","message":{"text":"Bus.pump (cyclomatic 17): Bus.pump has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/eventbus/bus.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"f69b2c2769f5f0c23e7075e06521da25cd5500c4ff42c7ddfb69ee4783141aa9"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.receiveIP (cyclomatic 17): Conn.receiveIP has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1830}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff4a93f5d94142557d5a5206021d007305db1a01026db10af4b960e3d1389bbd"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.upsertPeerLocked (cyclomatic 17): Conn.upsertPeerLocked has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3186}}}],"partialFingerprints":{"codehealthFindingId/v1":"11ba9cbe7c40c3ff1107982cd43220450c7fc92bc155a9da2da5a2f9bb0c9fe7"}},{"ruleId":"D1","level":"warning","message":{"text":"Conn.receiveDisco (cyclomatic 17): Conn.receiveDisco has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock_linux.go"},"region":{"startLine":370}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd19183b165b974166964954fbdedbef013b5813ebc9b1ce78aefb2355c7ee84"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.shouldSendToHost (cyclomatic 17): Impl.shouldSendToHost has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1101}}}],"partialFingerprints":{"codehealthFindingId/v1":"957e2c22d35bb3b4f8a7c34064a7431800beb52a217f3228f069de2a79768d77"}},{"ruleId":"D1","level":"warning","message":{"text":"userspaceEngine.onOpenTimeout (cyclomatic 17): userspaceEngine.onOpenTimeout has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/pendopen.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a5c3036301e8cddeb3e379b114614a0a10825a98674621dff54cf8eacd9fa38"}},{"ruleId":"D1","level":"warning","message":{"text":"windowsManager.SetDNS (cyclomatic 17): windowsManager.SetDNS has cyclomatic complexity 17 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"2de49046a2885a606a20d1bef19ade079539b083258c7c5a3a40ce33c66b8a58"}},{"ruleId":"D1","level":"warning","message":{"text":"Menu.eventLoop (cyclomatic 16): Menu.eventLoop has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4883a8dc42bd7b0d67d9ee8091ff5898d89358fb2b568f6ee853880a2f54bfb"}},{"ruleId":"D1","level":"warning","message":{"text":"main.reconcileMetricsResources (cyclomatic 16): main.reconcileMetricsResources has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/metrics_resources.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"b05e1fb26b87cf25091b2bb053fb6d072b0189693b7f256cc9c6a0791910f865"}},{"ruleId":"D1","level":"warning","message":{"text":"ConnectorReconciler.Reconcile (cyclomatic 16): ConnectorReconciler.Reconcile has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/connector.go"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf48c82c4fd38e9f9000752aefaf59f40fac81c44d50ec17b5053fa6dab4f933"}},{"ruleId":"D1","level":"warning","message":{"text":"dnsRecordsReconciler.maybeProvision (cyclomatic 16): dnsRecordsReconciler.maybeProvision has cyclomatic complexity 16 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/dnsrecords.go"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"85d6d2d2f62e7594829fabb86054be581fe56db850d2768566baca197f8b992c"}},{"ruleId":"D1","level":"warning","message":{"text":"RecorderReconciler.Reconcile (cyclomatic 16): RecorderReconciler.Reconcile has cyclomatic complexity 16 (threshold 15). Of this number, 14 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4c69e5d7d9aa37d1300d75ac034346bd8968ecb85ad0281a9fc9d261e32bea3"}},{"ruleId":"D1","level":"warning","message":{"text":"configLoader.watchConfigSecretChanges (cyclomatic 16): configLoader.watchConfigSecretChanges has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/internal/config/config.go"},"region":{"startLine":171}}}],"partialFingerprints":{"codehealthFindingId/v1":"389a2a3c0cbcf552f7469f04e8bf3ce943ac367eae48022a660c68614b9945ff"}},{"ruleId":"D1","level":"warning","message":{"text":"main.run (cyclomatic 16): main.run has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/sniproxy/sniproxy.go"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"c21056ce6035e6a26d5dad28e99c2420ec6791836a54d32c2ad37208ee0b6bb4"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.usageFuncOpt (cyclomatic 16): cli.usageFuncOpt has cyclomatic complexity 16 (threshold 15). Of this number, 8 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cli.go"},"region":{"startLine":436}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e8c17008acb81c2e015a7f7009d71b98e831faa43528308135b1dda87907327"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runFlashAppliance (cyclomatic 16): cli.runFlashAppliance has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4bb81a575fbb09320e83b6993bba9f730efd34873c14955afc06bbff5fc6984"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runConfigureSynology (cyclomatic 16): cli.runConfigureSynology has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-synology.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"e921bf96d66643193531090ec03563f905ac18189bb9697ccbe86b6c518e4b11"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runDNSQuery (cyclomatic 16): cli.runDNSQuery has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-query.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ef539991d69323d4a5e460f3e707a0645f323ee47a020e08259306a77a27dda"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runDNSStatus (cyclomatic 16): cli.runDNSStatus has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-status.go"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ed0a3dc5e037485c296fdcf692a8ac20810aa289d07ae1a68e4cce80c4b9bed"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.runFileGetOneBatch (cyclomatic 16): cli.runFileGetOneBatch has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":710}}}],"partialFingerprints":{"codehealthFindingId/v1":"17b02cac1fffae021b5f386d97876870f53bf9bfc8fc91c9a66b697b67fcd080"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.switchProfile (cyclomatic 16): cli.switchProfile has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/switch.go"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd2e0a547f9b9a235822c73aacbbf359b31cf84cbb604b527dbcc84f5d52c70d"}},{"ruleId":"D1","level":"warning","message":{"text":"cli.decodePlistValue (cyclomatic 16): cli.decodePlistValue has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance_darwin.go"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8720c6e6579e183ffd610445cad16b6595124459070fe6f487e5e5d1d4f8ff2"}},{"ruleId":"D1","level":"warning","message":{"text":"serveEnv.handleWebServe (cyclomatic 16): serveEnv.handleWebServe has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":318}}}],"partialFingerprints":{"codehealthFindingId/v1":"42f2b2795bbf2d0f4491a78781bc8174582d92e8d263d5928a86072a074e2e8c"}},{"ruleId":"D1","level":"warning","message":{"text":"main.tryEngine (cyclomatic 16): main.tryEngine has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":791}}}],"partialFingerprints":{"codehealthFindingId/v1":"de7604f8e9b9ef5c4334e0851d0ca6c741ab24909f752dbe11bb00b794d82319"}},{"ruleId":"D1","level":"warning","message":{"text":"mapSession.handleNonKeepAliveMapResponse (cyclomatic 16): mapSession.handleNonKeepAliveMapResponse has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa03ca4b5ffe7ed8083f69a8fa6a1319fd0239f6d98612ae56321b12674de778"}},{"ruleId":"D1","level":"warning","message":{"text":"controlhttpserver.acceptHTTP (cyclomatic 16): controlhttpserver.acceptHTTP has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/controlhttpserver/controlhttpserver.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c421c9800f4c1fa2b48066d10995a301bebd84fa172b753c48bcaff733d2ac0"}},{"ruleId":"D1","level":"warning","message":{"text":"taildrop.serveFiles (cyclomatic 16): taildrop.serveFiles has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/localapi.go"},"region":{"startLine":403}}}],"partialFingerprints":{"codehealthFindingId/v1":"529a9ea8365370c2f065c7c321cb4a38606237d0a8ad7d85f112c792d2fec53a"}},{"ruleId":"D1","level":"warning","message":{"text":"Builder.waitForImportSnapshot (cyclomatic 16): Builder.waitForImportSnapshot has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"gokrazy/build/build.go"},"region":{"startLine":452}}}],"partialFingerprints":{"codehealthFindingId/v1":"d61a21303b31e23e6e330df6de1e38f7f52238677ba7f4c3d5193d94addc577c"}},{"ruleId":"D1","level":"warning","message":{"text":"expiryManager.nextPeerExpiry (cyclomatic 16): expiryManager.nextPeerExpiry has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/expiry.go"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"d11c55b15d6848a6f0119c258c3ad102335cefc3331c4aa2d3d13f2b98e162ef"}},{"ruleId":"D1","level":"warning","message":{"text":"LocalBackend.checkEditPrefsAccessLocked (cyclomatic 16): LocalBackend.checkEditPrefsAccessLocked has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":5185}}}],"partialFingerprints":{"codehealthFindingId/v1":"63afdd85060a17380f437ebd7ed4fe4ec63acd065250db8386fed9664316aaef"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.serveProfiles (cyclomatic 16): Handler.serveProfiles has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":1534}}}],"partialFingerprints":{"codehealthFindingId/v1":"4dd1d759fb1d0eddd2f9d930dadb1bff080963b7c4cb93da7b2419106ed9c170"}},{"ruleId":"D1","level":"warning","message":{"text":"githook.appendLargeAdditions (cyclomatic 16): githook.appendLargeAdditions has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"misc/git_hook/githook/largefiles.go"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"91fc35d3a036e4182aabef51f500c945e21e2e7bff39495000bc90c50f0e1a47"}},{"ruleId":"D1","level":"warning","message":{"text":"Parsed.decode6 (cyclomatic 16): Parsed.decode6 has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":268}}}],"partialFingerprints":{"codehealthFindingId/v1":"b381a078515ff29d790068ba1ab10d1e1814026cce0749dcd80f5f6536957a88"}},{"ruleId":"D1","level":"warning","message":{"text":"Wrapper.Read (cyclomatic 16): Wrapper.Read has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":871}}}],"partialFingerprints":{"codehealthFindingId/v1":"861e26b1abdaa3fed3fba92d58788eb62babeb50e18f5c19373d9086b91c651c"}},{"ruleId":"D1","level":"warning","message":{"text":"portlist.appendParsePortsNetstat (cyclomatic 16): portlist.appendParsePortsNetstat has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/netstat.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"f59b93d46bb4cdba732f86aa87e25f79d1bdf54ae7247a6b417eb51fdb55f623"}},{"ruleId":"D1","level":"warning","message":{"text":"chonktest.RunChonkTests (cyclomatic 16): chonktest.RunChonkTests has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 94, 143, 55, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/chonktest/chonktest.go"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"08ce5f788d90b28c465f6307c53390fd3773d7cba6e99aafc6ad8f60d02c2e14"}},{"ruleId":"D1","level":"warning","message":{"text":"LogCatcher.ServeHTTP (cyclomatic 16): LogCatcher.ServeHTTP has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/integration.go"},"region":{"startLine":421}}}],"partialFingerprints":{"codehealthFindingId/v1":"8023d0d0788c52f5dd747e4d18d3b03f0e90225e9dbd7a326c49d9ae4a22b639"}},{"ruleId":"D1","level":"warning","message":{"text":"Env.ApproveRoutes (cyclomatic 16): Env.ApproveRoutes has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":1122}}}],"partialFingerprints":{"codehealthFindingId/v1":"c098bff08020b9c373269809619d791d1c04e40b43996db5bfa8a8d6ebe35a1e"}},{"ruleId":"D1","level":"warning","message":{"text":"Point.EqualApprox (cyclomatic 16): Point.EqualApprox has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/geo/point.go"},"region":{"startLine":272}}}],"partialFingerprints":{"codehealthFindingId/v1":"55d9cdc38bbd5ebf4a64942b89ac6720b1a40f21e44468d09954d6221c9107ad"}},{"ruleId":"D1","level":"warning","message":{"text":"version.parse (cyclomatic 16): version.parse has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/cmp.go"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b7be569021e29c174d91ea63851ffa21eca4c79924207eef8d2b40ce215a5eb"}},{"ruleId":"D1","level":"warning","message":{"text":"version.isValidLongWithTwoRepos (cyclomatic 16): version.isValidLongWithTwoRepos has cyclomatic complexity 16 (threshold 15). Of this number, 10 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/version.go"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"3bea28e058ee307438c4b6aa6ff83f04c0f1de6edc8347a64e0fc1ece0c2ca1c"}},{"ruleId":"D1","level":"warning","message":{"text":"magicsock.NewConn (cyclomatic 16): magicsock.NewConn has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":644}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a6f0da0e72e7e2ded854962a982c145d9ea64d480c210ca2c656ebbd281e2bc"}},{"ruleId":"D1","level":"warning","message":{"text":"endpoint.handlePongConnLocked (cyclomatic 16): endpoint.handlePongConnLocked has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1718}}}],"partialFingerprints":{"codehealthFindingId/v1":"366b3c82445bd7644852ed6e7d8668c2f4c107f7a7ffc2f49533b01d8e274b85"}},{"ruleId":"D1","level":"warning","message":{"text":"relayManager.handleRxDiscoMsgRunLoop (cyclomatic 16): relayManager.handleRxDiscoMsgRunLoop has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":584}}}],"partialFingerprints":{"codehealthFindingId/v1":"a792a27620d3a38f1e7567d765119f621fba9eda4b6f20c3b75bbd5c6239d04e"}},{"ruleId":"D1","level":"warning","message":{"text":"Impl.forwardUDP (cyclomatic 16): Impl.forwardUDP has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":2028}}}],"partialFingerprints":{"codehealthFindingId/v1":"85c775f279d97bded31f9e4ed421459f49a024f2cc0b62756a8fb4980d8ed079"}},{"ruleId":"D1","level":"warning","message":{"text":"PolicyLock.lockSlow (cyclomatic 16): PolicyLock.lockSlow has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 5 of the 16 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 192, 171). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/gp/policylock_windows.go"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"bccb817ec035b0730a37cf3f289572e6a1efa9ced573513793a129d13ab7dead"}},{"ruleId":"D1","level":"warning","message":{"text":"UniqueProcess.AsRestartableProcess (cyclomatic 16): UniqueProcess.AsRestartableProcess has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/restartmgr_windows.go"},"region":{"startLine":296}}}],"partialFingerprints":{"codehealthFindingId/v1":"625189c1896f4e4e12f338f8d62bf934f54136fd1b33b4951a64ecaf1e1ca007"}},{"ruleId":"D2","level":"warning","message":{"text":"main.genView (cognitive 147): main.genView has cognitive complexity 147 (threshold 15). Drivers by points: if/else 100, match/switch 38, boolean chains 7, loops 2 (nesting depth added 91). Of this number, 144 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/viewer/viewer.go"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"79b63a84c23d3d1035388769a1c7aceeeeb635a1a30c1d684e5fc06fe60caa7b"}},{"ruleId":"D2","level":"warning","message":{"text":"controlclient.peerChangeDiff (cognitive 143): controlclient.peerChangeDiff has cognitive complexity 143 (threshold 15). Drivers by points: if/else 123, boolean chains 10, loops 8, match/switch 2 (nesting depth added 86). Of this number, 142 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":990}}}],"partialFingerprints":{"codehealthFindingId/v1":"84a0294b04ee83f71357f32cbe440f5a247c38f9d99e8e73d7d7603c8212db4d"}},{"ruleId":"D2","level":"warning","message":{"text":"main.run (cognitive 126): main.run has cognitive complexity 126 (threshold 15). Drivers by points: if/else 109, boolean chains 7, match/switch 6, loops 4 (nesting depth added 55). Of this number, 108 points are the body\u0027s own statements and 18 belong to 5 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/k8s-proxy.go"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"32353aa999b034a5d9ac3ef35d618c1208cbf3302253753b409063e2d8e5306c"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runUp (cognitive 126): cli.runUp has cognitive complexity 126 (threshold 15). Drivers by points: if/else 107, boolean chains 9, match/switch 9, loops 1 (nesting depth added 58). Of this number, 61 points are the body\u0027s own statements and 65 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":500}}}],"partialFingerprints":{"codehealthFindingId/v1":"a47adfda7865afa3491099e87bf43e488620592f978f4a412a5d36bb64a6f18b"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.ensureConfigSecretsCreated (cognitive 107): ProxyGroupReconciler.ensureConfigSecretsCreated has cognitive complexity 107 (threshold 15). Drivers by points: if/else 96, loops 8, boolean chains 3 (nesting depth added 70). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":761}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bf0f7b9d0797f6ef3f844bfd5a0e76fe38c03689e028e7fc23bb4e6391cfece"}},{"ruleId":"D2","level":"warning","message":{"text":"main.runTests (cognitive 105): main.runTests has cognitive complexity 105 (threshold 15). Drivers by points: if/else 75, loops 22, match/switch 5, boolean chains 3 (nesting depth added 67). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"3fa8cee6a7fda5159ab584d6598216cad89033461d454c473c28588c9d8f6cfd"}},{"ruleId":"D2","level":"warning","message":{"text":"forwarder.forwardWithDestChan (cognitive 101): forwarder.forwardWithDestChan has cognitive complexity 101 (threshold 15). Drivers by points: if/else 68, match/switch 22, loops 10, boolean chains 1 (nesting depth added 63). Of this number, 89 points are the body\u0027s own statements and 12 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":1163}}}],"partialFingerprints":{"codehealthFindingId/v1":"1789948570fafdfde79585d1aab4e0789b9ff4abb5462009e88bb62b6ec01448"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serveMap (cognitive 95): Server.serveMap has cognitive complexity 95 (threshold 15). Drivers by points: if/else 84, boolean chains 4, loops 3, match/switch 3, jumps 1 (nesting depth added 51). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1390}}}],"partialFingerprints":{"codehealthFindingId/v1":"441db8c965702a012088040b75a84e5526b2749515027268cd4a833af7b12a6e"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxRouter.setNetfilterModeLocked (cognitive 94): linuxRouter.setNetfilterModeLocked has cognitive complexity 94 (threshold 15). Drivers by points: if/else 84, match/switch 7, boolean chains 2, loops 1 (nesting depth added 56). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":745}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f557488a8c2fafdedfb423a08c16a96fb09a963930abb8e66960be74017ff3f"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.setControlClientStatusLocked (cognitive 93): LocalBackend.setControlClientStatusLocked has cognitive complexity 93 (threshold 15). Drivers by points: if/else 81, boolean chains 9, loops 3 (nesting depth added 35). Of this number, 90 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1824}}}],"partialFingerprints":{"codehealthFindingId/v1":"9455c62b491ddf960861c86be08726957704f22a8d91808c346cc3796f25cb84"}},{"ruleId":"D2","level":"warning","message":{"text":"internal.Complete (cognitive 91): internal.Complete has cognitive complexity 91 (threshold 15). Drivers by points: if/else 70, loops 15, boolean chains 5, jumps 1 (nesting depth added 48). Of this number, 74 points are the body\u0027s own statements and 17 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ffcomplete/internal/complete.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"3eb06154308f77fe1840cd311d19fc955ed99faec5d302252b4c73876b4a26c5"}},{"ruleId":"D2","level":"warning","message":{"text":"Direct.sendMapRequest (cognitive 91): Direct.sendMapRequest has cognitive complexity 91 (threshold 15). Drivers by points: if/else 73, boolean chains 8, loops 5, match/switch 5 (nesting depth added 28). Of this number, 87 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":1062}}}],"partialFingerprints":{"codehealthFindingId/v1":"56867369fc08dcded294b726742e586a32a4bd154a3963371084c1b5b3d3c1f9"}},{"ruleId":"D2","level":"warning","message":{"text":"mapSession.updateStateFromResponse (cognitive 91): mapSession.updateStateFromResponse has cognitive complexity 91 (threshold 15). Drivers by points: if/else 68, loops 20, boolean chains 3 (nesting depth added 46). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":600}}}],"partialFingerprints":{"codehealthFindingId/v1":"078af0120cebdc9519785d315e3db3347fabe9590b69915fd15020bb9771bb4b"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.handleDiscoMessage (cognitive 91): Conn.handleDiscoMessage has cognitive complexity 91 (threshold 15). Drivers by points: if/else 83, boolean chains 6, match/switch 2 (nesting depth added 34). Of this number, 89 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":2193}}}],"partialFingerprints":{"codehealthFindingId/v1":"c73f3b06452aca7beab50c2bc59412fdec4100e35e17fc8e3e47ae5110fdceb8"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.configureInterface (cognitive 91): osrouter.configureInterface has cognitive complexity 91 (threshold 15). Drivers by points: if/else 67, boolean chains 16, loops 4, match/switch 4 (nesting depth added 32). Of this number, 77 points are the body\u0027s own statements and 14 belong to 2 function literals inside it that branch. This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"4dc0e2b408542e3ce9c936fb8390d89727749de413de2847ed76b5786a211a1a"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn25.mapDNSResponse (cognitive 88): Conn25.mapDNSResponse has cognitive complexity 88 (threshold 15). Drivers by points: if/else 79, loops 5, boolean chains 2, match/switch 2 (nesting depth added 51). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1148}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0d0df74795fc88e5edfd0242979049b92b2faac01ce48b3698c9b0b6d250476"}},{"ruleId":"D2","level":"warning","message":{"text":"Reconciler.validate (cognitive 88): Reconciler.validate has cognitive complexity 88 (threshold 15). Drivers by points: if/else 82, loops 4, boolean chains 2 (nesting depth added 57). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/proxyclass/proxyclass.go"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e9f795ebfe2000cc440d1803a60f52cecbaa95e9c70f980047df97d407643b8"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.createOrGetMapping (cognitive 85): Client.createOrGetMapping has cognitive complexity 85 (threshold 15). Drivers by points: if/else 75, boolean chains 6, match/switch 3, loops 1 (nesting depth added 40). Of this number, 80 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/portmapper.go"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc54b2df5e59acbe2a985b9f63911e22dde4eb4391a294f96f1bd026558ae6f6"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.runServeGetConfig (cognitive 82): serveEnv.runServeGetConfig has cognitive complexity 82 (threshold 15). Drivers by points: if/else 77, loops 3, boolean chains 2 (nesting depth added 45). Of this number, 24 points are the body\u0027s own statements and 58 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":661}}}],"partialFingerprints":{"codehealthFindingId/v1":"80d6edfbcf5647501608ba713d02399e4b9f8f330f73a2aa5bdab8db22fe372d"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runCp (cognitive 80): cli.runCp has cognitive complexity 80 (threshold 15). Drivers by points: if/else 72, boolean chains 6, loops 2 (nesting depth added 36). Of this number, 66 points are the body\u0027s own statements and 14 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"45ed74fceade5fe0cc813ce13e038b440d7583db41f8f3dc5056b273fa44baaa"}},{"ruleId":"D2","level":"warning","message":{"text":"main.runMTSServer (cognitive 80): main.runMTSServer has cognitive complexity 80 (threshold 15). Drivers by points: if/else 65, loops 14, match/switch 1 (nesting depth added 46). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/mts/mts.go"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"022345cae7807ce2c2e179ef64d192794dffc3c825a158e103cf41c88df1710a"}},{"ruleId":"D2","level":"warning","message":{"text":"Menu.rebuildExitNodeMenu (cognitive 79): Menu.rebuildExitNodeMenu has cognitive complexity 79 (threshold 15). Drivers by points: if/else 49, loops 24, boolean chains 5, match/switch 1 (nesting depth added 48). Of this number, 78 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":604}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4faafa65aef2777d88b6e7768ede7b62fa5afb4ac4d67a375cd3a5a94e8f68c"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runStatus (cognitive 78): cli.runStatus has cognitive complexity 78 (threshold 15). Drivers by points: if/else 63, loops 8, boolean chains 7 (nesting depth added 27). Of this number, 52 points are the body\u0027s own statements and 26 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/status.go"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c3a8d8e927a6a43bafa466157f29ec3e42d6093b5c52a408375326d59be8f96"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveDebugDERPRegion (cognitive 78): Handler.serveDebugDERPRegion has cognitive complexity 78 (threshold 15). Drivers by points: if/else 66, loops 7, boolean chains 3, match/switch 2 (nesting depth added 29). Of this number, 34 points are the body\u0027s own statements and 44 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debugderp.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"cef9ba1a765f0e4c05dfe82da6af973510280663eb7f33a36c3f42bdc4d2f24c"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.GetReport (cognitive 76): Client.GetReport has cognitive complexity 76 (threshold 15). Drivers by points: if/else 55, boolean chains 13, loops 7, match/switch 1 (nesting depth added 27). Of this number, 52 points are the body\u0027s own statements and 24 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":828}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4914db0607437f0500578f36481cace25e2b7415249cae08357b15d6952d309"}},{"ruleId":"D2","level":"warning","message":{"text":"derpProber.probeMapFn (cognitive 76): derpProber.probeMapFn has cognitive complexity 76 (threshold 15). Drivers by points: if/else 63, loops 11, boolean chains 2 (nesting depth added 53). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"e13750de2a793fb040edc826b4501e008598ac655d1bb24684c89a8dec504851"}},{"ruleId":"D2","level":"warning","message":{"text":"Env.Start (cognitive 76): Env.Start has cognitive complexity 76 (threshold 15). Drivers by points: if/else 65, loops 11 (nesting depth added 41). Of this number, 27 points are the body\u0027s own statements and 49 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":633}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7b954286935ba57de72f2a42e49689b47c9754965f027ebb3ea559920c15310"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.setNetMapLocked (cognitive 74): LocalBackend.setNetMapLocked has cognitive complexity 74 (threshold 15). Drivers by points: if/else 57, loops 11, boolean chains 6 (nesting depth added 25). Of this number, 72 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":7271}}}],"partialFingerprints":{"codehealthFindingId/v1":"03822ac079017cf7bfba0ebb4c914c018ba4dc689d4eda64febdd063cf9ded86"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.formatDNSStatusText (cognitive 69): cli.formatDNSStatusText has cognitive complexity 69 (threshold 15). Drivers by points: if/else 47, loops 22 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-status.go"},"region":{"startLine":190}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2ea29b94e26727c9e91ec22f64b56d40d03035292d362d561b58cefc9f5ea6f"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.runServeCombined (cognitive 68): serveEnv.runServeCombined has cognitive complexity 68 (threshold 15). Drivers by points: if/else 53, boolean chains 13, loops 2 (nesting depth added 17). Most of this is not in the body itself: 0 of the 68 points are its own statements and the rest belongs to one function literal inside it that branches (line 376). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":373}}}],"partialFingerprints":{"codehealthFindingId/v1":"08c31e189ce3c17e1b2235ac68d0c953bd0d6837dd2233e7fad9f1c70ba77476"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 67): main.main has cognitive complexity 67 (threshold 15). Drivers by points: if/else 57, loops 7, boolean chains 2, match/switch 1 (nesting depth added 13). Of this number, 21 points are the body\u0027s own statements and 46 belong to 15 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tta/tta.go"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"64a892076aa4c231a55932127fa61ed3ff34760d2573f3dd35cec1ad6ea6e751"}},{"ruleId":"D2","level":"warning","message":{"text":"nlConn.Receive (cognitive 67): nlConn.Receive has cognitive complexity 67 (threshold 15). Drivers by points: if/else 62, boolean chains 4, match/switch 1 (nesting depth added 34). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon_linux.go"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"20d816ac078499a0bf30fa600541c23bf7473eb1c822bbe92f8351920004822b"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.runServeSetConfig (cognitive 66): serveEnv.runServeSetConfig has cognitive complexity 66 (threshold 15). Drivers by points: if/else 53, loops 8, boolean chains 5 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":854}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b236ecc0d399a330cf02fcb5063f2849360e2a703fc2456b858fb4733aa865c"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.Probe (cognitive 66): Client.Probe has cognitive complexity 66 (threshold 15). Drivers by points: if/else 52, match/switch 11, boolean chains 2, loops 1 (nesting depth added 32). Of this number, 54 points are the body\u0027s own statements and 12 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/portmapper.go"},"region":{"startLine":875}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b73ab2fd6518fbb3a1782228bead314cbe8163aeb1dbc4c9d6a7e2ff940280e"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 65): main.main has cognitive complexity 65 (threshold 15). Drivers by points: if/else 53, boolean chains 6, loops 6 (nesting depth added 27). Of this number, 59 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":738}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7c19315ae8a16a6effceff37a1c5fbbe8a2e04db82ec9d7576ce4ed08686329"}},{"ruleId":"D2","level":"warning","message":{"text":"Direct.doLogin (cognitive 63): Direct.doLogin has cognitive complexity 63 (threshold 15). Drivers by points: if/else 57, boolean chains 5, match/switch 1 (nesting depth added 11). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":663}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6f118bd1c17627b7e1199d524ebde34cb3489a9ce509f6b8df8805d0d2de84a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 62): main.main has cognitive complexity 62 (threshold 15). Drivers by points: if/else 55, boolean chains 4, match/switch 3 (nesting depth added 20). Of this number, 39 points are the body\u0027s own statements and 23 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/derper.go"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e01696f2f020be02b03ef6401442ae9cb22090f65ceaed0e29c0abb3a9fb726"}},{"ruleId":"D2","level":"warning","message":{"text":"safediff.Lines (cognitive 62): safediff.Lines has cognitive complexity 62 (threshold 15). Drivers by points: if/else 24, loops 21, match/switch 9, boolean chains 8 (nesting depth added 28). Of this number, 46 points are the body\u0027s own statements and 16 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/safediff/diff.go"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"138d69cbdd4ae7d0e8b064da74f0cc8f354baf767aa3343b7b690564ab19a09e"}},{"ruleId":"D2","level":"warning","message":{"text":"settings.validate (cognitive 61): settings.validate has cognitive complexity 61 (threshold 15). Drivers by points: if/else 36, boolean chains 25 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/settings.go"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5f4aeeb1a709641c869b2de018c7c931cedd5c778f567fd76354f2721130b09"}},{"ruleId":"D2","level":"warning","message":{"text":"connector.handleDNS (cognitive 60): connector.handleDNS has cognitive complexity 60 (threshold 15). Drivers by points: if/else 46, loops 9, boolean chains 3, match/switch 2 (nesting depth added 32). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/natc/natc.go"},"region":{"startLine":351}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbc1862f4c90987f5fc431fb64c19f9f58b472ef24cb8db0aa6657b4416fd436"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.connect (cognitive 60): Client.connect has cognitive complexity 60 (threshold 15). Drivers by points: if/else 51, match/switch 5, boolean chains 4 (nesting depth added 19). Of this number, 50 points are the body\u0027s own statements and 10 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0bcebdb05b44f22d667bbecab01cbecc8b6535191472056f3c1943d66cdd6a1"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.startLocked (cognitive 59): LocalBackend.startLocked has cognitive complexity 59 (threshold 15). Drivers by points: if/else 47, boolean chains 9, loops 3 (nesting depth added 15). Of this number, 57 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3031}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f1d77f4d43311e8f8881b0f3fda8d718be5f55505b9cf3074ebd3901293ab1f"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.markAncestorIntersectionAUMs (cognitive 59): tka.markAncestorIntersectionAUMs has cognitive complexity 59 (threshold 15). Drivers by points: if/else 42, loops 15, boolean chains 1, jumps 1 (nesting depth added 37). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tailchonk.go"},"region":{"startLine":800}}}],"partialFingerprints":{"codehealthFindingId/v1":"31bed396bda1d1d474295a41c2fb3fffeb338492d05f404408292875d0d4bc5d"}},{"ruleId":"D2","level":"warning","message":{"text":"wgengine.NewUserspaceEngine (cognitive 58): wgengine.NewUserspaceEngine has cognitive complexity 58 (threshold 15). Drivers by points: if/else 50, boolean chains 6, loops 1, match/switch 1 (nesting depth added 11). Of this number, 41 points are the body\u0027s own statements and 17 belong to 8 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":303}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c4ae02ccc4782b8d03b806b755535960bc78e337e62a75e2cef46ced2959feb"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxRouter.Set (cognitive 58): linuxRouter.Set has cognitive complexity 58 (threshold 15). Drivers by points: if/else 49, boolean chains 3, loops 3, match/switch 3 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":436}}}],"partialFingerprints":{"codehealthFindingId/v1":"459467106ba0cefa5a341c7573e53537615cf1dff4a0a03ae0834d164440fc87"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 57): main.main has cognitive complexity 57 (threshold 15). Drivers by points: if/else 50, boolean chains 3, loops 3, match/switch 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d207ed5e3b88d0b068ac4793ceb037120d5df17bc0f66c8377151b745a1eb63"}},{"ruleId":"D2","level":"warning","message":{"text":"Options.init (cognitive 57): Options.init has cognitive complexity 57 (threshold 15). Drivers by points: if/else 47, boolean chains 5, loops 3, match/switch 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"971318f50d9c2b5d21194ecaa9849aa94c0d6f89dabda309a52e8fca8c3afde4"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 57): main.main has cognitive complexity 57 (threshold 15). Drivers by points: if/else 43, loops 6, boolean chains 5, jumps 3 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/listpkgs/listpkgs.go"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7736f8bf41db2b55e52e411fe52b1f951948ee0f47157bbbae79414cad72d8f"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.shouldProcessInbound (cognitive 57): Impl.shouldProcessInbound has cognitive complexity 57 (threshold 15). Drivers by points: if/else 48, boolean chains 9 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1209}}}],"partialFingerprints":{"codehealthFindingId/v1":"9974198b46e19bd8a44210587c7d16a7f621dc69a3e7574af5d7d073d9df9279"}},{"ruleId":"D2","level":"warning","message":{"text":"s4u.startProcessInternal (cognitive 57): s4u.startProcessInternal has cognitive complexity 57 (threshold 15). Drivers by points: if/else 50, boolean chains 5, match/switch 2 (nesting depth added 19). Of this number, 54 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/s4u/s4u_windows.go"},"region":{"startLine":364}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf1ab052ddefc1c034525682de989d87e2082c1c0bad7f578a012e7c113de300"}},{"ruleId":"D2","level":"warning","message":{"text":"tailscaleSTSReconciler.provisionSecrets (cognitive 56): tailscaleSTSReconciler.provisionSecrets has cognitive complexity 56 (threshold 15). Drivers by points: if/else 49, loops 4, boolean chains 3 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"685732ca004a23c0669bd7dd1863349e18f1106ba248b1772d19efc99f49c3c7"}},{"ruleId":"D2","level":"warning","message":{"text":"main.printMessage (cognitive 56): main.printMessage has cognitive complexity 56 (threshold 15). Drivers by points: if/else 27, loops 13, match/switch 11, boolean chains 5 (nesting depth added 21). Of this number, 36 points are the body\u0027s own statements and 20 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/netlogfmt/main.go"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8a4430398fbede448eb57f748239a77a588d125d33921d2fb77131f07c2f664"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 56): main.main has cognitive complexity 56 (threshold 15). Drivers by points: if/else 33, match/switch 18, loops 3, boolean chains 2 (nesting depth added 22). Of this number, 47 points are the body\u0027s own statements and 9 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":922}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bd61e01ee05042cedba4d1cba4dcfe95f7132d5cea84311b810af4a08a7ff8f"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.UpdateNetmapDelta (cognitive 56): LocalBackend.UpdateNetmapDelta has cognitive complexity 56 (threshold 15). Drivers by points: if/else 33, loops 11, boolean chains 7, match/switch 5 (nesting depth added 21). Of this number, 55 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":2415}}}],"partialFingerprints":{"codehealthFindingId/v1":"32769fde6532ec820587d2b48d93e422d63b8e41b8b043b0c3e5ed77a9c6dec1"}},{"ruleId":"D2","level":"warning","message":{"text":"tlsdial.Config (cognitive 56): tlsdial.Config has cognitive complexity 56 (threshold 15). Drivers by points: if/else 51, boolean chains 4, loops 1 (nesting depth added 18). Most of this is not in the body itself: 11 of the 56 points are its own statements and the rest belongs to one function literal inside it that branches (line 115). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tlsdial/tlsdial.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"565fadebbccb43e63d1e97d5e27508b7c16018311f51c6347f997ed58402dbec"}},{"ruleId":"D2","level":"warning","message":{"text":"main.getFieldComments (cognitive 53): main.getFieldComments has cognitive complexity 53 (threshold 15). Drivers by points: if/else 34, loops 16, boolean chains 3 (nesting depth added 36). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/viewer/viewer.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"e12abdd0238c7d7a709cf1737863b8a6b5ef452bf3153708b4f372ebfa6b37f8"}},{"ruleId":"D2","level":"warning","message":{"text":"mapSession.updatePeersStateFromResponse (cognitive 53): mapSession.updatePeersStateFromResponse has cognitive complexity 53 (threshold 15). Drivers by points: if/else 44, loops 9 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":782}}}],"partialFingerprints":{"codehealthFindingId/v1":"35c1c26dee64457604327e00d83fe6ae4cb6a086bfe1f72e4ba28038e8ec298d"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.WatchNotificationsAs (cognitive 53): LocalBackend.WatchNotificationsAs has cognitive complexity 53 (threshold 15). Drivers by points: if/else 49, boolean chains 4 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3723}}}],"partialFingerprints":{"codehealthFindingId/v1":"85b54c38ece11ea21c5e4afc4e93ad0fd8e505d37bdf7c82e0af567000aa84e4"}},{"ruleId":"D2","level":"warning","message":{"text":"Mutation.Commit (cognitive 53): Mutation.Commit has cognitive complexity 53 (threshold 15). Drivers by points: if/else 38, loops 9, match/switch 4, boolean chains 2 (nesting depth added 27). Of this number, 50 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":511}}}],"partialFingerprints":{"codehealthFindingId/v1":"126a91bd9fe8fdb09fc39084fbbd2f9107d5e9ffa558f65f46e27a53fc501fe9"}},{"ruleId":"D2","level":"warning","message":{"text":"Tracker.updateBuiltinWarnablesLocked (cognitive 52): Tracker.updateBuiltinWarnablesLocked has cognitive complexity 52 (threshold 15). Drivers by points: if/else 39, boolean chains 7, loops 6 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"health/health.go"},"region":{"startLine":1104}}}],"partialFingerprints":{"codehealthFindingId/v1":"b08e82c8da769ea5c8b4968734910eb998d44b0e58e7ba54e674eb96902b5dae"}},{"ruleId":"D2","level":"warning","message":{"text":"main.gen (cognitive 51): main.gen has cognitive complexity 51 (threshold 15). Drivers by points: if/else 44, boolean chains 4, match/switch 2, loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/cloner/cloner.go"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"62914bb50b42d012dbec7a4e4fb3c0fdafb51540a3a0bd19b92c6192cc0d6738"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runPing (cognitive 51): cli.runPing has cognitive complexity 51 (threshold 15). Drivers by points: if/else 46, boolean chains 4, loops 1 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ping.go"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d86f33a556160bdeabfda183824bfce39be90b88294f8ab4da75097ffd2a144"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 51): main.main has cognitive complexity 51 (threshold 15). Drivers by points: if/else 43, boolean chains 8 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"63c5e93d3f5b40c8d62bd575b3fe17effc836b8045e8f91d81413fb311e80800"}},{"ruleId":"D2","level":"warning","message":{"text":"nodeBackend.UpdateNetmapDelta (cognitive 51): nodeBackend.UpdateNetmapDelta has cognitive complexity 51 (threshold 15). Drivers by points: if/else 36, loops 13, match/switch 2 (nesting depth added 34). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1084}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1d55e59a6e2d5c4987978d4a518b4ae73852cb11245ed8bb99684ba0b335df4"}},{"ruleId":"D2","level":"warning","message":{"text":"nmManager.GetBaseConfig (cognitive 51): nmManager.GetBaseConfig has cognitive complexity 51 (threshold 15). Drivers by points: if/else 40, loops 10, boolean chains 1 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nm.go"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"cae9db0bf9b01627950a9edb7257d2d4af2ec6dca865569b5fd014e7c9de1d63"}},{"ruleId":"D2","level":"warning","message":{"text":"resolvedManager.run (cognitive 51): resolvedManager.run has cognitive complexity 51 (threshold 15). Drivers by points: if/else 46, boolean chains 2, match/switch 2, loops 1 (nesting depth added 28). Of this number, 46 points are the body\u0027s own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolved.go"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"a77f8cf66cf5f5bd7ff662ba644fe4b6d9f8364b4f00efd23d546782518a6688"}},{"ruleId":"D2","level":"warning","message":{"text":"netcheck.makeProbePlan (cognitive 51): netcheck.makeProbePlan has cognitive complexity 51 (threshold 15). Drivers by points: if/else 39, boolean chains 9, loops 3 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"397c1a7cfa4a67048c0942f30320a0a4fb3f0e79045a53073f31ff890bac9d8f"}},{"ruleId":"D2","level":"warning","message":{"text":"Wrapper.filterPacketInboundFromWireGuard (cognitive 51): Wrapper.filterPacketInboundFromWireGuard has cognitive complexity 51 (threshold 15). Drivers by points: if/else 45, boolean chains 6 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":1097}}}],"partialFingerprints":{"codehealthFindingId/v1":"c842036479e24f28edcc1e31ef3bdca97b21e87171d58afdd8edbbf403157a5d"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.initFromConfig (cognitive 51): Server.initFromConfig has cognitive complexity 51 (threshold 15). Drivers by points: if/else 44, loops 5, boolean chains 2 (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/conf.go"},"region":{"startLine":476}}}],"partialFingerprints":{"codehealthFindingId/v1":"10dc34899ae4d97c9c2c051f9e87b436d3bde2ce261d5c5ac36de34f289aa961"}},{"ruleId":"D2","level":"warning","message":{"text":"filter.MatchesFromFilterRules (cognitive 51): filter.MatchesFromFilterRules has cognitive complexity 51 (threshold 15). Drivers by points: if/else 24, loops 24, boolean chains 3 (nesting depth added 30). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/tailcfg.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c6346480a9d0389b011d904353f1e858a3994054fbecf8bb9316c66d386adc5"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.recvTimeout (cognitive 50): Client.recvTimeout has cognitive complexity 50 (threshold 15). Drivers by points: if/else 46, match/switch 2, boolean chains 1, loops 1 (nesting depth added 28). Of this number, 49 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derp_client.go"},"region":{"startLine":499}}}],"partialFingerprints":{"codehealthFindingId/v1":"a86958dbfdeba537e00991e5d7c85c86e285959b49748ad7ba6f5d4d0974652f"}},{"ruleId":"D2","level":"warning","message":{"text":"prober.derpProbeBandwidthTUN (cognitive 50): prober.derpProbeBandwidthTUN has cognitive complexity 50 (threshold 15). Drivers by points: if/else 41, loops 6, match/switch 3 (nesting depth added 20). Most of this is not in the body itself: 11 of the 50 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 958, 1011, 1111, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":898}}}],"partialFingerprints":{"codehealthFindingId/v1":"40ed822d61551b67050781b857786cdd5832e717cc607e743aa6af61be4401b1"}},{"ruleId":"D2","level":"warning","message":{"text":"varz.writePromExpVar (cognitive 50): varz.writePromExpVar has cognitive complexity 50 (threshold 15). Drivers by points: if/else 30, match/switch 17, boolean chains 3 (nesting depth added 25). Of this number, 38 points are the body\u0027s own statements and 12 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/varz/varz.go"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c33f30934a3a9b6abd1f3efe8fb3f70cc72df8213e27e4a862b08a86e4cfb67"}},{"ruleId":"D2","level":"warning","message":{"text":"main.applyProxyClassToStatefulSet (cognitive 49): main.applyProxyClassToStatefulSet has cognitive complexity 49 (threshold 15). Drivers by points: if/else 34, boolean chains 8, loops 7 (nesting depth added 11). Of this number, 41 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":862}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb54bffe1497ffb007d57951ff7165bf8a96572c838096e6917a031adaf2770b"}},{"ruleId":"D2","level":"warning","message":{"text":"main.probeNodes (cognitive 49): main.probeNodes has cognitive complexity 49 (threshold 15). Drivers by points: if/else 27, loops 16, match/switch 6 (nesting depth added 29). Of this number, 40 points are the body\u0027s own statements and 9 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":580}}}],"partialFingerprints":{"codehealthFindingId/v1":"23c8dad03c456c5c297b91611c4b63f98d63241e774a4b350c74c3e8220d42d0"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runCert (cognitive 49): cli.runCert has cognitive complexity 49 (threshold 15). Drivers by points: if/else 44, boolean chains 3, match/switch 2 (nesting depth added 18). Of this number, 41 points are the body\u0027s own statements and 8 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cert.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"c51f641f2e6058ed09c77e844e324c01807daa1261cffb2a0d30e0cad407816a"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.RunWatchConnectionLoop (cognitive 49): Client.RunWatchConnectionLoop has cognitive complexity 49 (threshold 15). Drivers by points: if/else 35, match/switch 8, loops 4, boolean chains 2 (nesting depth added 24). Of this number, 41 points are the body\u0027s own statements and 8 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/mesh_client.go"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"7faa94111063caf5e3162ab1aa6811fd24f92b9990730a4a41aa2eb005e5374b"}},{"ruleId":"D2","level":"warning","message":{"text":"netmon.LocalAddresses (cognitive 49): netmon.LocalAddresses has cognitive complexity 49 (threshold 15). Drivers by points: if/else 38, boolean chains 5, loops 3, match/switch 3 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b80bb6bce70bdb35e89d73cbb40a9d3f4291479dc8b6d0c5085753b099f6ffa"}},{"ruleId":"D2","level":"warning","message":{"text":"State.InterfaceDiff (cognitive 49): State.InterfaceDiff has cognitive complexity 49 (threshold 15). Drivers by points: if/else 43, loops 4, boolean chains 2 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"84a97517ea16862e21828401967efb0c39895cc4893a3cdbe892ef3e1e484cc3"}},{"ruleId":"D2","level":"warning","message":{"text":"AppConnector.ObserveDNSResponse (cognitive 48): AppConnector.ObserveDNSResponse has cognitive complexity 48 (threshold 15). Drivers by points: if/else 40, loops 4, match/switch 4 (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"appc/observe.go"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"80fbd131f28349f60375a2848a831a25e5a5873ff020bc722fc87967aae5bcb2"}},{"ruleId":"D2","level":"warning","message":{"text":"main.measureICMPRTT (cognitive 48): main.measureICMPRTT has cognitive complexity 48 (threshold 15). Drivers by points: if/else 43, loops 3, boolean chains 2 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp_linux.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fe2e7b52e006ff670b77bd00786955957b77757cb43de7ece2fae561cb9b4f6"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runSet (cognitive 48): cli.runSet has cognitive complexity 48 (threshold 15). Drivers by points: if/else 41, boolean chains 4, loops 2, match/switch 1 (nesting depth added 14). Of this number, 47 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/set.go"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"64de60a67382f70465e5a6e45ef1750c0410807556f2b06871ca45aa9a819d60"}},{"ruleId":"D2","level":"warning","message":{"text":"lowerell.run (cognitive 48): lowerell.run has cognitive complexity 48 (threshold 15). Drivers by points: if/else 30, loops 14, boolean chains 2, match/switch 2 (nesting depth added 31). Most of this is not in the body itself: 1 of the 48 points is its own statement and the rest belongs to one function literal inside it that branches (line 65). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vet/lowerell/analyzer.go"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"064ade82c341defb17d4308af8c12ef4df912c81bcc8ebd34853ff2d7387a538"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.mkReceiveFunc (cognitive 48): Conn.mkReceiveFunc has cognitive complexity 48 (threshold 15). Drivers by points: if/else 43, loops 3, boolean chains 2 (nesting depth added 29). Most of this is not in the body itself: 0 of the 48 points are its own statements and the rest belongs to one function literal inside it that branches (line 1751). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1747}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ff4319a00a9fbd766da4ad2cd58d595d8d2431d6ace6acb09937299e637297a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.watchServeConfigChanges (cognitive 47): main.watchServeConfigChanges has cognitive complexity 47 (threshold 15). Drivers by points: if/else 42, boolean chains 2, match/switch 2, loops 1 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/serve.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"085e2eb8b63f1131d80aa020d060467819828b5347d667ae86f5235b0c8d1152"}},{"ruleId":"D2","level":"warning","message":{"text":"egressProxy.syncEgressConfigs (cognitive 47): egressProxy.syncEgressConfigs has cognitive complexity 47 (threshold 15). Drivers by points: if/else 37, loops 8, boolean chains 2 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"203303dc0dbe9ea8121dd995ae47dce0a6619470b4bd00f1cdeb0de26dadc0e0"}},{"ruleId":"D2","level":"warning","message":{"text":"sshSession.startNewRecording (cognitive 47): sshSession.startNewRecording has cognitive complexity 47 (threshold 15). Drivers by points: if/else 38, boolean chains 6, match/switch 3 (nesting depth added 18). Of this number, 33 points are the body\u0027s own statements and 14 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":1405}}}],"partialFingerprints":{"codehealthFindingId/v1":"f255ad88cee3d182185e1bebf70a52a4d9937da2cb5a9bdd5172923b22e50f41"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.dnsConfigForNetmap (cognitive 46): ipnlocal.dnsConfigForNetmap has cognitive complexity 46 (threshold 15). Drivers by points: if/else 33, loops 7, boolean chains 3, match/switch 3 (nesting depth added 13). Of this number, 38 points are the body\u0027s own statements and 8 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1444}}}],"partialFingerprints":{"codehealthFindingId/v1":"800ca0aaa77b17c64c20102571ae5250a1cde73767e76cae1e2233c93944e90c"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.runDerpReader (cognitive 46): Conn.runDerpReader has cognitive complexity 46 (threshold 15). Drivers by points: if/else 23, match/switch 18, loops 4, boolean chains 1 (nesting depth added 28). Of this number, 43 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":533}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d55a12c7f8a67d76efdad5a24fc91e1584dfb5065bd56e2cff03f7a358ce4ab"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.suggestExitNodeUsingDERP (cognitive 45): ipnlocal.suggestExitNodeUsingDERP has cognitive complexity 45 (threshold 15). Drivers by points: if/else 38, boolean chains 5, loops 2 (nesting depth added 15). Of this number, 40 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":8821}}}],"partialFingerprints":{"codehealthFindingId/v1":"9440ec8dc0e2690ecdd9d59917c1de27943e92bc5cc7b086759cb6a571382a50"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.updateStatusLocked (cognitive 45): LocalBackend.updateStatusLocked has cognitive complexity 45 (threshold 15). Drivers by points: if/else 34, loops 9, boolean chains 2 (nesting depth added 21). Most of this is not in the body itself: 10 of the 45 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1471, 1525). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1468}}}],"partialFingerprints":{"codehealthFindingId/v1":"801ec1ff07826f750d7b3a1701c976d0a70cc18bfa0a70fe0ca244bf6e860712"}},{"ruleId":"D2","level":"warning","message":{"text":"main.updatesForCfg (cognitive 44): main.updatesForCfg has cognitive complexity 44 (threshold 15). Drivers by points: loops 26, if/else 18 (nesting depth added 24). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"a61aae1e22ef2a383b76bb3d638d372d5db39df16df9d01fb87a1490c50e7462"}},{"ruleId":"D2","level":"warning","message":{"text":"main.mustFormatFile (cognitive 44): main.mustFormatFile has cognitive complexity 44 (threshold 15). Drivers by points: if/else 29, loops 9, match/switch 4, boolean chains 2 (nesting depth added 23). Of this number, 26 points are the body\u0027s own statements and 18 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/jsonimports/format.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fb6fcd8245d3e06a38add6754402ac077d0afcc4f3778b417b0a179d725255f"}},{"ruleId":"D2","level":"warning","message":{"text":"egressSvcsReconciler.provision (cognitive 44): egressSvcsReconciler.provision has cognitive complexity 44 (threshold 15). Drivers by points: if/else 35, loops 7, boolean chains 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services.go"},"region":{"startLine":280}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f196be1f8f4a46a60fda344b80a33d071a28b7beacdf0dcf0ff0d49e5a11ace"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.validateServeConfigUpdate (cognitive 44): ipnlocal.validateServeConfigUpdate has cognitive complexity 44 (threshold 15). Drivers by points: if/else 28, loops 10, boolean chains 6 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":1737}}}],"partialFingerprints":{"codehealthFindingId/v1":"e05b0310d83af7e56fc5f0b02404a7678e014d55cd2b9185c58064322e3b8cad"}},{"ruleId":"D2","level":"warning","message":{"text":"Prefs.pretty (cognitive 44): Prefs.pretty has cognitive complexity 44 (threshold 15). Drivers by points: if/else 36, boolean chains 8 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":546}}}],"partialFingerprints":{"codehealthFindingId/v1":"524c60834e0d124584925651cffe7e0b3d130b1b9ff1094ff0dbbe15e4de23f3"}},{"ruleId":"D2","level":"warning","message":{"text":"Table.Insert (cognitive 44): Table.Insert has cognitive complexity 44 (threshold 15). Drivers by points: if/else 41, match/switch 2, loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/art/table.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b0d430be8fed30d94b812292c49cc52dec573b36d38d71273b5f88ec9282b6b"}},{"ruleId":"D2","level":"warning","message":{"text":"sshSession.run (cognitive 44): sshSession.run has cognitive complexity 44 (threshold 15). Drivers by points: if/else 42, boolean chains 2 (nesting depth added 17). Of this number, 39 points are the body\u0027s own statements and 5 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":1006}}}],"partialFingerprints":{"codehealthFindingId/v1":"305a4d8ded8b12af85202346c1ddd33a4dacfe6e083f2a06185202178015a8b9"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.MapResponse (cognitive 44): Server.MapResponse has cognitive complexity 44 (threshold 15). Drivers by points: if/else 37, loops 6, boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1630}}}],"partialFingerprints":{"codehealthFindingId/v1":"134cae500fbd6f8d8dea0bcd51fceae7824c2fcfb652c3d93b92e9bbbe6308e2"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ServeUnixConn (cognitive 44): Server.ServeUnixConn has cognitive complexity 44 (threshold 15). Drivers by points: if/else 36, match/switch 6, boolean chains 1, loops 1 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1332}}}],"partialFingerprints":{"codehealthFindingId/v1":"e714cef79c7ef9bb711d294689418f353612f2cc0a0ae82a7e4c22799a4e622f"}},{"ruleId":"D2","level":"warning","message":{"text":"HAServiceReconciler.maybeProvision (cognitive 43): HAServiceReconciler.maybeProvision has cognitive complexity 43 (threshold 15). Drivers by points: if/else 36, boolean chains 3, loops 2, match/switch 2 (nesting depth added 10). Of this number, 42 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"ecaa044f30bb6e1a2c98aac80583c5b8263e47694e1e47a045affabae5414d99"}},{"ruleId":"D2","level":"warning","message":{"text":"conffile.loadConfigV0 (cognitive 43): conffile.loadConfigV0 has cognitive complexity 43 (threshold 15). Drivers by points: if/else 35, boolean chains 5, loops 3 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/conffile/serveconf.go"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"e847bbf58598f8d2237fd8778487d8c222863284cbc16f7fead4f5ea38984a08"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.routerConfigLocked (cognitive 43): LocalBackend.routerConfigLocked has cognitive complexity 43 (threshold 15). Drivers by points: if/else 27, boolean chains 8, match/switch 5, loops 3 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6514}}}],"partialFingerprints":{"codehealthFindingId/v1":"b85f30fb52c47d59def8b45e49fc7305f0edbc675409b8ff4df89079b9bc24b7"}},{"ruleId":"D2","level":"warning","message":{"text":"StatusBuilder.AddPeer (cognitive 43): StatusBuilder.AddPeer has cognitive complexity 43 (threshold 15). Drivers by points: if/else 40, boolean chains 3. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnstate/ipnstate.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"38a1dfafc5c02ae7a1a4eadf9251543fcb1f015d0465096812ee290d2353da9f"}},{"ruleId":"D2","level":"warning","message":{"text":"resolver.handleExitNodeDNSQueryWithNetPkg (cognitive 43): resolver.handleExitNodeDNSQueryWithNetPkg has cognitive complexity 43 (threshold 15). Drivers by points: if/else 40, loops 2, match/switch 1 (nesting depth added 19). Of this number, 39 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9fa00893b0e38709a17dbcf99a9a133c92be2dda371717bd710b200a775aeed"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serveRegister (cognitive 43): Server.serveRegister has cognitive complexity 43 (threshold 15). Drivers by points: if/else 35, boolean chains 6, match/switch 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":953}}}],"partialFingerprints":{"codehealthFindingId/v1":"55fc75ccb5bc9269a049795aaea673f36d2889b42d6e79d37db9e60b0e739796"}},{"ruleId":"D2","level":"warning","message":{"text":"extension.issueACMECert (cognitive 42): extension.issueACMECert has cognitive complexity 42 (threshold 15). Drivers by points: if/else 37, match/switch 3, loops 2 (nesting depth added 15). Of this number, 36 points are the body\u0027s own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/acme/cert.go"},"region":{"startLine":456}}}],"partialFingerprints":{"codehealthFindingId/v1":"946fefdf419d2902e5133a280ed73da3d87b5d88e2373cbd775f4a42a7d1b090"}},{"ruleId":"D2","level":"warning","message":{"text":"endpoint.send (cognitive 42): endpoint.send has cognitive complexity 42 (threshold 15). Drivers by points: if/else 32, boolean chains 4, loops 4, match/switch 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1046}}}],"partialFingerprints":{"codehealthFindingId/v1":"667cd5e2851473b9e7a177a9a8b70d3f9627ae27a27adc706068011dfbe9dc79"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 41): main.main has cognitive complexity 41 (threshold 15). Drivers by points: if/else 35, match/switch 3, loops 2, boolean chains 1 (nesting depth added 15). Of this number, 35 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/cigocacher/cigocacher.go"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa98850a50e806300721ca3188e91371f88603e2395f3c083f0fc6ac38933f28"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runIP (cognitive 41): cli.runIP has cognitive complexity 41 (threshold 15). Drivers by points: if/else 33, boolean chains 4, loops 4 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ip.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bcdea407352895366f53d481285926fada3380825e7ffe8519fc5ca6738bf95"}},{"ruleId":"D2","level":"warning","message":{"text":"idpServer.serveToken (cognitive 41): idpServer.serveToken has cognitive complexity 41 (threshold 15). Drivers by points: if/else 38, boolean chains 3 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":844}}}],"partialFingerprints":{"codehealthFindingId/v1":"99357166e4ce4b5c66330207841b6c6669dbeb17d06df71f296c641bc68e875d"}},{"ruleId":"D2","level":"warning","message":{"text":"ConfigVAlpha.ToPrefs (cognitive 41): ConfigVAlpha.ToPrefs has cognitive complexity 41 (threshold 15). Drivers by points: if/else 37, boolean chains 2, loops 2 (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/conf.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b3bbf449df5f020de3294d3a103d750bdbd30eae5bdfc5096cff402fc561302"}},{"ruleId":"D2","level":"warning","message":{"text":"tstun.diagnoseLinuxTUNFailure (cognitive 41): tstun.diagnoseLinuxTUNFailure has cognitive complexity 41 (threshold 15). Drivers by points: if/else 31, loops 6, boolean chains 3, match/switch 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/tun_linux.go"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"508da80aed7f0bf44a5f15217a24013076de1d1f29e02f10e5d05f3e57f6ab50"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.determineEndpoints (cognitive 41): Conn.determineEndpoints has cognitive complexity 41 (threshold 15). Drivers by points: if/else 25, boolean chains 8, loops 8 (nesting depth added 9). Of this number, 37 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1284}}}],"partialFingerprints":{"codehealthFindingId/v1":"67af0211f549b66e41a866bb64fa7dde6029ffbb2379c1e7b5dc7f4dc659d3e5"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.maybeProvision (cognitive 40): ProxyGroupReconciler.maybeProvision has cognitive complexity 40 (threshold 15). Drivers by points: if/else 38, boolean chains 1, loops 1 (nesting depth added 15). Of this number, 34 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c06a1b223f32e1851158e13f558a573e1bd02923827eb64f484129eb9ffb830"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runTailnetLockRemove (cognitive 40): cli.runTailnetLockRemove has cognitive complexity 40 (threshold 15). Drivers by points: if/else 33, loops 7 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":334}}}],"partialFingerprints":{"codehealthFindingId/v1":"01b6cdcd574e54bb9dc4e3288119cb7d5ce9683791881a3f52a742a039f57447"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.messageForPort (cognitive 40): serveEnv.messageForPort has cognitive complexity 40 (threshold 15). Drivers by points: if/else 29, boolean chains 6, loops 4, match/switch 1 (nesting depth added 10). Of this number, 39 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1045}}}],"partialFingerprints":{"codehealthFindingId/v1":"50651d91a6a117dc43ee377cdff04dbaa7c6cfbef1a7cce84821119215be7166"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.updateFilterLocked (cognitive 40): LocalBackend.updateFilterLocked has cognitive complexity 40 (threshold 15). Drivers by points: if/else 32, loops 5, boolean chains 3 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3358}}}],"partialFingerprints":{"codehealthFindingId/v1":"f37978badb1c5cf06b094eeb694e481e0de036989535aabf2d034f08a6814ca8"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveShares (cognitive 40): Handler.serveShares has cognitive complexity 40 (threshold 15). Drivers by points: if/else 39, match/switch 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi_drive.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"93b0089a2d032b59c0fa732bebc6c0f007ef27577c515ea2742f8ef99a3ff7c7"}},{"ruleId":"D2","level":"warning","message":{"text":"Table.Delete (cognitive 40): Table.Delete has cognitive complexity 40 (threshold 15). Drivers by points: if/else 36, loops 2, match/switch 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/art/table.go"},"region":{"startLine":318}}}],"partialFingerprints":{"codehealthFindingId/v1":"07d2697a59af9cab97f1e3b30dd45609537d8f720974f16861fd206fc7574514"}},{"ruleId":"D2","level":"warning","message":{"text":"netns.controlC (cognitive 40): netns.controlC has cognitive complexity 40 (threshold 15). Drivers by points: if/else 35, boolean chains 4, match/switch 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_windows.go"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"3fa0b5877cd746d21e1ef9d62ccde459fc0e5622bd72f6a2ca19ecc716d35e63"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.UpdateNetstackIPs (cognitive 40): Impl.UpdateNetstackIPs has cognitive complexity 40 (threshold 15). Drivers by points: if/else 24, loops 15, boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":705}}}],"partialFingerprints":{"codehealthFindingId/v1":"980c3c01823c2286ed70373cd9ad9139c574e76ae7eef7f661a40fb3585a44a4"}},{"ruleId":"D2","level":"warning","message":{"text":"Auto.authRoutine (cognitive 39): Auto.authRoutine has cognitive complexity 39 (threshold 15). Drivers by points: if/else 34, match/switch 4, loops 1 (nesting depth added 20). Of this number, 37 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/auto.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6e15d17113c424b9242ec514328f963de3591e5315b93aa7256a0023232a0b2"}},{"ruleId":"D2","level":"warning","message":{"text":"taildrop.handlePeerPutWithBackend (cognitive 39): taildrop.handlePeerPutWithBackend has cognitive complexity 39 (threshold 15). Drivers by points: if/else 28, match/switch 7, loops 3, boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/peerapi.go"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b098ee49fe9077347a6b8151af1a38905bc818bf2c4b7db12cab54afed22c46"}},{"ruleId":"D2","level":"warning","message":{"text":"State.applyVerifiedAUM (cognitive 39): State.applyVerifiedAUM has cognitive complexity 39 (threshold 15). Drivers by points: if/else 33, loops 4, boolean chains 1, match/switch 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/state.go"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0abd140d404e0e6cd6a43192136f7bf0d9adf41a6fff4f69ac9d8124133b33a"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.start (cognitive 39): Server.start has cognitive complexity 39 (threshold 15). Drivers by points: if/else 34, boolean chains 3, match/switch 2 (nesting depth added 5). Of this number, 33 points are the body\u0027s own statements and 6 belong to 4 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":767}}}],"partialFingerprints":{"codehealthFindingId/v1":"9caf7d869ca57f7361ab87a59587092305dc2f8186ba15ab83b03ec54e41e5ca"}},{"ruleId":"D2","level":"warning","message":{"text":"network.acceptTCP (cognitive 39): network.acceptTCP has cognitive complexity 39 (threshold 15). Drivers by points: if/else 31, boolean chains 8 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":391}}}],"partialFingerprints":{"codehealthFindingId/v1":"18442d816ced0ce9745ab490ad4b0b9c92c29d60473b109871f692deb20921d7"}},{"ruleId":"D2","level":"warning","message":{"text":"relayManager.runLoop (cognitive 39): relayManager.runLoop has cognitive complexity 39 (threshold 15). Drivers by points: if/else 36, match/switch 2, loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdc947897fee132033208ca3001c6717cf6b3a54199adde2d7ab013ae908d330"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.shouldSendToHost (cognitive 39): Impl.shouldSendToHost has cognitive complexity 39 (threshold 15). Drivers by points: if/else 37, boolean chains 1, match/switch 1 (nesting depth added 24). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1101}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d54485f154927e1dc97db67ef6015dd3b7b7bd96f6765067f27d767f34300f3"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.acceptTCP (cognitive 39): Impl.acceptTCP has cognitive complexity 39 (threshold 15). Drivers by points: if/else 34, boolean chains 3, loops 1, match/switch 1 (nesting depth added 12). Of this number, 29 points are the body\u0027s own statements and 10 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1512}}}],"partialFingerprints":{"codehealthFindingId/v1":"84b7d90969b7fd7f7edd9e9c40bfc7fda556aa8844f7c0918902bb35d591258d"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.findStaticEndpoints (cognitive 38): ProxyGroupReconciler.findStaticEndpoints has cognitive complexity 38 (threshold 15). Drivers by points: if/else 31, loops 5, boolean chains 2 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":1068}}}],"partialFingerprints":{"codehealthFindingId/v1":"313200019991764aa5b3c8d6db9f5109993de4502ae5004e0c05c49e2f83fd31"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.printTailnetLockStatus (cognitive 38): cli.printTailnetLockStatus has cognitive complexity 38 (threshold 15). Drivers by points: if/else 28, loops 7, boolean chains 3 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"5674c9351753a6fe7b17b7788a3f43f579df807b903573bf67df3a664f817d06"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.NewLocalBackend (cognitive 38): ipnlocal.NewLocalBackend has cognitive complexity 38 (threshold 15). Drivers by points: if/else 35, loops 2, boolean chains 1 (nesting depth added 10). Of this number, 37 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":543}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c93ef7ea1080b9bcc5aa19bd369d2384c578f83757a3fa59ce44283d0c26f8c"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.addrDiscoveryLoop (cognitive 38): Server.addrDiscoveryLoop has cognitive complexity 38 (threshold 15). Drivers by points: if/else 28, loops 6, boolean chains 2, match/switch 2 (nesting depth added 15). Most of this is not in the body itself: 6 of the 38 points are its own statements and the rest belongs to one function literal inside it that branches (line 463). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":458}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b24a6b3ae4c89cb5b9189a482a740d1a35acfb7186222f03d1c02ce5192310e"}},{"ruleId":"D2","level":"warning","message":{"text":"Menu.rebuild (cognitive 37): Menu.rebuild has cognitive complexity 37 (threshold 15). Drivers by points: if/else 25, match/switch 6, boolean chains 3, loops 3 (nesting depth added 12). Of this number, 32 points are the body\u0027s own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"600a3fbbae1691cf5c7626878937a3f2c0da45a9d9f4a38f44eeb7c4f259c8fa"}},{"ruleId":"D2","level":"warning","message":{"text":"HAServiceReconciler.maybeUpdateAdvertiseServicesConfig (cognitive 37): HAServiceReconciler.maybeUpdateAdvertiseServicesConfig has cognitive complexity 37 (threshold 15). Drivers by points: if/else 27, boolean chains 4, loops 3, match/switch 3 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":637}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a8aec6fc2f1f91bbf8048a262d415f917beba00fb7084d16b1def5b43374b20"}},{"ruleId":"D2","level":"warning","message":{"text":"ServiceReconciler.maybeProvision (cognitive 37): ServiceReconciler.maybeProvision has cognitive complexity 37 (threshold 15). Drivers by points: if/else 33, boolean chains 3, loops 1 (nesting depth added 8). Of this number, 36 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc.go"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e5f4a8ee9d34d70c54e7b3acc73296985367676dab0e926e9d44ce175fce97e"}},{"ruleId":"D2","level":"warning","message":{"text":"controlclient.NewDirect (cognitive 37): controlclient.NewDirect has cognitive complexity 37 (threshold 15). Drivers by points: if/else 33, boolean chains 4 (nesting depth added 10). Of this number, 31 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":301}}}],"partialFingerprints":{"codehealthFindingId/v1":"391ac0954ffc2bad9f5285d7e4dce871531c7265af474eaef7af913da8b3ffd2"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.dialNode (cognitive 37): Client.dialNode has cognitive complexity 37 (threshold 15). Drivers by points: if/else 26, boolean chains 5, match/switch 5, loops 1 (nesting depth added 13). Of this number, 22 points are the body\u0027s own statements and 15 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":737}}}],"partialFingerprints":{"codehealthFindingId/v1":"71b9d112c0c213aa01d03fe90362be5c3116749003d041cdcb8190d84106ef79"}},{"ruleId":"D2","level":"warning","message":{"text":"ServeConfig.HasPathHandler (cognitive 37): ServeConfig.HasPathHandler has cognitive complexity 37 (threshold 15). Drivers by points: if/else 19, loops 18 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":234}}}],"partialFingerprints":{"codehealthFindingId/v1":"22d3e55118a62163067ff1c66e1ecfe2ad5b8516e8de231cf0a69fe2f2eeb41b"}},{"ruleId":"D2","level":"warning","message":{"text":"logpolicy.tryFixLogStateLocation (cognitive 37): logpolicy.tryFixLogStateLocation has cognitive complexity 37 (threshold 15). Drivers by points: if/else 29, loops 5, match/switch 2, boolean chains 1 (nesting depth added 11). Of this number, 27 points are the body\u0027s own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"083756993be6cdec3fef6425c262408f146b5ade03124b2d21afac9a9e4da93a"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.nodeAddrPort (cognitive 37): Client.nodeAddrPort has cognitive complexity 37 (threshold 15). Drivers by points: if/else 28, boolean chains 6, loops 2, match/switch 1 (nesting depth added 12). Of this number, 33 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1654}}}],"partialFingerprints":{"codehealthFindingId/v1":"b992b5008a48421127d9e3089679a088f7f0cb14dad5771323d5eeec8cb01866"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.packetReadLoop (cognitive 37): Server.packetReadLoop has cognitive complexity 37 (threshold 15). Drivers by points: if/else 28, loops 8, boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":865}}}],"partialFingerprints":{"codehealthFindingId/v1":"5006f33cb2f9eae276ec9febedb99714ac3064136cd177387ca431a63748a14c"}},{"ruleId":"D2","level":"warning","message":{"text":"Dialer.tryURLUpgrade (cognitive 36): Dialer.tryURLUpgrade has cognitive complexity 36 (threshold 15). Drivers by points: if/else 33, boolean chains 3 (nesting depth added 8). Of this number, 25 points are the body\u0027s own statements and 11 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client.go"},"region":{"startLine":405}}}],"partialFingerprints":{"codehealthFindingId/v1":"6444c55f105275365d74a0997cdf5eeec6db5476ada4ac155e688413a950f7d0"}},{"ruleId":"D2","level":"warning","message":{"text":"Resolver.resolveLocal (cognitive 36): Resolver.resolveLocal has cognitive complexity 36 (threshold 15). Drivers by points: if/else 23, loops 8, match/switch 3, boolean chains 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":722}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b61026614e4fe16b917655906627637c7c209c4f3e6896ab6cd1d8ec694117f"}},{"ruleId":"D2","level":"warning","message":{"text":"AUM.StaticValidate (cognitive 36): AUM.StaticValidate has cognitive complexity 36 (threshold 15). Drivers by points: if/else 27, boolean chains 7, loops 1, match/switch 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/aum.go"},"region":{"startLine":159}}}],"partialFingerprints":{"codehealthFindingId/v1":"23196b47eaafaba5b9b9b0549da1988cab8c7099f9cb5e1780f5ce85fd13ae3f"}},{"ruleId":"D2","level":"warning","message":{"text":"main.autoflagsForTest (cognitive 36): main.autoflagsForTest has cognitive complexity 36 (threshold 15). Drivers by points: if/else 25, match/switch 10, boolean chains 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/gocross/autoflags.go"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e2496c8f3cce9b4ada848e7860b7283f4424a8cbde829f6977877b4280d8faf"}},{"ruleId":"D2","level":"warning","message":{"text":"osdiag.getRegSubKey (cognitive 36): osdiag.getRegSubKey has cognitive complexity 36 (threshold 15). Drivers by points: if/else 23, loops 8, match/switch 4, jumps 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/osdiag/osdiag_windows.go"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b96b6c2c8ba3b972e81b46d2d3e6097b1807c01f107666f4c2181c52aaa48da"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serveAPIAuth (cognitive 35): Server.serveAPIAuth has cognitive complexity 35 (threshold 15). Drivers by points: if/else 24, boolean chains 8, match/switch 3 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":654}}}],"partialFingerprints":{"codehealthFindingId/v1":"59c400b9258d49191bbfd05300b1831be03354a367c0c20df6726fdfa5a9abc3"}},{"ruleId":"D2","level":"warning","message":{"text":"dnsRecordsReconciler.getPodIPs (cognitive 35): dnsRecordsReconciler.getPodIPs has cognitive complexity 35 (threshold 15). Drivers by points: if/else 24, loops 6, match/switch 4, boolean chains 1 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/dnsrecords.go"},"region":{"startLine":453}}}],"partialFingerprints":{"codehealthFindingId/v1":"41647e8900c2fd2aac0f00d86fcb9d0cd64b5e0e0e538670cd8174c6bb8dea44"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 35): main.main has cognitive complexity 35 (threshold 15). Drivers by points: if/else 33, loops 2 (nesting depth added 10). Of this number, 33 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/natc/natc.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd776a149b4c63c029c3cda23702496ff332b72cb0af2ef848aa6c06a5e6bb97"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runTailnetLockRevokeKeys (cognitive 35): cli.runTailnetLockRevokeKeys has cognitive complexity 35 (threshold 15). Drivers by points: if/else 32, loops 2, boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":832}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7fe9f21184fb17ea5933144d2b37088a66ee79da1cf900361111f75a10733de"}},{"ruleId":"D2","level":"warning","message":{"text":"tailssh.getSSHUsernames (cognitive 35): tailssh.getSSHUsernames has cognitive complexity 35 (threshold 15). Drivers by points: if/else 23, boolean chains 6, loops 4, match/switch 2 (nesting depth added 13). Of this number, 30 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/c2n.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"a865c983c96d8b243a7c9d2c27798613b1ec6471e34938b8181a108f3dec8332"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 35): main.main has cognitive complexity 35 (threshold 15). Drivers by points: if/else 30, loops 3, match/switch 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/gocross/gocross.go"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"c76defa30c2b39c1e4869e93f16a7016a19403aaec9ef2c076ad55cd1a77db9c"}},{"ruleId":"D2","level":"warning","message":{"text":"Env.startTailMacVM (cognitive 35): Env.startTailMacVM has cognitive complexity 35 (threshold 15). Drivers by points: if/else 28, loops 5, match/switch 2 (nesting depth added 14). Most of this is not in the body itself: 15 of the 35 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 683, 654, 667). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/tailmac.go"},"region":{"startLine":547}}}],"partialFingerprints":{"codehealthFindingId/v1":"decfc6f96e598f93ca8a7b78c878d1d2b85016a60e10965349091e8927bf86f1"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.monitorDefaultRoutes (cognitive 35): osrouter.monitorDefaultRoutes has cognitive complexity 35 (threshold 15). Drivers by points: if/else 32, boolean chains 3 (nesting depth added 16). Most of this is not in the body itself: 2 of the 35 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 48, 101). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"e028016b96c0bf53c8450f7fc6383581335ef2fe6b2f0709dcff34e23d98b1f4"}},{"ruleId":"D2","level":"warning","message":{"text":"userspaceBSDRouter.Set (cognitive 35): userspaceBSDRouter.Set has cognitive complexity 35 (threshold 15). Drivers by points: if/else 25, boolean chains 5, loops 5 (nesting depth added 12). Of this number, 34 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_userspace_bsd.go"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a77838103a6cb4fa2da28f5be3ec260e63551a674f3b0dc2bc5297851073b40"}},{"ruleId":"D2","level":"warning","message":{"text":"egressPodsReconciler.Reconcile (cognitive 34): egressPodsReconciler.Reconcile has cognitive complexity 34 (threshold 15). Drivers by points: if/else 28, loops 4, boolean chains 2 (nesting depth added 11). Most of this is not in the body itself: 14 of the 34 points are its own statements and the rest belongs to one function literal inside it that branches (line 141). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-pod-readiness.go"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"438936a8e41fac0bffccc489562f8fe20efbc0e910a7daceb932896253c29d1b"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.isLegacyInvocation (cognitive 34): cli.isLegacyInvocation has cognitive complexity 34 (threshold 15). Drivers by points: if/else 22, boolean chains 10, match/switch 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c9702c0356b195996685f09e6cff51cf3210738082f62ad9e0bc48bb9860533"}},{"ruleId":"D2","level":"warning","message":{"text":"Filch.TryReadLine (cognitive 34): Filch.TryReadLine has cognitive complexity 34 (threshold 15). Drivers by points: if/else 28, match/switch 3, boolean chains 2, loops 1 (nesting depth added 18). Of this number, 28 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/filch/filch.go"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f40938892c3919cb0ec3224bafc39d991c752051df78aa9e66df972b4fb37d7"}},{"ruleId":"D2","level":"warning","message":{"text":"Manager.compileConfig (cognitive 34): Manager.compileConfig has cognitive complexity 34 (threshold 15). Drivers by points: if/else 17, boolean chains 10, loops 6, match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager.go"},"region":{"startLine":306}}}],"partialFingerprints":{"codehealthFindingId/v1":"d968c73f6211b4dd64739dffc0bb5279145f4b1b5e58fdddf7996d91c54525ca"}},{"ruleId":"D2","level":"warning","message":{"text":"nmManager.trySet (cognitive 34): nmManager.trySet has cognitive complexity 34 (threshold 15). Drivers by points: if/else 27, loops 6, boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nm.go"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"59f83af6a613dfe252639a7b0c28a53b51a5a6ddf4ac1c14937e7fdfa449a8d3"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.runHTTPOnlyChecks (cognitive 34): Client.runHTTPOnlyChecks has cognitive complexity 34 (threshold 15). Drivers by points: if/else 25, loops 5, boolean chains 4 (nesting depth added 14). Of this number, 20 points are the body\u0027s own statements and 14 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1068}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2837499729d137d4cff26c9c991820aabfecebdaed38cc7a4d9f1032fd47b0a"}},{"ruleId":"D2","level":"warning","message":{"text":"netmon.likelyHomeRouterIPLinux (cognitive 34): netmon.likelyHomeRouterIPLinux has cognitive complexity 34 (threshold 15). Drivers by points: if/else 29, loops 4, boolean chains 1 (nesting depth added 16). Of this number, 24 points are the body\u0027s own statements and 10 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_linux.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f978b94819417604a5bc2b915720aeec005bdff24e886328806ebe310a8d237"}},{"ruleId":"D2","level":"warning","message":{"text":"conn.clientAuth (cognitive 34): conn.clientAuth has cognitive complexity 34 (threshold 15). Drivers by points: if/else 28, match/switch 3, boolean chains 2, loops 1 (nesting depth added 16). Of this number, 29 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"732d1762f0374e860827bd89a0bd6c88424cf8a3dd0d5a4dec62d92e94602093"}},{"ruleId":"D2","level":"warning","message":{"text":"State.staticValidateCheckpoint (cognitive 34): State.staticValidateCheckpoint has cognitive complexity 34 (threshold 15). Drivers by points: if/else 27, loops 7 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/state.go"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc8763c6839218cb672cfb0cbf75e4c8c93739cf06599dcab8fa42d44f21f3bb"}},{"ruleId":"D2","level":"warning","message":{"text":"winutil.OpenKeyWait (cognitive 34): winutil.OpenKeyWait has cognitive complexity 34 (threshold 15). Drivers by points: if/else 30, loops 3, boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/winutil_windows.go"},"region":{"startLine":516}}}],"partialFingerprints":{"codehealthFindingId/v1":"82685c6b3506bdf661dade6e034c3cc8f2cdb83c5af26104297c679ec0d177fa"}},{"ruleId":"D2","level":"warning","message":{"text":"firewallTweaker.doSet (cognitive 34): firewallTweaker.doSet has cognitive complexity 34 (threshold 15). Drivers by points: if/else 31, loops 3 (nesting depth added 15). Of this number, 26 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_windows.go"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe60556788e6c23bab8d202451b01bf8b36d6925390d4ad2eb9a25b4a0045703"}},{"ruleId":"D2","level":"warning","message":{"text":"main.initTSNet (cognitive 33): main.initTSNet has cognitive complexity 33 (threshold 15). Drivers by points: if/else 27, boolean chains 2, match/switch 2, jumps 1, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"23c1af00f039fa4771a036891100321e044f376254db6fa283ea75e0b5c77cd3"}},{"ruleId":"D2","level":"warning","message":{"text":"main.runReconcilers (cognitive 33): main.runReconcilers has cognitive complexity 33 (threshold 15). Drivers by points: if/else 32, boolean chains 1 (nesting depth added 2). Of this number, 32 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"34ee8037c7fceae5e08461bb97f4a129f6ef42e99a83b668cb5f2eb2ba6198ee"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runTS2021 (cognitive 33): cli.runTS2021 has cognitive complexity 33 (threshold 15). Drivers by points: if/else 30, boolean chains 1, loops 1, match/switch 1 (nesting depth added 8). Of this number, 23 points are the body\u0027s own statements and 10 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":1043}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4bf63da9554a427ee7a609a43aa58531ca7c186a9c1e2947d08c0ea0e86a967"}},{"ruleId":"D2","level":"warning","message":{"text":"idpServer.authorize (cognitive 33): idpServer.authorize has cognitive complexity 33 (threshold 15). Drivers by points: if/else 33 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":427}}}],"partialFingerprints":{"codehealthFindingId/v1":"84bfce5870a854c912674d73ac191eb612079758a542e59d344b2cd2c4ad3c11"}},{"ruleId":"D2","level":"warning","message":{"text":"main.runMap (cognitive 33): main.runMap has cognitive complexity 33 (threshold 15). Drivers by points: if/else 29, boolean chains 3, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsp/tsp.go"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c696cba9e417e22b17b6a49a91dcb62e6f6e48de978b89c04a6d66da49f97b3"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ServeDebugTraffic (cognitive 33): Server.ServeDebugTraffic has cognitive complexity 33 (threshold 15). Drivers by points: if/else 29, loops 3, boolean chains 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":2590}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7db8798d4e1e5952690afa201c25cba427ed0edcf593b1ef3b82b0b09282ab8"}},{"ruleId":"D2","level":"warning","message":{"text":"ipn.CheckFunnelPort (cognitive 33): ipn.CheckFunnelPort has cognitive complexity 33 (threshold 15). Drivers by points: if/else 29, loops 4 (nesting depth added 14). Of this number, 29 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":667}}}],"partialFingerprints":{"codehealthFindingId/v1":"7736cd1b3e63df0800a813a0dc2736f7e627501c550ce1d27085e74f891338f9"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.notifyForSessionLocked (cognitive 33): LocalBackend.notifyForSessionLocked has cognitive complexity 33 (threshold 15). Drivers by points: if/else 19, boolean chains 10, loops 4 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":4134}}}],"partialFingerprints":{"codehealthFindingId/v1":"211d5081acce9e75992d510a598acc17be422180fd6c0f1c4d69a4b05406e0d1"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.initPeerAPIListenerLocked (cognitive 33): LocalBackend.initPeerAPIListenerLocked has cognitive complexity 33 (threshold 15). Drivers by points: if/else 27, boolean chains 3, loops 3 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6378}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e7d0a5c5fb09263d2db886a03feb3d33271907d1a0e59577beda0704b90f306"}},{"ruleId":"D2","level":"warning","message":{"text":"ChangeDelta.isInterestingInterfaceChange (cognitive 33): ChangeDelta.isInterestingInterfaceChange has cognitive complexity 33 (threshold 15). Drivers by points: if/else 25, boolean chains 6, loops 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon.go"},"region":{"startLine":271}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7e52766418d5cbd2809715911315d9e9cc904b70ce84502088275a440c3c4c2"}},{"ruleId":"D2","level":"warning","message":{"text":"routetable.Get (cognitive 33): routetable.Get has cognitive complexity 33 (threshold 15). Drivers by points: if/else 28, loops 2, match/switch 2, boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routetable/routetable_linux.go"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"c90320070e616c2ce1a6ca6406119e05089d6bb0b68756808503ef54e9d12b01"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.bindSockets (cognitive 33): Server.bindSockets has cognitive complexity 33 (threshold 15). Drivers by points: if/else 22, match/switch 4, loops 3, boolean chains 2, jumps 2 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":655}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c38462b771a4ace1d2efa833b5ef7174709c4fe9874a150b237b622509c5512"}},{"ruleId":"D2","level":"warning","message":{"text":"prober.runDerpProbeQueuingDelayContinously (cognitive 33): prober.runDerpProbeQueuingDelayContinously has cognitive complexity 33 (threshold 15). Drivers by points: if/else 16, match/switch 9, loops 6, jumps 2 (nesting depth added 16). Most of this is not in the body itself: 3 of the 33 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 488, 456, 433). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":411}}}],"partialFingerprints":{"codehealthFindingId/v1":"e79a91d3378dac3f0ab984b07525366343a88283c7ff712ea26283cbd0855f8a"}},{"ruleId":"D2","level":"warning","message":{"text":"network.HandleEthernetPacket (cognitive 33): network.HandleEthernetPacket has cognitive complexity 33 (threshold 15). Drivers by points: if/else 25, boolean chains 7, match/switch 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1572}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3a2ba9886cb08a3301aa7662016723463bd952fb91475d78331db1632440c83"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxfw.printMatchInfo (cognitive 33): linuxfw.printMatchInfo has cognitive complexity 33 (threshold 15). Drivers by points: if/else 29, loops 2, match/switch 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"4145c2958eaa434b6677e4e6b371fed18b557428f8798dbd11fffbf16ea81d43"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serveGetNodeData (cognitive 32): Server.serveGetNodeData has cognitive complexity 32 (threshold 15). Drivers by points: if/else 25, boolean chains 4, loops 3 (nesting depth added 8). Of this number, 30 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":876}}}],"partialFingerprints":{"codehealthFindingId/v1":"27ef7d67a54ee743b9b4ee01cbb8fd64736448532b2c128516295176293fc27a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 32): main.main has cognitive complexity 32 (threshold 15). Drivers by points: if/else 19, loops 12, boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/featuretags/featuretags.go"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"851815f9547c9c55377a97494221897a03b52d8c4a7428d3c9f270d9961d20ea"}},{"ruleId":"D2","level":"warning","message":{"text":"jsontags.run (cognitive 32): jsontags.run has cognitive complexity 32 (threshold 15). Drivers by points: if/else 14, boolean chains 8, match/switch 7, loops 3 (nesting depth added 15). Most of this is not in the body itself: 0 of the 32 points are its own statements and the rest belongs to one function literal inside it that branches (line 30). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vet/jsontags/analyzer.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"9201045326bc2071dc6b44eda494ae1589ff6320e329a71008888055ed91ef6f"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.setServeConfigLocked (cognitive 32): LocalBackend.setServeConfigLocked has cognitive complexity 32 (threshold 15). Drivers by points: if/else 25, loops 6, boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4e71fe146fd2d147bd9674057dbb01a6fa711e813328e7efaa1b10df856f901"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.tkaFilterNetmapLocked (cognitive 32): LocalBackend.tkaFilterNetmapLocked has cognitive complexity 32 (threshold 15). Drivers by points: if/else 25, boolean chains 4, loops 3 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":181}}}],"partialFingerprints":{"codehealthFindingId/v1":"9335dc317767839ff06f403acba9996caee1ef98ad3f4f4ba29e17a163f1d3d2"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.tkaSyncIfNeeded (cognitive 32): LocalBackend.tkaSyncIfNeeded has cognitive complexity 32 (threshold 15). Drivers by points: if/else 26, boolean chains 6 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":349}}}],"partialFingerprints":{"codehealthFindingId/v1":"401131f82f495f5c0bbb17cc7e8ec6ad682ae7b33008a825aa4d90c760703f3c"}},{"ruleId":"D2","level":"warning","message":{"text":"conn.processFrames (cognitive 32): conn.processFrames has cognitive complexity 32 (threshold 15). Drivers by points: if/else 28, boolean chains 3, loops 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/ws/conn.go"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ddd9b908eb027291be8701762343d3cbf00a97fbca01a6709f6f464e3fe74ee"}},{"ruleId":"D2","level":"warning","message":{"text":"Logger.uploading (cognitive 32): Logger.uploading has cognitive complexity 32 (threshold 15). Drivers by points: if/else 25, loops 3, boolean chains 2, match/switch 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"94bac08aec09f708d75128c2e58b69cbd45c347973641f9cb89c21edd964840a"}},{"ruleId":"D2","level":"warning","message":{"text":"resolver.marshalResponse (cognitive 32): resolver.marshalResponse has cognitive complexity 32 (threshold 15). Drivers by points: if/else 28, loops 2, boolean chains 1, match/switch 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":1200}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f9149c57846efd67eff7be1f680deceeda0ed47b536fdc4986375fef6167ae7"}},{"ruleId":"D2","level":"warning","message":{"text":"State.String (cognitive 32): State.String has cognitive complexity 32 (threshold 15). Drivers by points: if/else 24, loops 4, match/switch 3, boolean chains 1 (nesting depth added 14). Of this number, 31 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":297}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d0c9dfe2c1734405efd85638a8addca26c19624aac3db012fffeb144f62af30"}},{"ruleId":"D2","level":"warning","message":{"text":"netx.RaceDial (cognitive 32): netx.RaceDial has cognitive complexity 32 (threshold 15). Drivers by points: if/else 19, match/switch 10, loops 3 (nesting depth added 17). Of this number, 16 points are the body\u0027s own statements and 16 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netx/racedial.go"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"5898af3c4eb925f68b5e065e42db5b61258b6eee4086d15c448c5424bf84fcb6"}},{"ruleId":"D2","level":"warning","message":{"text":"RouteManager.applyDirty (cognitive 32): RouteManager.applyDirty has cognitive complexity 32 (threshold 15). Drivers by points: if/else 17, boolean chains 9, loops 4, match/switch 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":909}}}],"partialFingerprints":{"codehealthFindingId/v1":"127192965662880e216fc1ae40098b5bd07efeaa8093d4cb2d6a4eb36e61f83b"}},{"ruleId":"D2","level":"warning","message":{"text":"tstun.New (cognitive 32): tstun.New has cognitive complexity 32 (threshold 15). Drivers by points: if/else 27, loops 2, match/switch 2, boolean chains 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/tun.go"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"89db6c4288ca1c1e68f4b2ecc639d9d1107709f2768602dfe167fd438443aed8"}},{"ruleId":"D2","level":"warning","message":{"text":"portlist.appendParsePortsNetstat (cognitive 32): portlist.appendParsePortsNetstat has cognitive complexity 32 (threshold 15). Drivers by points: if/else 28, boolean chains 3, loops 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/netstat.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"698ea3578db8bf512e55916a9e81bb14becd5cb2e51a7006ad208f0a5bf71719"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxImpl.parseProcNetFile (cognitive 32): linuxImpl.parseProcNetFile has cognitive complexity 32 (threshold 15). Drivers by points: if/else 28, boolean chains 3, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/portlist_linux.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2fb546dcc86b7538fdd05c23f504470cc2c9e98192eea79dd769403ff09e343"}},{"ruleId":"D2","level":"warning","message":{"text":"tgzTarget.Build (cognitive 32): tgzTarget.Build has cognitive complexity 32 (threshold 15). Drivers by points: if/else 32 (nesting depth added 7). Of this number, 28 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"release/dist/unixpkgs/pkgs.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9dda0355b2883462bb94b90c88d0062f8a367f140297cca02bf4b4b0ca46ffe"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.Up (cognitive 32): Server.Up has cognitive complexity 32 (threshold 15). Drivers by points: if/else 31, loops 1 (nesting depth added 20). Of this number, 24 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":535}}}],"partialFingerprints":{"codehealthFindingId/v1":"865ff5e38b124d8a0258424a939147a5ac84fafb5be8cad91d23c215d87dcb23"}},{"ruleId":"D2","level":"warning","message":{"text":"main.certProviderByCertMode (cognitive 31): main.certProviderByCertMode has cognitive complexity 31 (threshold 15). Drivers by points: if/else 28, boolean chains 2, match/switch 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/cert.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"23b79bd534190a55c82cb5d4b4c7f3a13771f846d38439c06ffc39c63c007c5a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.watchKeyboardForConsole (cognitive 31): main.watchKeyboardForConsole has cognitive complexity 31 (threshold 15). Drivers by points: if/else 24, boolean chains 4, match/switch 2, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":330}}}],"partialFingerprints":{"codehealthFindingId/v1":"06711d59189a108311b5e375930f6b13f17f1e51db8935cc46673c05c8ddea96"}},{"ruleId":"D2","level":"warning","message":{"text":"Dialer.dialHostOpt (cognitive 31): Dialer.dialHostOpt has cognitive complexity 31 (threshold 15). Drivers by points: if/else 20, match/switch 6, boolean chains 4, loops 1 (nesting depth added 12). Of this number, 26 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client.go"},"region":{"startLine":239}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd67ce90f9090da7a003c84de5c16b822e3b81c28a2265d68ce9fafbaf756e3a"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.addReportHistoryAndSetPreferredDERP (cognitive 31): Client.addReportHistoryAndSetPreferredDERP has cognitive complexity 31 (threshold 15). Drivers by points: if/else 21, boolean chains 8, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1415}}}],"partialFingerprints":{"codehealthFindingId/v1":"26c7a743d0fdc5538993150d1353ac2e56cc5c02d9d2a3a0637e622e52942f7d"}},{"ruleId":"D2","level":"warning","message":{"text":"NodeKeySignature.verifySignature (cognitive 31): NodeKeySignature.verifySignature has cognitive complexity 31 (threshold 15). Drivers by points: if/else 28, match/switch 3 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/sig.go"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc959da60ac2fc023e1e6b3b31a298bb28ee9dfffd456499f2ffc17d6f49488e"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ListenService (cognitive 31): Server.ListenService has cognitive complexity 31 (threshold 15). Drivers by points: if/else 26, loops 3, boolean chains 1, match/switch 1 (nesting depth added 10). Of this number, 30 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":1835}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1e49f1140b1257af55677b8c9bbe28288ba7fcde1eb1a084addb540847e6d50"}},{"ruleId":"D2","level":"warning","message":{"text":"network.HandleEthernetPacketForRouter (cognitive 31): network.HandleEthernetPacketForRouter has cognitive complexity 31 (threshold 15). Drivers by points: if/else 22, boolean chains 9 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1862}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e2d82b1c77cefdee9b0e2877e685cca73fefa543790e146b0a3dbe112ebb32a"}},{"ruleId":"D2","level":"warning","message":{"text":"network.handleUDPPacketForRouter (cognitive 31): network.handleUDPPacketForRouter has cognitive complexity 31 (threshold 15). Drivers by points: if/else 27, boolean chains 4 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1997}}}],"partialFingerprints":{"codehealthFindingId/v1":"937808ffc17d37ea67639f71fb5f0b4160bc4e7d21fd894348d993ca3fbdd42f"}},{"ruleId":"D2","level":"warning","message":{"text":"relayManager.handshakeServerEndpoint (cognitive 31): relayManager.handshakeServerEndpoint has cognitive complexity 31 (threshold 15). Drivers by points: if/else 24, match/switch 5, loops 2 (nesting depth added 16). Of this number, 27 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":875}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f8a50cc1ce3af960b85df12e91a3b9466f821486f70a334e88f3b47703f4d08"}},{"ruleId":"D2","level":"warning","message":{"text":"windowsManager.SetDNS (cognitive 31): windowsManager.SetDNS has cognitive complexity 31 (threshold 15). Drivers by points: if/else 30, boolean chains 1 (nesting depth added 11). Of this number, 24 points are the body\u0027s own statements and 7 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"a897a3b3cd94b85025e9dff6b1d38742c4828353cf8f567ded4eb4c29e04be98"}},{"ruleId":"D2","level":"warning","message":{"text":"RestartableProcesses.Terminate (cognitive 31): RestartableProcesses.Terminate has cognitive complexity 31 (threshold 15). Drivers by points: if/else 25, loops 5, boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/restartmgr_windows.go"},"region":{"startLine":474}}}],"partialFingerprints":{"codehealthFindingId/v1":"ccceee6dc181978e1e12cd27b81bb15d58570dfa7620eaa550bda7a560933f2e"}},{"ruleId":"D2","level":"warning","message":{"text":"egressSvcsReadinessReconciler.Reconcile (cognitive 30): egressSvcsReadinessReconciler.Reconcile has cognitive complexity 30 (threshold 15). Drivers by points: if/else 24, loops 5, jumps 1 (nesting depth added 6). Of this number, 29 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services-readiness.go"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"76f99f2f9649f3d0101fe83e2a395a17e6bc6312e1129fd79d5bc5f55e207049"}},{"ruleId":"D2","level":"warning","message":{"text":"IngressReconciler.maybeProvision (cognitive 30): IngressReconciler.maybeProvision has cognitive complexity 30 (threshold 15). Drivers by points: if/else 25, loops 3, boolean chains 2 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":135}}}],"partialFingerprints":{"codehealthFindingId/v1":"66f1e86fa1c3059ccdebaa04e6aa6bc6829152f5e3bc4849f575a257a7186f66"}},{"ruleId":"D2","level":"warning","message":{"text":"configLoader.watchConfigSecretChanges (cognitive 30): configLoader.watchConfigSecretChanges has cognitive complexity 30 (threshold 15). Drivers by points: if/else 23, match/switch 5, boolean chains 1, loops 1 (nesting depth added 17). Of this number, 29 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/internal/config/config.go"},"region":{"startLine":171}}}],"partialFingerprints":{"codehealthFindingId/v1":"97776e1d84f6c86c85f720a8e637132a8548ce9fb29f69ee0c7842cf382cf6fc"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.RunWithContext (cognitive 30): cli.RunWithContext has cognitive complexity 30 (threshold 15). Drivers by points: if/else 22, loops 4, boolean chains 2, match/switch 2 (nesting depth added 13). Of this number, 25 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cli.go"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c38610c9924c2a7133f3fcf4ad55c77b4a16d73f2a196277dd4088c0ab3152d"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.prefsFromUpArgs (cognitive 30): cli.prefsFromUpArgs has cognitive complexity 30 (threshold 15). Drivers by points: if/else 25, boolean chains 3, loops 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":299}}}],"partialFingerprints":{"codehealthFindingId/v1":"403395f01e36f1ab8acba01d33360482fd359e0be236c3f7f78fc086d2b94c9a"}},{"ruleId":"D2","level":"warning","message":{"text":"Builder.waitForImportSnapshot (cognitive 30): Builder.waitForImportSnapshot has cognitive complexity 30 (threshold 15). Drivers by points: if/else 27, match/switch 2, loops 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"gokrazy/build/build.go"},"region":{"startLine":452}}}],"partialFingerprints":{"codehealthFindingId/v1":"c433b3ec54ce14955aa0334d2e3321834cb2b2a6bb40a04911d641b9af48e806"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.setPrefsLocked (cognitive 30): LocalBackend.setPrefsLocked has cognitive complexity 30 (threshold 15). Drivers by points: if/else 26, boolean chains 4 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":5495}}}],"partialFingerprints":{"codehealthFindingId/v1":"75b6f199b68c7b707a590fc88b1c2f03821bc2e3a41ec46a26b64583244e2f66"}},{"ruleId":"D2","level":"warning","message":{"text":"state.KeepKeysUpdated (cognitive 30): state.KeepKeysUpdated has cognitive complexity 30 (threshold 15). Drivers by points: if/else 26, loops 4 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"kube/state/state.go"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cbd672a89c5f0b9e9c1a2f3af1a45d78d22ce65eedfc70dddc3efa0eaf83fba"}},{"ruleId":"D2","level":"warning","message":{"text":"dns.dnsMode (cognitive 30): dns.dnsMode has cognitive complexity 30 (threshold 15). Drivers by points: if/else 27, match/switch 3 (nesting depth added 11). Of this number, 26 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_linux.go"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0532fcac87f116c95036182b2c7c5d1a76e9060c3cf170a1bbfc9d164b2e446"}},{"ruleId":"D2","level":"warning","message":{"text":"Parsed.decode4 (cognitive 30): Parsed.decode4 has cognitive complexity 30 (threshold 15). Drivers by points: if/else 28, match/switch 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"446f2353389e9b4ba40388b482f910dee587308b21199cacedc7c273edbd2922"}},{"ruleId":"D2","level":"warning","message":{"text":"Bus.pump (cognitive 30): Bus.pump has cognitive complexity 30 (threshold 15). Drivers by points: loops 16, match/switch 8, if/else 4, jumps 2 (nesting depth added 18). Of this number, 29 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/eventbus/bus.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad981ecd1fc3eea92746fe671082e794c464835e1a9d2fb71b8b171dc60dba16"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.sendDiscoMessage (cognitive 30): Conn.sendDiscoMessage has cognitive complexity 30 (threshold 15). Drivers by points: if/else 22, boolean chains 4, match/switch 4 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1969}}}],"partialFingerprints":{"codehealthFindingId/v1":"30d6c0b42fa8ccc511e8f8ef367be133aab0f3a4b8f01bc4cb8522b7bb844c5e"}},{"ruleId":"D2","level":"warning","message":{"text":"nameserver.resetRecords (cognitive 29): nameserver.resetRecords has cognitive complexity 29 (threshold 15). Drivers by points: if/else 22, loops 6, boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-nameserver/main.go"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"0bb8bec213668f3dd91555b0910ef805b1975166934d0fcbbcbe0d9f15cd04ae"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runConfigureSynologyCert (cognitive 29): cli.runConfigureSynologyCert has cognitive complexity 29 (threshold 15). Drivers by points: if/else 25, boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-synology-cert.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4dbbf7b7bc8d27b0c004f392666ec3744970091644c869fe9b00863ba1d9b9b"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runDaemonMetrics (cognitive 29): cli.runDaemonMetrics has cognitive complexity 29 (threshold 15). Drivers by points: if/else 21, loops 6, boolean chains 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":936}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae5de3c2cc7e76c5cbc2bd653066b024f5e6561f7d1983212fe025eea2b502c8"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.filterFormatAndSortExitNodes (cognitive 29): cli.filterFormatAndSortExitNodes has cognitive complexity 29 (threshold 15). Drivers by points: if/else 20, loops 7, boolean chains 2 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/exitnode.go"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"58ae972bc2a6f304c5c5ba1cfb5d8def0e8171d7afbfe589377612c87876b561"}},{"ruleId":"D2","level":"warning","message":{"text":"tapDevice.handleDHCPRequest (cognitive 29): tapDevice.handleDHCPRequest has cognitive complexity 29 (threshold 15). Drivers by points: if/else 27, boolean chains 1, match/switch 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/tap/tap_linux.go"},"region":{"startLine":204}}}],"partialFingerprints":{"codehealthFindingId/v1":"69009eb72d228b790bab40798a89c0a01d5c3b67f10d376fc6d7121a9f2c2126"}},{"ruleId":"D2","level":"warning","message":{"text":"Status.WriteHTML (cognitive 29): Status.WriteHTML has cognitive complexity 29 (threshold 15). Drivers by points: if/else 24, loops 3, boolean chains 2 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnstate/ipnstate.go"},"region":{"startLine":586}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b26eb87955d053501eb96ff88ae77d417e042d2a82d67de9fbfd988089a7f97"}},{"ruleId":"D2","level":"warning","message":{"text":"githook.CheckForbiddenMarkers (cognitive 29): githook.CheckForbiddenMarkers has cognitive complexity 29 (threshold 15). Drivers by points: if/else 18, loops 10, boolean chains 1 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"misc/git_hook/githook/pre-commit.go"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"78ea37e92911f64327d45c987d12f8f8aa8bf1e769225c83d958f79be5dcc6dc"}},{"ruleId":"D2","level":"warning","message":{"text":"Resolver.LookupIP (cognitive 29): Resolver.LookupIP has cognitive complexity 29 (threshold 15). Drivers by points: if/else 23, boolean chains 3, loops 2, match/switch 1 (nesting depth added 13). Of this number, 28 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnscache/dnscache.go"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"81ec8296a3fba8b3dbe549303eaac1370f067a7a2a9559d071600b5cdaaa8e8d"}},{"ruleId":"D2","level":"warning","message":{"text":"netutil.CalcAdvertiseRoutes (cognitive 29): netutil.CalcAdvertiseRoutes has cognitive complexity 29 (threshold 15). Drivers by points: if/else 24, loops 3, boolean chains 2 (nesting depth added 13). Of this number, 28 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netutil/routes.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"79bec65321b4d49a2ec427ede4419c5325f1cf862c74e7c50d1aa8e1534a3931"}},{"ruleId":"D2","level":"warning","message":{"text":"tailssh.doDropPrivileges (cognitive 29): tailssh.doDropPrivileges has cognitive complexity 29 (threshold 15). Drivers by points: if/else 27, boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":766}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3b24daae216fcf7f8e08a4b181c0cc29a27c539cded7f963654caa061df4806"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.bindSocket (cognitive 29): Conn.bindSocket has cognitive complexity 29 (threshold 15). Drivers by points: if/else 26, boolean chains 2, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3711}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b9f017eb680c337951216728eb5065fbe4a133837216a04dfe19d2801d3108b"}},{"ruleId":"D2","level":"warning","message":{"text":"userspaceEngine.Reconfig (cognitive 29): userspaceEngine.Reconfig has cognitive complexity 29 (threshold 15). Drivers by points: if/else 24, boolean chains 5 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":809}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba409cd036b4090110d20c1a3c519a3f3dd582f92a24e1e5b4d948ae57efb43e"}},{"ruleId":"D2","level":"warning","message":{"text":"macOSImpl.addProcesses (cognitive 29): macOSImpl.addProcesses has cognitive complexity 29 (threshold 15). Drivers by points: if/else 22, match/switch 5, boolean chains 1, loops 1 (nesting depth added 13). Of this number, 27 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/portlist_macos.go"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc5f13805cfa5902b71bcb865cb27cf92711cb2546852636316280b39e96e25f"}},{"ruleId":"D2","level":"warning","message":{"text":"Menu.watchIPNBusInner (cognitive 28): Menu.watchIPNBusInner has cognitive complexity 28 (threshold 15). Drivers by points: if/else 25, match/switch 2, loops 1 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":533}}}],"partialFingerprints":{"codehealthFindingId/v1":"0050e303575eac56c9fc5d2adfd85e1a065d323a1578a7a2d53c0cb9eb2b38cb"}},{"ruleId":"D2","level":"warning","message":{"text":"main.nodeMetaFromDERPMap (cognitive 28): main.nodeMetaFromDERPMap has cognitive complexity 28 (threshold 15). Drivers by points: if/else 18, loops 8, boolean chains 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":387}}}],"partialFingerprints":{"codehealthFindingId/v1":"09ea2e4187461696fd6d36f105f37d6b174941e02b9b3ea5bc953611e0769ca8"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runDNSStatus (cognitive 28): cli.runDNSStatus has cognitive complexity 28 (threshold 15). Drivers by points: if/else 15, loops 13 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-status.go"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c842c0cbf545d164393158b566f1823bcd5e5af581f901884e19720ffb24878"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.checkForAccidentalSettingReverts (cognitive 28): cli.checkForAccidentalSettingReverts has cognitive complexity 28 (threshold 15). Drivers by points: if/else 20, boolean chains 6, loops 2 (nesting depth added 7). Of this number, 22 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":1010}}}],"partialFingerprints":{"codehealthFindingId/v1":"6344faa6414621e52041a322fb90859942312c0fcff7cb8cadacb63256b6247e"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.runServe (cognitive 28): serveEnv.runServe has cognitive complexity 28 (threshold 15). Drivers by points: if/else 20, boolean chains 7, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"497ecb10bc62ad3345d53577cf60c1fbaa4558224852918442f30aa8d3e50c0d"}},{"ruleId":"D2","level":"warning","message":{"text":"main.handleWebSocket (cognitive 28): main.handleWebSocket has cognitive complexity 28 (threshold 15). Drivers by points: if/else 25, loops 2, match/switch 1 (nesting depth added 7). Most of this is not in the body itself: 10 of the 28 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 291, 271, 234, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vnet/vnet-main.go"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a4dd39c17fe75ac97ee6a977b4936c081e95f0b85f93ab62a9f741e4929ac7c"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.writePrettyDNSReply (cognitive 28): ipnlocal.writePrettyDNSReply has cognitive complexity 28 (threshold 15). Drivers by points: if/else 25, match/switch 2, loops 1 (nesting depth added 14). Of this number, 27 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":876}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc31aee9b2ad5b0a64f37e718a0300e684cf5ea492961e785d8cf9d889fe6a3b"}},{"ruleId":"D2","level":"warning","message":{"text":"profileManager.setProfilePrefs (cognitive 28): profileManager.setProfilePrefs has cognitive complexity 28 (threshold 15). Drivers by points: if/else 24, boolean chains 4 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/profiles.go"},"region":{"startLine":411}}}],"partialFingerprints":{"codehealthFindingId/v1":"321a051bb7fb45a887fd79486bba844ecd5fb8deb35b36d23e5dc98505cec885"}},{"ruleId":"D2","level":"warning","message":{"text":"ServeConfig.IsServingUnixAny (cognitive 28): ServeConfig.IsServingUnixAny has cognitive complexity 28 (threshold 15). Drivers by points: if/else 15, loops 13 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":272}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3143428904c1d64231ed5cbb500bb4bd763e8f45baecaaddc98fbee97b3c643"}},{"ruleId":"D2","level":"warning","message":{"text":"Reconciler.createOrUpdate (cognitive 28): Reconciler.createOrUpdate has cognitive complexity 28 (threshold 15). Drivers by points: if/else 23, loops 4, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/peerrelay/peerrelay.go"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"637c7d43577c8feeb32406b56125f156f346f1f559650eda5cf247aad1d28acd"}},{"ruleId":"D2","level":"warning","message":{"text":"dns.compileHostEntries (cognitive 28): dns.compileHostEntries has cognitive complexity 28 (threshold 15). Drivers by points: if/else 19, loops 6, boolean chains 3 (nesting depth added 13). Of this number, 24 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager.go"},"region":{"startLine":237}}}],"partialFingerprints":{"codehealthFindingId/v1":"819da31365a1d8ccdbd5be73123149476497076f581f01c7bf0c4e6a7fef20b8"}},{"ruleId":"D2","level":"warning","message":{"text":"Resolver.lookupIP (cognitive 28): Resolver.lookupIP has cognitive complexity 28 (threshold 15). Drivers by points: if/else 22, boolean chains 4, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnscache/dnscache.go"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"4edce02e30b39d77231768f1601e08cb5b1131f110abd932959e1a053f2f5d63"}},{"ruleId":"D2","level":"warning","message":{"text":"serverEndpoint.handleDiscoControlMsg (cognitive 28): serverEndpoint.handleDiscoControlMsg has cognitive complexity 28 (threshold 15). Drivers by points: if/else 23, boolean chains 2, loops 2, match/switch 1 (nesting depth added 11). Of this number, 26 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"b378ff3c6cce64453f58eabf691d3562a60d1abfa6ea48125f961a621b957a80"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.computeSyncIntersection (cognitive 28): tka.computeSyncIntersection has cognitive complexity 28 (threshold 15). Drivers by points: if/else 25, loops 3 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/sync.go"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0d87cd8e9b966a86faccbc84517533968e18500a83291e5bf76dce36be094d1"}},{"ruleId":"D2","level":"warning","message":{"text":"Env.tailLogFile (cognitive 28): Env.tailLogFile has cognitive complexity 28 (threshold 15). Drivers by points: if/else 17, loops 5, match/switch 5, boolean chains 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/qemu.go"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"f543e63042cac42aead73e51f57d5285c824ea033028fe8ca55332bd7964fea9"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.receiveDisco (cognitive 28): Conn.receiveDisco has cognitive complexity 28 (threshold 15). Drivers by points: if/else 24, boolean chains 3, loops 1 (nesting depth added 9). Of this number, 27 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock_linux.go"},"region":{"startLine":370}}}],"partialFingerprints":{"codehealthFindingId/v1":"21b806f142c5508ed161f1f858d10f8b95986b608a1714a09b3dbe5713c29c34"}},{"ruleId":"D2","level":"warning","message":{"text":"userspaceEngine.onOpenTimeout (cognitive 28): userspaceEngine.onOpenTimeout has cognitive complexity 28 (threshold 15). Drivers by points: if/else 24, boolean chains 2, loops 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/pendopen.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"17b1250d1e5d977188b7a58548e84e8026b7fbbe3ef43b3090ff25695575d225"}},{"ruleId":"D2","level":"warning","message":{"text":"main.proxyClassHandlerForSvc (cognitive 27): main.proxyClassHandlerForSvc has cognitive complexity 27 (threshold 15). Drivers by points: if/else 20, loops 7 (nesting depth added 15). Most of this is not in the body itself: 0 of the 27 points are its own statements and the rest belongs to one function literal inside it that branches (line 1000). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":999}}}],"partialFingerprints":{"codehealthFindingId/v1":"dad6dded97e4f10b15d93b3d90ed4e7f760951e34c51c8a8528bb80ec46fde74"}},{"ruleId":"D2","level":"warning","message":{"text":"tailscaleSTSReconciler.reconcileSTS (cognitive 27): tailscaleSTSReconciler.reconcileSTS has cognitive complexity 27 (threshold 15). Drivers by points: if/else 20, loops 6, boolean chains 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":637}}}],"partialFingerprints":{"codehealthFindingId/v1":"178bbbc0ebad24bce6123f4bdb829802449f6da728f6689e0eaca6467e4c1a88"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.printNetCheckReport (cognitive 27): cli.printNetCheckReport has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, loops 2, match/switch 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/netcheck.go"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"6641b7b7e738a4af527fdc9c8cc648e92ddd47ae3f6df827c9f1365952955732"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runWait (cognitive 27): cli.runWait has cognitive complexity 27 (threshold 15). Drivers by points: if/else 23, loops 3, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/wait.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"853aa32b2bfefc6a6f60dfba1451cd7fe318d6ac22ed682130c5942b8688afc6"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.enableFeatureInteractive (cognitive 27): serveEnv.enableFeatureInteractive has cognitive complexity 27 (threshold 15). Drivers by points: if/else 22, loops 5 (nesting depth added 10). Of this number, 24 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":793}}}],"partialFingerprints":{"codehealthFindingId/v1":"003eca2c1b85036e4dcb8b65c37eea79c89f7882e0f1b454d986293011cf3c42"}},{"ruleId":"D2","level":"warning","message":{"text":"main.getLocalBackend (cognitive 27): main.getLocalBackend has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, boolean chains 3 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":652}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8f6100c01e811731cab76875613f791cb6ceb04dfc64cd9407285e4a1e611bf"}},{"ruleId":"D2","level":"warning","message":{"text":"main.tryEngine (cognitive 27): main.tryEngine has cognitive complexity 27 (threshold 15). Drivers by points: if/else 25, boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":791}}}],"partialFingerprints":{"codehealthFindingId/v1":"415f0a5068bdedfd026ba5d809b92f35fd535a018e6e81ea0c2d595e2dc44667"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.unregisterClient (cognitive 27): Server.unregisterClient has cognitive complexity 27 (threshold 15). Drivers by points: if/else 23, loops 3, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":837}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d2aeb0e0cd5426e82025bfd06269b861ad75ba26fe741e50baf3fec04ac7ccf"}},{"ruleId":"D2","level":"warning","message":{"text":"fsFileOps.Rename (cognitive 27): fsFileOps.Rename has cognitive complexity 27 (threshold 15). Drivers by points: if/else 25, boolean chains 1, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/fileops_fs.go"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"58ddc93d19c535f08aa596e5574eda4cace181910e9505bad76cc2665a4d06c1"}},{"ruleId":"D2","level":"warning","message":{"text":"tapDevice.handleTAPFrame (cognitive 27): tapDevice.handleTAPFrame has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, match/switch 3 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/tap/tap_linux.go"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e4b12f9b520a5cf699d7c7e6d3a51097c28563315209bc9c4f1c90638eb8f29"}},{"ruleId":"D2","level":"warning","message":{"text":"Store.updateSecret (cognitive 27): Store.updateSecret has cognitive complexity 27 (threshold 15). Drivers by points: if/else 16, loops 10, boolean chains 1 (nesting depth added 11). Of this number, 15 points are the body\u0027s own statements and 12 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/kubestore/store_kube.go"},"region":{"startLine":443}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b594a41019c67fef14e756dcc9047da1829a9eaaf2a7b4ca6379d934194e2fc"}},{"ruleId":"D2","level":"warning","message":{"text":"proxyclass.validateNodePortRanges (cognitive 27): proxyclass.validateNodePortRanges has cognitive complexity 27 (threshold 15). Drivers by points: if/else 17, loops 7, boolean chains 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/proxyclass/proxyclass.go"},"region":{"startLine":414}}}],"partialFingerprints":{"codehealthFindingId/v1":"3877d5f4e62b43cdf0afd4b35dc237645628442a8393aa50dc7bb58634d76ef7"}},{"ruleId":"D2","level":"warning","message":{"text":"dnsfallback.lookup (cognitive 27): dnsfallback.lookup has cognitive complexity 27 (threshold 15). Drivers by points: if/else 19, loops 5, boolean chains 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnsfallback/dnsfallback.go"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4f5363b5daaaa9b55171704c59f7f331686ccb189bd1c94ee85c4c535873a30"}},{"ruleId":"D2","level":"warning","message":{"text":"netutil.DefaultInterfacePortable (cognitive 27): netutil.DefaultInterfacePortable has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, loops 3 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netutil/default_interface_portable.go"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"233a0f56237cc1dc12f7f5202660f69d7749d5bcb391d6b6c75ec3d5aef18ee2"}},{"ruleId":"D2","level":"warning","message":{"text":"netutil.CheckIPForwarding (cognitive 27): netutil.CheckIPForwarding has cognitive complexity 27 (threshold 15). Drivers by points: if/else 21, boolean chains 3, match/switch 2, loops 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netutil/ip_forward.go"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"729958aa8f77c0afa97f705879004027eefa3310831c9acc6e8f061181d77ca8"}},{"ruleId":"D2","level":"warning","message":{"text":"portmapper.selectBestService (cognitive 27): portmapper.selectBestService has cognitive complexity 27 (threshold 15). Drivers by points: if/else 18, loops 9 (nesting depth added 9). Of this number, 26 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/upnp.go"},"region":{"startLine":296}}}],"partialFingerprints":{"codehealthFindingId/v1":"01a31d99cabbeae0f2ad4ad62e7929d536a14df62004e873856b00f04ae03646"}},{"ruleId":"D2","level":"warning","message":{"text":"tailssh.matchAcceptEnvPattern (cognitive 27): tailssh.matchAcceptEnvPattern has cognitive complexity 27 (threshold 15). Drivers by points: if/else 19, loops 7, boolean chains 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/accept_env.go"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"dccd81dcf9a08c5433c2fb7c20c01a84b08b5e556e8b1c20f99b3393ad3b8f36"}},{"ruleId":"D2","level":"warning","message":{"text":"vmtest.waitForVMIP (cognitive 27): vmtest.waitForVMIP has cognitive complexity 27 (threshold 15). Drivers by points: if/else 21, loops 5, boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/tailmac.go"},"region":{"startLine":408}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b3b3aad047f89f8ed364899b0fe32ad9b910435d7afe84aabca032f352e2682"}},{"ruleId":"D2","level":"warning","message":{"text":"vnet.newVIP (cognitive 27): vnet.newVIP has cognitive complexity 27 (threshold 15). Drivers by points: if/else 19, boolean chains 4, loops 2, match/switch 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vip.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"083ab53f6b46f3751e6f2bb66891448bb56ad9c37ad61cd00a2b5ff66472038c"}},{"ruleId":"D2","level":"warning","message":{"text":"vnet.mkPacket (cognitive 27): vnet.mkPacket has cognitive complexity 27 (threshold 15). Drivers by points: if/else 19, match/switch 4, boolean chains 2, loops 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":3037}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa5d7fea4dd8a3e4f51d2a32ae3cf6f240959e967a1a9a447422025860be6163"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.createDNSResponse (cognitive 27): Server.createDNSResponse has cognitive complexity 27 (threshold 15). Drivers by points: if/else 21, loops 4, boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2526}}}],"partialFingerprints":{"codehealthFindingId/v1":"1176994f48c3c7c28416ea22aaeb88ebb004a71ee6fcaa4c8cc8788aa6ac73f7"}},{"ruleId":"D2","level":"warning","message":{"text":"cloudenv.getCloud (cognitive 27): cloudenv.getCloud has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, boolean chains 2, match/switch 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/cloudenv/cloudenv.go"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"28fe4f07a0f160dabf85e7064f71f68b9c1f1df6a66f62745d18e24528e81312"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.updateEndpoints (cognitive 27): Conn.updateEndpoints has cognitive complexity 27 (threshold 15). Drivers by points: if/else 26, boolean chains 1 (nesting depth added 13). Most of this is not in the body itself: 6 of the 27 points are its own statements and the rest belongs to one function literal inside it that branches (line 895). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":893}}}],"partialFingerprints":{"codehealthFindingId/v1":"659ac2efaab4fc6cd80746cb4ed91aa6d5cc98f5fdd22921b9ff573cfbd764a7"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.handlePingLocked (cognitive 27): Conn.handlePingLocked has cognitive complexity 27 (threshold 15). Drivers by points: if/else 23, boolean chains 4 (nesting depth added 8). Of this number, 22 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":2539}}}],"partialFingerprints":{"codehealthFindingId/v1":"c527d4f6a9380fa108c6cb38675a4503a03a5d37222cd9a1786458069b10601b"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.updateNodes (cognitive 27): Conn.updateNodes has cognitive complexity 27 (threshold 15). Drivers by points: if/else 16, loops 7, boolean chains 4 (nesting depth added 8). Of this number, 25 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3089}}}],"partialFingerprints":{"codehealthFindingId/v1":"465090b4b11699f8e8d8c61e2f497240e8c1f6e16b6c4416f9cd9cd48d8fad1d"}},{"ruleId":"D2","level":"warning","message":{"text":"PolicyLock.lockSlow (cognitive 27): PolicyLock.lockSlow has cognitive complexity 27 (threshold 15). Drivers by points: if/else 16, match/switch 6, jumps 3, boolean chains 1, loops 1 (nesting depth added 10). Most of this is not in the body itself: 4 of the 27 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 192, 171). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/gp/policylock_windows.go"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"6507c9c7dbd1f042a180d1e6daf5e59782f9afdb6eafff58210a1271cb885403"}},{"ruleId":"D2","level":"warning","message":{"text":"darwinRouteMon.Receive (cognitive 27): darwinRouteMon.Receive has cognitive complexity 27 (threshold 15). Drivers by points: if/else 24, loops 3 (nesting depth added 15). Of this number, 25 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon_darwin.go"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"2554db1722c74b6dd7f6722ed913d7cbb18b0dd23047527fa7b63e7e13883ffb"}},{"ruleId":"D2","level":"warning","message":{"text":"AppConnector.updateDomains (cognitive 26): AppConnector.updateDomains has cognitive complexity 26 (threshold 15). Drivers by points: if/else 17, loops 9 (nesting depth added 14). Of this number, 22 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"appc/appconnector.go"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"23c524af04a9686f6ee1dd98297e28729fdb138c0c4416ba166038464615ca5c"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.tailscaleUp (cognitive 26): Server.tailscaleUp has cognitive complexity 26 (threshold 15). Drivers by points: if/else 21, boolean chains 2, match/switch 2, loops 1 (nesting depth added 10). Of this number, 15 points are the body\u0027s own statements and 11 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":1136}}}],"partialFingerprints":{"codehealthFindingId/v1":"95015780a3c1597b2f42283e9411fa56968d0e78d63c486e7d22db2998a72189"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runDebug (cognitive 26): cli.runDebug has cognitive complexity 26 (threshold 15). Drivers by points: if/else 26 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"983f44272bd2634efdb7da0994fc058e3e3022d7737a1acae64871fb94f07819"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 26): main.main has cognitive complexity 26 (threshold 15). Drivers by points: if/else 23, loops 2, boolean chains 1 (nesting depth added 5). Of this number, 23 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vnet/vnet-main.go"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"72a17a08339808a85358d7426b684aeab8612ac9f3cc0d9b0815a191220c98b4"}},{"ruleId":"D2","level":"warning","message":{"text":"debugportmapper.serveDebugPortmap (cognitive 26): debugportmapper.serveDebugPortmap has cognitive complexity 26 (threshold 15). Drivers by points: if/else 21, match/switch 4, boolean chains 1 (nesting depth added 3). Of this number, 19 points are the body\u0027s own statements and 7 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/debugportmapper/debugportmapper.go"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddd741f5882536c54f22dfcd844648508d8fe282b8b2b55ceddfbded91381c7d"}},{"ruleId":"D2","level":"warning","message":{"text":"wakeonlan.getWoLMACs (cognitive 26): wakeonlan.getWoLMACs has cognitive complexity 26 (threshold 15). Drivers by points: if/else 19, loops 3, match/switch 3, boolean chains 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/wakeonlan/wakeonlan.go"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"949d8932b3ad81b69bb29049679a369bbd01c54e25a65343ac3d1629c67d6049"}},{"ruleId":"D2","level":"warning","message":{"text":"ipn.ExpandProxyTargetValue (cognitive 26): ipn.ExpandProxyTargetValue has cognitive complexity 26 (threshold 15). Drivers by points: if/else 23, boolean chains 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":761}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee56a2252684782b7c6453f04e109476aa4ba9e7954950ab5c4c903dcb65b7e6"}},{"ruleId":"D2","level":"warning","message":{"text":"Cache.Load (cognitive 26): Cache.Load has cognitive complexity 26 (threshold 15). Drivers by points: if/else 20, loops 6 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/netmapcache/netmapcache.go"},"region":{"startLine":323}}}],"partialFingerprints":{"codehealthFindingId/v1":"3872ad31cb53487cc497b6c43d16d2372787ebdcadfde8cf452534897be59475"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serveHTTP (cognitive 26): Server.serveHTTP has cognitive complexity 26 (threshold 15). Drivers by points: if/else 24, boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnserver/server.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"206e45f0653b6815f2f3daa040afbdccb0b29dd6252e606424da12fff123dbe0"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveWhoIsWithBackend (cognitive 26): Handler.serveWhoIsWithBackend has cognitive complexity 26 (threshold 15). Drivers by points: if/else 24, match/switch 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":556}}}],"partialFingerprints":{"codehealthFindingId/v1":"91267e263cc6ce8355b06f4aeafa0fb8a8ba575f6195cf2cd7011bbab722154d"}},{"ruleId":"D2","level":"warning","message":{"text":"githook.appendLargeAdditions (cognitive 26): githook.appendLargeAdditions has cognitive complexity 26 (threshold 15). Drivers by points: if/else 18, boolean chains 3, loops 3, match/switch 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"misc/git_hook/githook/largefiles.go"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"c88f74ef9475e688e19a6ef0219964cd7e6b081336f86fedf01fe935ff39df4f"}},{"ruleId":"D2","level":"warning","message":{"text":"resolvedManager.setConfigOverDBus (cognitive 26): resolvedManager.setConfigOverDBus has cognitive complexity 26 (threshold 15). Drivers by points: if/else 20, boolean chains 3, loops 3 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolved.go"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"937bd542cb0ef29ebd1bb6115a1248002d146de9cca07e542fd4f3e690cf934b"}},{"ruleId":"D2","level":"warning","message":{"text":"forwarder.send (cognitive 26): forwarder.send has cognitive complexity 26 (threshold 15). Drivers by points: if/else 24, boolean chains 2 (nesting depth added 5). Of this number, 18 points are the body\u0027s own statements and 8 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":627}}}],"partialFingerprints":{"codehealthFindingId/v1":"bee99fb810df08f1fe05e88b636e63d9266ffcf45afbf052127b93c2af4c774a"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.logConciseReport (cognitive 26): Client.logConciseReport has cognitive complexity 26 (threshold 15). Drivers by points: if/else 24, loops 2 (nesting depth added 11). Most of this is not in the body itself: 0 of the 26 points are its own statements and the rest belongs to one function literal inside it that branches (line 1300). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1299}}}],"partialFingerprints":{"codehealthFindingId/v1":"990ad9171541d5d74435da5dc2da6383742a2e6e6165ca2730ea0ae17e894007"}},{"ruleId":"D2","level":"warning","message":{"text":"netmon.getState (cognitive 26): netmon.getState has cognitive complexity 26 (threshold 15). Drivers by points: if/else 18, boolean chains 7, loops 1 (nesting depth added 7). Of this number, 16 points are the body\u0027s own statements and 10 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":591}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1220aea3e85bd9cb557c0fec93dcb6c84be4e016a4a652c61b026d4ea4c3eab"}},{"ruleId":"D2","level":"warning","message":{"text":"sshSession.newIncubatorCommand (cognitive 26): sshSession.newIncubatorCommand has cognitive complexity 26 (threshold 15). Drivers by points: if/else 17, boolean chains 5, match/switch 4 (nesting depth added 6). Of this number, 24 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"67bf716c77d24e85e2a2aeef185f5ee8288da59f86fbcb8aa41b629c6e13fae0"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.SeedAUMs (cognitive 26): tka.SeedAUMs has cognitive complexity 26 (threshold 15). Drivers by points: if/else 20, loops 6 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/sync.go"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"37489177ee16274ebc8cd29634b58053df39a7eebeb6be112f2fe9d5e5aa8903"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.markActiveChain (cognitive 26): tka.markActiveChain has cognitive complexity 26 (threshold 15). Drivers by points: if/else 22, loops 3, boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tailchonk.go"},"region":{"startLine":706}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8fd2eb7e9d077f61e7a924917cc9090c12faeacc6f860d8297136867cdee161"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.computeStateAt (cognitive 26): tka.computeStateAt has cognitive complexity 26 (threshold 15). Drivers by points: if/else 22, boolean chains 2, loops 2 (nesting depth added 12). Of this number, 20 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tka.go"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"e87d162f659752bad2cd728218a2efc4adf3aa2b5615c3f46b4010a2cb38aaef"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ListenFunnel (cognitive 26): Server.ListenFunnel has cognitive complexity 26 (threshold 15). Drivers by points: if/else 23, match/switch 2, loops 1 (nesting depth added 7). Of this number, 20 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":1474}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd95ab6e5dd307c1c453824acb8a4fe4e384251d3ea1c94809a48360c22f181f"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ServeHTTP (cognitive 26): Server.ServeHTTP has cognitive complexity 26 (threshold 15). Drivers by points: if/else 21, loops 4, boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/mts/mts.go"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"aeb015a4906ba97c9421ba2c81410f3d4b074cf8d4715fd9d5f1ad86f6182475"}},{"ruleId":"D2","level":"warning","message":{"text":"Machine.ListenPacket (cognitive 26): Machine.ListenPacket has cognitive complexity 26 (threshold 15). Drivers by points: if/else 22, boolean chains 2, match/switch 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/natlab.go"},"region":{"startLine":628}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c59471f05ec34f67ed594227f10f5d741fbfa977d7fe75122af096c0040f200"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxfw.DebugNetfilter (cognitive 26): linuxfw.DebugNetfilter has cognitive complexity 26 (threshold 15). Drivers by points: if/else 11, loops 11, match/switch 4 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab8f49a98c53203f810cc309eccc19ae2e5e2ee3000e24b63e4bacff155e128c"}},{"ruleId":"D2","level":"warning","message":{"text":"gro.RXChecksumOffload (cognitive 26): gro.RXChecksumOffload has cognitive complexity 26 (threshold 15). Drivers by points: if/else 20, boolean chains 5, match/switch 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/gro/gro.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"c341c2f05cabed5cdbf1e088ffd1eec139cca66234dba829f097f15ab0aaef91"}},{"ruleId":"D2","level":"warning","message":{"text":"lsaSession.logonAs (cognitive 26): lsaSession.logonAs has cognitive complexity 26 (threshold 15). Drivers by points: if/else 22, boolean chains 2, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/s4u/lsa_windows.go"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a9b9e0c0031dbb9c9900b23e6d659222b10aabb65296e3c28ae855fe0638f95"}},{"ruleId":"D2","level":"warning","message":{"text":"main.installIngressForwardingRuleForDNSTarget (cognitive 25): main.installIngressForwardingRuleForDNSTarget has cognitive complexity 25 (threshold 15). Drivers by points: if/else 20, boolean chains 3, loops 2 (nesting depth added 6). Of this number, 23 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/forwarding.go"},"region":{"startLine":193}}}],"partialFingerprints":{"codehealthFindingId/v1":"61196451079e126c2c48d0fa29cef99d071aa561136e8fe901ae13c128e8209b"}},{"ruleId":"D2","level":"warning","message":{"text":"main.handlersForIngress (cognitive 25): main.handlersForIngress has cognitive complexity 25 (threshold 15). Drivers by points: if/else 17, loops 5, boolean chains 3 (nesting depth added 7). Most of this is not in the body itself: 9 of the 25 points are its own statements and the rest belongs to one function literal inside it that branches (line 325). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e3e19c5381c7c2fdf9ea5397c7e8d3f95bd0aadbdc89d0de21068ee567deeea"}},{"ruleId":"D2","level":"warning","message":{"text":"configLoader.watchConfigFileChanges (cognitive 25): configLoader.watchConfigFileChanges has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, match/switch 2, boolean chains 1, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/internal/config/config.go"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"e251dc00a4cb9494b59a473d4bf6463567fa8f884cee3e7b8c5d77b2b2c38f49"}},{"ruleId":"D2","level":"warning","message":{"text":"proxy.serve (cognitive 25): proxy.serve has cognitive complexity 25 (threshold 15). Drivers by points: if/else 22, boolean chains 2, match/switch 1 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/pgproxy/pgproxy.go"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"40d0791d966fcfa270bb12c454203b4aa30a0fe6b9ba9d19f26b666860460ce3"}},{"ruleId":"D2","level":"warning","message":{"text":"main.run (cognitive 25): main.run has cognitive complexity 25 (threshold 15). Drivers by points: if/else 24, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/sniproxy/sniproxy.go"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7a03f3782bafb3c5cab7ac29e34c275fc989dac0c7902dab729ac3872668029"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.usageFuncOpt (cognitive 25): cli.usageFuncOpt has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, boolean chains 2, loops 2 (nesting depth added 9). Most of this is not in the body itself: 11 of the 25 points are its own statements and the rest belongs to one function literal inside it that branches (line 471). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/cli.go"},"region":{"startLine":436}}}],"partialFingerprints":{"codehealthFindingId/v1":"6901195ef3f4047e9cd899a313941d93c5cd1bd8757ae43959628b03a637653c"}},{"ruleId":"D2","level":"warning","message":{"text":"main.babysitProc (cognitive 25): main.babysitProc has cognitive complexity 25 (threshold 15). Drivers by points: if/else 19, loops 3, match/switch 3 (nesting depth added 11). Of this number, 16 points are the body\u0027s own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled_windows.go"},"region":{"startLine":422}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c870f853815a9afc931d8a0de73d7dc3c849bb6064baef669057bb531e396c6"}},{"ruleId":"D2","level":"warning","message":{"text":"main.testsForShard (cognitive 25): main.testsForShard has cognitive complexity 25 (threshold 15). Drivers by points: if/else 17, loops 6, boolean chains 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":181}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c99be3c4c62d8053c14731ee58d2365862a302b1eb00c7cfb311cca503d540a"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.verifyClient (cognitive 25): Server.verifyClient has cognitive complexity 25 (threshold 15). Drivers by points: if/else 25 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":1581}}}],"partialFingerprints":{"codehealthFindingId/v1":"51b121aa841feb00cad875914a1b88bbf35c4edb668ca2283e9e1fe1ef676074"}},{"ruleId":"D2","level":"warning","message":{"text":"taildrop.serveFiles (cognitive 25): taildrop.serveFiles has cognitive complexity 25 (threshold 15). Drivers by points: if/else 23, boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/localapi.go"},"region":{"startLine":403}}}],"partialFingerprints":{"codehealthFindingId/v1":"89b62e2e58c63938ac2da3d3084acb0cce1b9cf340d6b3944fa9225c169d641f"}},{"ruleId":"D2","level":"warning","message":{"text":"hostinfo.linuxVersionMeta (cognitive 25): hostinfo.linuxVersionMeta has cognitive complexity 25 (threshold 15). Drivers by points: if/else 19, match/switch 3, boolean chains 2, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"hostinfo/hostinfo_linux.go"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca0400ef4b20b555874f738697c7787b61c0083af5aad58f00b4ef79e56e5bab"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.applyPrefsToHostinfoLocked (cognitive 25): LocalBackend.applyPrefsToHostinfoLocked has cognitive complexity 25 (threshold 15). Drivers by points: if/else 19, boolean chains 5, loops 1 (nesting depth added 7). Of this number, 22 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6636}}}],"partialFingerprints":{"codehealthFindingId/v1":"550a53b57371c5a5d8f2832de1a185b7e0df71d5c2a7dff616cd56ee28718aa7"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.forwardTCPWithProxyProtocol (cognitive 25): LocalBackend.forwardTCPWithProxyProtocol has cognitive complexity 25 (threshold 15). Drivers by points: if/else 25 (nesting depth added 11). Of this number, 22 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":720}}}],"partialFingerprints":{"codehealthFindingId/v1":"684199052b07941197158cb0b98c87db3aa24fcbbb1d076cf44bc26a56e6517d"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveBugReport (cognitive 25): Handler.serveBugReport has cognitive complexity 25 (threshold 15). Drivers by points: if/else 22, loops 2, match/switch 1 (nesting depth added 6). Of this number, 24 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"88f80fb78b556a5c75bf45d8ccd05111bd121cdbb6cd21cc34580413b8eacb84"}},{"ruleId":"D2","level":"warning","message":{"text":"logtail.UploadLogs (cognitive 25): logtail.UploadLogs has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, boolean chains 3, loops 1 (nesting depth added 9). Of this number, 19 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"43ee765bf0c6d525d82274e57f79a12c21a7926dd921eda584e7e69a61671c7d"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxBatchingConn.coalesceMessages (cognitive 25): linuxBatchingConn.coalesceMessages has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, boolean chains 3, loops 1 (nesting depth added 11). Of this number, 23 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/batching/conn_linux.go"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"630633d8fbab7abfe6edb64f80cad8d8c5a0ae87dd82898f7bdbbf85815b44fc"}},{"ruleId":"D2","level":"warning","message":{"text":"errorHandler.handleError (cognitive 25): errorHandler.handleError has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, boolean chains 2, match/switch 2 (nesting depth added 6). Of this number, 22 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/tsweb.go"},"region":{"startLine":781}}}],"partialFingerprints":{"codehealthFindingId/v1":"be198fc5ae62c023d29ebe2df25c71b3c4fb02dd9916c418d2ebf5dcfea9b1f4"}},{"ruleId":"D2","level":"warning","message":{"text":"osdiag.getSecurityInfo (cognitive 25): osdiag.getSecurityInfo has cognitive complexity 25 (threshold 15). Drivers by points: if/else 18, match/switch 4, loops 3 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/osdiag/osdiag_windows.go"},"region":{"startLine":517}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f2cc4b20f81db91047e792e9d6d4c7152ae4b274158693e2cce86eb9f44ec5e"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.handleLocalPackets (cognitive 25): Impl.handleLocalPackets has cognitive complexity 25 (threshold 15). Drivers by points: if/else 20, boolean chains 4, match/switch 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":842}}}],"partialFingerprints":{"codehealthFindingId/v1":"84185b8f2ce503ce5432b059182fe63a6ce59233f6063c3b9ecc488888eeb091"}},{"ruleId":"D2","level":"warning","message":{"text":"userspaceEngine.linkChange (cognitive 25): userspaceEngine.linkChange has cognitive complexity 25 (threshold 15). Drivers by points: if/else 21, boolean chains 2, match/switch 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":1144}}}],"partialFingerprints":{"codehealthFindingId/v1":"9043925622de93b999227e797d999c28ec11ee51bfe9306268813223a1397dae"}},{"ruleId":"D2","level":"warning","message":{"text":"windowsManager.setPrimaryDNS (cognitive 25): windowsManager.setPrimaryDNS has cognitive complexity 25 (threshold 15). Drivers by points: if/else 23, loops 2 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":287}}}],"partialFingerprints":{"codehealthFindingId/v1":"73fda14a02be3d0af95f5ee15c4420ba32f985fd381839ab1fda6157997a30c2"}},{"ruleId":"D2","level":"warning","message":{"text":"windowsManager.getBasePrimaryResolver (cognitive 25): windowsManager.getBasePrimaryResolver has cognitive complexity 25 (threshold 15). Drivers by points: if/else 17, loops 7, jumps 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":654}}}],"partialFingerprints":{"codehealthFindingId/v1":"43581b225dd1ccf28620fdfa5b385c28df84f1ebc9da367bd99ad66316c8bb9c"}},{"ruleId":"D2","level":"warning","message":{"text":"Menu.eventLoop (cognitive 24): Menu.eventLoop has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, match/switch 2, loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"48458e9aebc19a29f7e57cd49127cc31add1868523cae264202251ed32b3933a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.ensureIPForwarding (cognitive 24): main.ensureIPForwarding has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, loops 2, boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/forwarding.go"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"57b0caec9f40e7f8b62b97d4373f31062b05dabb0d9a034a1157bc6f8bcb7a9a"}},{"ruleId":"D2","level":"warning","message":{"text":"main.serviceHandlerForIngress (cognitive 24): main.serviceHandlerForIngress has cognitive complexity 24 (threshold 15). Drivers by points: if/else 15, loops 6, boolean chains 3 (nesting depth added 11). Most of this is not in the body itself: 0 of the 24 points are its own statements and the rest belongs to one function literal inside it that branches (line 1272). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1271}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e05661b775608d2a7bc3ba11d1f94d8ea5626612c0ed60b01b554b1a232b8e5"}},{"ruleId":"D2","level":"warning","message":{"text":"KubeAPIServerTSServiceReconciler.maybeAdvertiseServices (cognitive 24): KubeAPIServerTSServiceReconciler.maybeAdvertiseServices has cognitive complexity 24 (threshold 15). Drivers by points: if/else 22, boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/api-server-proxy-pg.go"},"region":{"startLine":342}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f3380f5bafa4d9e32963510aa0f340d14afcc5b10b23bc9414dffc1ad4318cc"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 24): main.main has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, loops 2, match/switch 1 (nesting depth added 7). Of this number, 23 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/generate/main.go"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2ed68426f2e1c8479c6ed0f1bb681de9f1a4d010775f85b6e70043dbf81388b"}},{"ruleId":"D2","level":"warning","message":{"text":"NameserverReconciler.Reconcile (cognitive 24): NameserverReconciler.Reconcile has cognitive complexity 24 (threshold 15). Drivers by points: if/else 23, boolean chains 1 (nesting depth added 6). Of this number, 21 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/nameserver.go"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ed58e4f3030e4e5d2d14b57f194f20bf517b218ed0d0baddba7b08d560dbd51"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.validate (cognitive 24): ProxyGroupReconciler.validate has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, boolean chains 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fc3bf83c6ae295d429a281d863ab3e37edc3f14896e4da32233d0d24cf158ce"}},{"ruleId":"D2","level":"warning","message":{"text":"HAServiceReconciler.maybeCleanupProxyGroup (cognitive 24): HAServiceReconciler.maybeCleanupProxyGroup has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, loops 3 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":428}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3a022805cd4d0455ec45d22e7d69d82b5a526cf7fdcb1efa48aa74fb7974cff"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 24): main.main has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, loops 2, boolean chains 1 (nesting depth added 9). Most of this is not in the body itself: 8 of the 24 points are its own statements and the rest belongs to one function literal inside it that branches (line 159). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/proxy-to-grafana/proxy-to-grafana.go"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"227d5aad4b404190916fe3ecca1a8186cb4f2331e1b93a211b54ecc3d955a0d6"}},{"ruleId":"D2","level":"warning","message":{"text":"sclient.run (cognitive 24): sclient.run has cognitive complexity 24 (threshold 15). Drivers by points: if/else 20, match/switch 2, boolean chains 1, loops 1 (nesting depth added 11). Of this number, 16 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":1093}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd926818eb6a364848495835199037c44dc4f11e6d07539348111254a00b41cd"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 24): main.main has cognitive complexity 24 (threshold 15). Drivers by points: if/else 23, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/xdp/headers/update.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"b635ad7f03a953aef94b56f69d1ad632b1622bc37fa0037cb697aca443753305"}},{"ruleId":"D2","level":"warning","message":{"text":"ipn.exitNodeIPOfArg (cognitive 24): ipn.exitNodeIPOfArg has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, boolean chains 1, loops 1, match/switch 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":885}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9dd71dc4bc0e5972f13feef646cd544bdcd8c843bb5d546e07d1b8d48e9059c"}},{"ruleId":"D2","level":"warning","message":{"text":"localListener.Run (cognitive 24): localListener.Run has cognitive complexity 24 (threshold 15). Drivers by points: if/else 22, boolean chains 1, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"e49aa908c2e877961fab6148ddcdaa48bc60c117edb403c80c0242da62185ee5"}},{"ruleId":"D2","level":"warning","message":{"text":"store.maybeMigrateLocalStateFile (cognitive 24): store.maybeMigrateLocalStateFile has cognitive complexity 24 (threshold 15). Drivers by points: if/else 22, boolean chains 1, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/stores.go"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"71bb205a12bf1c827b387250c4f335ad1e60cac1b67e0db24fc07b7bc808f98d"}},{"ruleId":"D2","level":"warning","message":{"text":"netns.interfaceIndexFor (cognitive 24): netns.interfaceIndexFor has cognitive complexity 24 (threshold 15). Drivers by points: if/else 20, match/switch 2, boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_darwin.go"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef0acbc0c17ef968a57f592b808c0da4bbf07d2efb4679f0371f218873d1a20b"}},{"ruleId":"D2","level":"warning","message":{"text":"Wrapper.filterPacketOutboundToWireGuard (cognitive 24): Wrapper.filterPacketOutboundToWireGuard has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21, match/switch 2, boolean chains 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":745}}}],"partialFingerprints":{"codehealthFindingId/v1":"54c2d2e491dd60b1715526a295eca05e9b98716d9be4a0d4ec92194ab32dc128"}},{"ruleId":"D2","level":"warning","message":{"text":"derpProber.updateMap (cognitive 24): derpProber.updateMap has cognitive complexity 24 (threshold 15). Drivers by points: if/else 20, loops 3, boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":566}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ee747088d071f8d1e2531fe7fce07ba0b082e221696a2be9d523c4a7e47cdde"}},{"ruleId":"D2","level":"warning","message":{"text":"tka.computeChainCandidates (cognitive 24): tka.computeChainCandidates has cognitive complexity 24 (threshold 15). Drivers by points: if/else 19, loops 4, boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tka.go"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c4617d29f2ff7ec52e969c055255f5e9d8ea66656d2b6660f651a3e000e6274"}},{"ruleId":"D2","level":"warning","message":{"text":"LogCatcher.ServeHTTP (cognitive 24): LogCatcher.ServeHTTP has cognitive complexity 24 (threshold 15). Drivers by points: if/else 20, boolean chains 2, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/integration.go"},"region":{"startLine":421}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c0a7a879f29b996f057bd49e5b821edb43aab1959cecd62913adf2299ec28f2"}},{"ruleId":"D2","level":"warning","message":{"text":"Env.ApproveRoutes (cognitive 24): Env.ApproveRoutes has cognitive complexity 24 (threshold 15). Drivers by points: if/else 15, loops 6, boolean chains 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":1122}}}],"partialFingerprints":{"codehealthFindingId/v1":"2eae13fe06f9e09f0e05ed52b5e4bb1a3c5344617a87e56942e231e5384b4c04"}},{"ruleId":"D2","level":"warning","message":{"text":"zstdframe.NextSize (cognitive 24): zstdframe.NextSize has cognitive complexity 24 (threshold 15). Drivers by points: if/else 22, loops 2 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/zstdframe/zstd.go"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"456ad07de36f400f555cd1ed703836656dbddff2358673db562f2bfcc506085c"}},{"ruleId":"D2","level":"warning","message":{"text":"record.toMessage (cognitive 24): record.toMessage has cognitive complexity 24 (threshold 15). Drivers by points: if/else 16, loops 5, match/switch 2, boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netlog/record.go"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cf3652d3b7c4ee19c7933569cd65a13b6bcf58cafe3e42f326f75404b755cf4"}},{"ruleId":"D2","level":"warning","message":{"text":"main.handleBootstrapDNS (cognitive 23): main.handleBootstrapDNS has cognitive complexity 23 (threshold 15). Drivers by points: if/else 22, boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/bootstrap_dns.go"},"region":{"startLine":138}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a69f3b442bfc0fc8f449d929aebf688e296a28951a05231aedfc4b43216a279"}},{"ruleId":"D2","level":"warning","message":{"text":"main.watchBusOnce (cognitive 23): main.watchBusOnce has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, loops 4, boolean chains 1 (nesting depth added 12). Of this number, 19 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":178}}}],"partialFingerprints":{"codehealthFindingId/v1":"55fe1422f511eb424f3ff3da1da186cb1ecbe8f434bf843cc177e728c75873ec"}},{"ruleId":"D2","level":"warning","message":{"text":"main.serviceHandlerForIngressPG (cognitive 23): main.serviceHandlerForIngressPG has cognitive complexity 23 (threshold 15). Drivers by points: if/else 14, loops 6, boolean chains 3 (nesting depth added 11). Most of this is not in the body itself: 0 of the 23 points are its own statements and the rest belongs to one function literal inside it that branches (line 1808). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1807}}}],"partialFingerprints":{"codehealthFindingId/v1":"a36f0c5238941050bcbc91ad188077ec99bd489c67f68764d209b81132e0ae4f"}},{"ruleId":"D2","level":"warning","message":{"text":"RecorderReconciler.ensureAuthSecretsCreated (cognitive 23): RecorderReconciler.ensureAuthSecretsCreated has cognitive complexity 23 (threshold 15). Drivers by points: if/else 20, match/switch 2, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":447}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b9aa003ca51a1ee05aa78fb5376ab045fb43367fcfac20302ac2852e77d190f"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runPVEAppliance (cognitive 23): cli.runPVEAppliance has cognitive complexity 23 (threshold 15). Drivers by points: if/else 22, boolean chains 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-pve-appliance.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"806c5a205139510be9b18220a7a3a6fd4a7d5acb8a54bb278c4483d2b1063d6f"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runLocalAPI (cognitive 23): cli.runLocalAPI has cognitive complexity 23 (threshold 15). Drivers by points: if/else 22, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":541}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9db4417f5255c1a69815665f9c6d8d358b3754adcf4e73b3ca3bd8b2ebe816c"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runDNSQuery (cognitive 23): cli.runDNSQuery has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, loops 5 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/dns-query.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"79bd1db0ad2e32570f20bba7aa6bafe247b3178894580e9791d3a484a45e5af7"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runFileGetOneBatch (cognitive 23): cli.runFileGetOneBatch has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, boolean chains 3, loops 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":710}}}],"partialFingerprints":{"codehealthFindingId/v1":"b11537def6ee1ad4b79c50338bae4363db6d32598fa066f2be3d5aec05c47a37"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runWeb (cognitive 23): cli.runWeb has cognitive complexity 23 (threshold 15). Drivers by points: if/else 19, boolean chains 3, match/switch 1 (nesting depth added 5). Of this number, 16 points are the body\u0027s own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/web.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"13dbdfeb3f852d5da6caafd7039f98287a282a8bed5fd6a0e2110c9229b6d904"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.decodePlistValue (cognitive 23): cli.decodePlistValue has cognitive complexity 23 (threshold 15). Drivers by points: if/else 17, match/switch 4, loops 2 (nesting depth added 14). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance_darwin.go"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc122c93cdea409598a7a4c3edb8ad6f5593244e5ea359f64eaa56762b278057"}},{"ruleId":"D2","level":"warning","message":{"text":"main.run (cognitive 23): main.run has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, boolean chains 3, match/switch 2 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":430}}}],"partialFingerprints":{"codehealthFindingId/v1":"9da3f645758fcd5c519303c91be90c3556d4399a0d71f3a657a8abb287daf3b9"}},{"ruleId":"D2","level":"warning","message":{"text":"controlbase.Server (cognitive 23): controlbase.Server has cognitive complexity 23 (threshold 15). Drivers by points: if/else 23 (nesting depth added 3). Of this number, 20 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlbase/handshake.go"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"4f431b4cb833d3df80cb6338548864c38604c4d2f526b4ba1fa37ca45ed70c18"}},{"ruleId":"D2","level":"warning","message":{"text":"client.rewriteDNSResponse (cognitive 23): client.rewriteDNSResponse has cognitive complexity 23 (threshold 15). Drivers by points: if/else 21, loops 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1329}}}],"partialFingerprints":{"codehealthFindingId/v1":"0af6840377fa7915f7743ffe2628cfc15cbcde3368b08e4dc53950b7e79dd20a"}},{"ruleId":"D2","level":"warning","message":{"text":"fileDeleter.waitAndDelete (cognitive 23): fileDeleter.waitAndDelete has cognitive complexity 23 (threshold 15). Drivers by points: if/else 15, loops 4, boolean chains 3, match/switch 1 (nesting depth added 12). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/delete.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5232d3f89b6141ec993cd5ceb330d4a9549a12d4478efa9dfcecf07b14c9056"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.populatePeerStatusLocked (cognitive 23): LocalBackend.populatePeerStatusLocked has cognitive complexity 23 (threshold 15). Drivers by points: if/else 12, loops 9, boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1576}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c3d0eca2e013a5a189d8306542c93bb559ae592994046c94658f112010e9e8b"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.WhoIs (cognitive 23): LocalBackend.WhoIs has cognitive complexity 23 (threshold 15). Drivers by points: if/else 19, loops 3, boolean chains 1 (nesting depth added 10). Of this number, 22 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1706}}}],"partialFingerprints":{"codehealthFindingId/v1":"e37ccd070b8e3d9ace9ca1012009c8c650ac862382e17918170b336b7e9f4fb8"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.applyExitNodeSysPolicyLocked (cognitive 23): LocalBackend.applyExitNodeSysPolicyLocked has cognitive complexity 23 (threshold 15). Drivers by points: if/else 21, boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":2256}}}],"partialFingerprints":{"codehealthFindingId/v1":"852df7ac64f02bc66093bbd802dee72a8412668fe7620a2e8e67040a9ec56139"}},{"ruleId":"D2","level":"warning","message":{"text":"logpolicy.awaitGokrazyNetwork (cognitive 23): logpolicy.awaitGokrazyNetwork has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, boolean chains 2, match/switch 2, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":968}}}],"partialFingerprints":{"codehealthFindingId/v1":"035ba8498547360b1832b3c4842f15be0a60bc9d410f02be94bafeff543f8d2a"}},{"ruleId":"D2","level":"warning","message":{"text":"Logger.appendMetadata (cognitive 23): Logger.appendMetadata has cognitive complexity 23 (threshold 15). Drivers by points: if/else 19, boolean chains 4 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":813}}}],"partialFingerprints":{"codehealthFindingId/v1":"09814c3b49ab4590d170eab392ae7e8e0ae0a8d4c6428320b44f2046dc23dbda"}},{"ruleId":"D2","level":"warning","message":{"text":"netns.getInterfaceIndex (cognitive 23): netns.getInterfaceIndex has cognitive complexity 23 (threshold 15). Drivers by points: if/else 19, boolean chains 4 (nesting depth added 5). Most of this is not in the body itself: 8 of the 23 points are its own statements and the rest belongs to one function literal inside it that branches (line 59). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_darwin.go"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f6a15a3b4f6e216c5191a78e37d8c937ab4b95dfdffa779daf1dae1811404ef"}},{"ruleId":"D2","level":"warning","message":{"text":"speedtest.doTest (cognitive 23): speedtest.doTest has cognitive complexity 23 (threshold 15). Drivers by points: if/else 16, match/switch 3, jumps 2, boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/speedtest/speedtest_server.go"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fe51a3bdf968a0146c779ace99af974b30627dffdc14a551ce37a32cb8fdd71"}},{"ruleId":"D2","level":"warning","message":{"text":"Wrapper.Read (cognitive 23): Wrapper.Read has cognitive complexity 23 (threshold 15). Drivers by points: if/else 20, boolean chains 2, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":871}}}],"partialFingerprints":{"codehealthFindingId/v1":"7778a98aa548e4af7de993f83d5c2e8e3a2d1645941e9fa5e0cac33bf1f5325d"}},{"ruleId":"D2","level":"warning","message":{"text":"sshSession.startWithPTY (cognitive 23): sshSession.startWithPTY has cognitive complexity 23 (threshold 15). Drivers by points: if/else 22, loops 1 (nesting depth added 5). Most of this is not in the body itself: 9 of the 23 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1051, 1040). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":1025}}}],"partialFingerprints":{"codehealthFindingId/v1":"8df1ce039ef51afc698af36a1e1c08ed6c5ad22df67a86547b74ede14864bec8"}},{"ruleId":"D2","level":"warning","message":{"text":"Authority.MakeRetroactiveRevocation (cognitive 23): Authority.MakeRetroactiveRevocation has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, loops 5 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tka.go"},"region":{"startLine":806}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f8abaefef7787b4bbfa59d0219e648ac739830ea9d553dc3aa383b8127a6100"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.resolveAuthKey (cognitive 23): Server.resolveAuthKey has cognitive complexity 23 (threshold 15). Drivers by points: if/else 20, boolean chains 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":999}}}],"partialFingerprints":{"codehealthFindingId/v1":"fec5db6927cb692f15720d75d5457c35b8e44211945bafcc41826c33d2d08d01"}},{"ruleId":"D2","level":"warning","message":{"text":"DepChecker.Check (cognitive 23): DepChecker.Check has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18, loops 5 (nesting depth added 7). Of this number, 22 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/deptest/deptest.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"0140f92c600b270356be99c123f59f40338eb380562230721261683c9aa286b0"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.RunInstance (cognitive 23): Server.RunInstance has cognitive complexity 23 (threshold 15). Drivers by points: if/else 16, loops 5, boolean chains 2 (nesting depth added 6). Of this number, 22 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/mts/mts.go"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"057c9575fa683109d1cbb59c458fc3d73ce3e007f3e1badbcfd97d3dd4e713ce"}},{"ruleId":"D2","level":"warning","message":{"text":"vmtest.ensureImage (cognitive 23): vmtest.ensureImage has cognitive complexity 23 (threshold 15). Drivers by points: if/else 23 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/images.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2f87e756ab3f3e0a999fdb5d30e655401d3071e99f44157be0d89b6f083c3a3"}},{"ruleId":"D2","level":"warning","message":{"text":"vmtest.ensureVersionBinaries (cognitive 23): vmtest.ensureVersionBinaries has cognitive complexity 23 (threshold 15). Drivers by points: if/else 21, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/version.go"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"165938d1c52327ff1dac8409092a6cdfc0aaa3191911303c159a44d6103f4f99"}},{"ruleId":"D2","level":"warning","message":{"text":"endpoint.startDiscoPingLocked (cognitive 23): endpoint.startDiscoPingLocked has cognitive complexity 23 (threshold 15). Drivers by points: if/else 16, boolean chains 6, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1293}}}],"partialFingerprints":{"codehealthFindingId/v1":"4dd1dcf5f3a5da765befefaa1f7c8d635250dd76be755da55728ee141bde181e"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.upsertPeerLocked (cognitive 23): Conn.upsertPeerLocked has cognitive complexity 23 (threshold 15). Drivers by points: if/else 19, boolean chains 3, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3186}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e976ac8bc6516494e066c6b98ad4de3f61f8d005cc43c2009d581bfed7d33fc"}},{"ruleId":"D2","level":"warning","message":{"text":"KubeAPIServerTSServiceReconciler.maybeProvision (cognitive 22): KubeAPIServerTSServiceReconciler.maybeProvision has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, boolean chains 2 (nesting depth added 3). Of this number, 17 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/api-server-proxy-pg.go"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c9253b05eb85902943c037c634777b93c222f5aa4a32069da4d6c851a2b2d37"}},{"ruleId":"D2","level":"warning","message":{"text":"RecorderReconciler.Reconcile (cognitive 22): RecorderReconciler.Reconcile has cognitive complexity 22 (threshold 15). Drivers by points: if/else 22 (nesting depth added 6). Of this number, 19 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"54e8d97bdb60feffd61d61418673a6c20c5ea43665dc477df3afd5f68e470954"}},{"ruleId":"D2","level":"warning","message":{"text":"main.newConnAndMeasureFn (cognitive 22): main.newConnAndMeasureFn has cognitive complexity 22 (threshold 15). Drivers by points: if/else 18, boolean chains 3, match/switch 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"7390c2e24e9935c300780934de36b017cc178f319ebd29ecad86d1b6210845e7"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 22): main.main has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, loops 2, boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/sync-containers/main.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8d9c8425afb275324edf9f897abe240823bb673f9888af7075edcca6589f3da"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runNetcheck (cognitive 22): cli.runNetcheck has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, boolean chains 2, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/netcheck.go"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"60394724f2ae3a5ddf5417e4470b3f8fda07f3c94e18de62f5d5921efbc28a1a"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.serviceActionTypes (cognitive 22): cli.serviceActionTypes has cognitive complexity 22 (threshold 15). Drivers by points: if/else 16, loops 5, boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/service.go"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"6033fb1f127ef98e6cfe917511818bf6eb844e39cf1469c5832115b030e4a99e"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runSSH (cognitive 22): cli.runSSH has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, boolean chains 2 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/ssh.go"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d6d1ccbd1a936e56ab1f6fb208f8b27aff20b5c674611a9226dceb917a20ae8"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runTailnetLockInit (cognitive 22): cli.runTailnetLockInit has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, loops 3 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"051d9cd13f56341f1dda431a6e96400617f39b73b55adaefa9ed7f6bd84836f6"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.updatePrefs (cognitive 22): cli.updatePrefs has cognitive complexity 22 (threshold 15). Drivers by points: if/else 16, boolean chains 6 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":428}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa10a0bf811d9576abcacb6c58d1427d592937e3f5bf7f554bc0e1c40da8696e"}},{"ruleId":"D2","level":"warning","message":{"text":"idpServer.handleEditClient (cognitive 22): idpServer.handleEditClient has cognitive complexity 22 (threshold 15). Drivers by points: if/else 22 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/ui.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"813b3559d784246a83d2b11cbe6845ac6717db814554636e99fa54792fb8b91d"}},{"ruleId":"D2","level":"warning","message":{"text":"Dialer.dial (cognitive 22): Dialer.dial has cognitive complexity 22 (threshold 15). Drivers by points: if/else 15, match/switch 4, loops 2, boolean chains 1 (nesting depth added 10). Of this number, 12 points are the body\u0027s own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client.go"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bfd686355cb7d4c3cb5b86e988e8eac7a7e35253a31efbe75f5ce92c0d6ef30"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.dialNodeUsingProxy (cognitive 22): Client.dialNodeUsingProxy has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, boolean chains 1, match/switch 1 (nesting depth added 5). Of this number, 19 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":847}}}],"partialFingerprints":{"codehealthFindingId/v1":"48f34469fd0e08731d1f99c3b787a7110d7f43482b4aa4a0d047c34b089984e0"}},{"ruleId":"D2","level":"warning","message":{"text":"conn25.configFromNodeView (cognitive 22): conn25.configFromNodeView has cognitive complexity 22 (threshold 15). Drivers by points: if/else 17, loops 3, boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ec9a376b77c6e5d5d4472438c465acf7f9800d1746e0feb45544734ae64b662"}},{"ruleId":"D2","level":"warning","message":{"text":"extension.installHooks (cognitive 22): extension.installHooks has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, boolean chains 1, loops 1 (nesting depth added 1). Most of this is not in the body itself: 4 of the 22 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 163, 268, 191, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"64a5849ca00a35c251ee761c2c466617d161ec895343bb56ea9d03a9c9c89d68"}},{"ruleId":"D2","level":"warning","message":{"text":"client.reserveAddresses (cognitive 22): client.reserveAddresses has cognitive complexity 22 (threshold 15). Drivers by points: if/else 21, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":871}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3d5c6d5d97265bce269bf8cea3c432aa30f020aee42fda9f61459694b86708e"}},{"ruleId":"D2","level":"warning","message":{"text":"fileDeleter.Init (cognitive 22): fileDeleter.Init has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, match/switch 2, loops 1 (nesting depth added 11). Most of this is not in the body itself: 2 of the 22 points are its own statements and the rest belongs to one function literal inside it that branches (line 67). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/delete.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"6489b4d78b324832e1263aed6378bd86bf6d81f3dc31f7f3653d09251833b964"}},{"ruleId":"D2","level":"warning","message":{"text":"manager.DeleteFile (cognitive 22): manager.DeleteFile has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, boolean chains 2, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/retrieve.go"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"66e1cbbf9a3514199b85f2fa1afc145933dfa8c3adec8c7d2811a214ad845528"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.authReconfigLocked (cognitive 22): LocalBackend.authReconfigLocked has cognitive complexity 22 (threshold 15). Drivers by points: if/else 16, boolean chains 3, loops 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6051}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0c04235f1dc77133043c5013d68d63850ba3bdde7239ce42a2ce0ac1efa6248"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.TailnetLockModify (cognitive 22): LocalBackend.TailnetLockModify has cognitive complexity 22 (threshold 15). Drivers by points: if/else 18, boolean chains 2, loops 2 (nesting depth added 3). Of this number, 21 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":890}}}],"partialFingerprints":{"codehealthFindingId/v1":"184145febfe01a2b7bc2417c7a55ef21dbf73ca24bfdd59e94f1c2c4ee3aae49"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnserver.connIsLocalAdmin (cognitive 22): ipnserver.connIsLocalAdmin has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, boolean chains 1, match/switch 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnserver/actor.go"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"942f2780feef925a9615f81ead84bca109a6f6da9cf44c184ba05cebaf1319bf"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveDebug (cognitive 22): Handler.serveDebug has cognitive complexity 22 (threshold 15). Drivers by points: if/else 20, match/switch 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"383edc5ea13fb6f3d3af78985bb009afa9edc3c2f9d082467b1426eb170a5239"}},{"ruleId":"D2","level":"warning","message":{"text":"MaskedPrefs.Pretty (cognitive 22): MaskedPrefs.Pretty has cognitive complexity 22 (threshold 15). Drivers by points: if/else 15, match/switch 6, loops 1 (nesting depth added 12). Of this number, 17 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":470}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae1998ce31622416e3f9f3581f6dc2cf0b37d0d2685ece44e020a672c5712114"}},{"ruleId":"D2","level":"warning","message":{"text":"conn.Read (cognitive 22): conn.Read has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, match/switch 2, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/spdy/conn.go"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fc21137cdd2e6d51686893973008a6bb80eb0bfa1f38fd8710f4a6e060b3922"}},{"ruleId":"D2","level":"warning","message":{"text":"CertManager.EnsureCertLoops (cognitive 22): CertManager.EnsureCertLoops has cognitive complexity 22 (threshold 15). Drivers by points: if/else 14, loops 7, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"kube/certs/certs.go"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f9ba49abf5f3b3f5d707f7261beddbbc357cbad44334d8ebc2b9a0524278586"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 22): main.main has cognitive complexity 22 (threshold 15). Drivers by points: if/else 21, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/example/logreprocess/logreprocess.go"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"685173943ecf6df5c765bd8d770642f54e89487972f17bd7ae5cc4d0d3fa4823"}},{"ruleId":"D2","level":"warning","message":{"text":"netcheck.makeProbePlanInitial (cognitive 22): netcheck.makeProbePlanInitial has cognitive complexity 22 (threshold 15). Drivers by points: if/else 12, boolean chains 7, loops 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":559}}}],"partialFingerprints":{"codehealthFindingId/v1":"afdc1f76daf3a703ec7ace92bfb563bad1e1f882b9fd01264cdfb61088cf8f4d"}},{"ruleId":"D2","level":"warning","message":{"text":"packet.Hexdump (cognitive 22): packet.Hexdump has cognitive complexity 22 (threshold 15). Drivers by points: if/else 12, loops 7, boolean chains 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":554}}}],"partialFingerprints":{"codehealthFindingId/v1":"c69fdecf63430dde421e51a526573432cbaedc1c5f37a97fc69fd5a6539d2ee4"}},{"ruleId":"D2","level":"warning","message":{"text":"Wrapper.pollVector (cognitive 22): Wrapper.pollVector has cognitive complexity 22 (threshold 15). Drivers by points: loops 11, if/else 9, boolean chains 2 (nesting depth added 11). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":470}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fd5032a46cb206760deba304922c113933d90979099d2d2f1934bd4bfc0673f"}},{"ruleId":"D2","level":"warning","message":{"text":"Wrapper.injectedRead (cognitive 22): Wrapper.injectedRead has cognitive complexity 22 (threshold 15). Drivers by points: if/else 19, loops 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":1003}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f3c7e755616dbbeda6c9d4e8c5a7e55a3294e8756b09226d88976bb711e99ae"}},{"ruleId":"D2","level":"warning","message":{"text":"prober.runDerpProbeNodePair (cognitive 22): prober.runDerpProbeNodePair has cognitive complexity 22 (threshold 15). Drivers by points: if/else 17, match/switch 3, loops 2 (nesting depth added 11). Most of this is not in the body itself: 5 of the 22 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 822, 809). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":800}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b4eba80d843b8a56ab8b4b28ca7c6a2fa58dddd1aea75af570c48ecdba13a2c"}},{"ruleId":"D2","level":"warning","message":{"text":"source.keyToEnvVarName (cognitive 22): source.keyToEnvVarName has cognitive complexity 22 (threshold 15). Drivers by points: boolean chains 10, if/else 9, match/switch 2, loops 1 (nesting depth added 5). Of this number, 16 points are the body\u0027s own statements and 6 belong to 4 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/env_policy_store.go"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fae7b758480b124cae42f86aa0435b7eaf9d72898e94a2ce81232a1891188de"}},{"ruleId":"D2","level":"warning","message":{"text":"magicsock.betterAddr (cognitive 22): magicsock.betterAddr has cognitive complexity 22 (threshold 15). Drivers by points: if/else 18, boolean chains 4 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1848}}}],"partialFingerprints":{"codehealthFindingId/v1":"5434815cb84ee4a5ac1264064881dc1eba3bb21309d75e12fb1aa5a7bccd3414"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.derpWriteChanForRegion (cognitive 22): Conn.derpWriteChanForRegion has cognitive complexity 22 (threshold 15). Drivers by points: if/else 18, boolean chains 3, match/switch 1 (nesting depth added 3). Of this number, 19 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"c501630f28c4c4d6f1bb8c5c9b29b2d96be28676036f402808393ea30570e467"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.sendUDP (cognitive 22): Conn.sendUDP has cognitive complexity 22 (threshold 15). Drivers by points: if/else 18, match/switch 3, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1558}}}],"partialFingerprints":{"codehealthFindingId/v1":"30abd7ea5b8c7587908963386ab4463eb83285edb5610734cc42da64bd7259d1"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.forwardUDP (cognitive 22): Impl.forwardUDP has cognitive complexity 22 (threshold 15). Drivers by points: if/else 21, boolean chains 1 (nesting depth added 5). Of this number, 21 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":2028}}}],"partialFingerprints":{"codehealthFindingId/v1":"48d319167f11cba506d09f74c1649fdc1ba28fe74fa453825658fc51716f83d3"}},{"ruleId":"D2","level":"warning","message":{"text":"Firewall.UpdatePermittedRoutes (cognitive 22): Firewall.UpdatePermittedRoutes has cognitive complexity 22 (threshold 15). Drivers by points: if/else 16, loops 6 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wf/firewall.go"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f91ba4cbdbbcc053767c16920f8479f0500c5324a0f53265fc97b4849500ef2"}},{"ruleId":"D2","level":"warning","message":{"text":"uiState.updateLAN (cognitive 21): uiState.updateLAN has cognitive complexity 21 (threshold 15). Drivers by points: if/else 16, loops 3, boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d361f378b50ce5719efdc198435a4729fc69f72a1e069639f87f03a2278644b"}},{"ruleId":"D2","level":"warning","message":{"text":"ConnectorReconciler.Reconcile (cognitive 21): ConnectorReconciler.Reconcile has cognitive complexity 21 (threshold 15). Drivers by points: if/else 21 (nesting depth added 5). Of this number, 20 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/connector.go"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"57c0cafd99d84f3c85a8e79418eb5c9e25ed24243f213b9b76da29aa82c3f577"}},{"ruleId":"D2","level":"warning","message":{"text":"ConnectorReconciler.maybeProvisionConnector (cognitive 21): ConnectorReconciler.maybeProvisionConnector has cognitive complexity 21 (threshold 15). Drivers by points: if/else 19, boolean chains 1, loops 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/connector.go"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"8528b34b59a8250669fb3dc0fd64f19c35b2aeb7ac8424189b2bb8809bcf6685"}},{"ruleId":"D2","level":"warning","message":{"text":"egressEpsReconciler.Reconcile (cognitive 21): egressEpsReconciler.Reconcile has cognitive complexity 21 (threshold 15). Drivers by points: if/else 20, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-eps.go"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65048793158e9d205e3fe6809b2a9ba5f1fa3b385e3b05084add7c47f69c882"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.cleanupDanglingResources (cognitive 21): ProxyGroupReconciler.cleanupDanglingResources has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17, boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":660}}}],"partialFingerprints":{"codehealthFindingId/v1":"0dd53d27e5e9bcadb01a45d802dbf6e4bdfbd0f7310b9d970df1aecaa86adeb5"}},{"ruleId":"D2","level":"warning","message":{"text":"main.staleMarkersFromNodeMeta (cognitive 21): main.staleMarkersFromNodeMeta has cognitive complexity 21 (threshold 15). Drivers by points: loops 21 (nesting depth added 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":756}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c6f1ba18c38d5fca6b93be90808f9a855e7273bc5a67d383d0448008d32d38a"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.handleWebServe (cognitive 21): serveEnv.handleWebServe has cognitive complexity 21 (threshold 15). Drivers by points: if/else 19, boolean chains 1, match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":318}}}],"partialFingerprints":{"codehealthFindingId/v1":"df70067f7b2af8fe6fd14f93a04b42a5d6b7476124dedbb7829a86d0bc1e8ab9"}},{"ruleId":"D2","level":"warning","message":{"text":"mapSession.handleNonKeepAliveMapResponse (cognitive 21): mapSession.handleNonKeepAliveMapResponse has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12, loops 8, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a15a16d050a93154f2479db0ce97e9681c606685cb463567bf35ab2462448a9"}},{"ruleId":"D2","level":"warning","message":{"text":"StatCache.set (cognitive 21): StatCache.set has cognitive complexity 21 (threshold 15). Drivers by points: if/else 15, loops 4, match/switch 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"drive/driveimpl/compositedav/stat_cache.go"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"96411fdd5412c8d8b6d96eb664e031206075b94aa8ab719ae4ff7b8d24dbb6c2"}},{"ruleId":"D2","level":"warning","message":{"text":"clientupdate.findCmdTailscale (cognitive 21): clientupdate.findCmdTailscale has cognitive complexity 21 (threshold 15). Drivers by points: if/else 14, boolean chains 4, match/switch 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/clientupdate/clientupdate.go"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"5fddf2b11f8face778b7c1802e5dea25e505842d65b7efbdc323603bcaa3a936"}},{"ruleId":"D2","level":"warning","message":{"text":"RouterTracker.watchIPNBus (cognitive 21): RouterTracker.watchIPNBus has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11, boolean chains 4, loops 4, match/switch 2 (nesting depth added 7). Most of this is not in the body itself: 0 of the 21 points are its own statements and the rest belongs to one function literal inside it that branches (line 179). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/routecheck/routertracker.go"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"1189999116aaaa190f6f526beb4f664b43ecd9c1f05ac8146c79c90c02c69220"}},{"ruleId":"D2","level":"warning","message":{"text":"taildrop.multiFilePost (cognitive 21): taildrop.multiFilePost has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17, loops 4 (nesting depth added 10). Of this number, 20 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/localapi.go"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"201c5c7bade33f1b8942ab7dde9b5db53df648e9798775ce54e86c90b05bea92"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.serveSetTCPPortsInterceptedFromNetmapAndPrefsLocked (cognitive 21): ipnlocal.serveSetTCPPortsInterceptedFromNetmapAndPrefsLocked has cognitive complexity 21 (threshold 15). Drivers by points: if/else 14, loops 7 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":1570}}}],"partialFingerprints":{"codehealthFindingId/v1":"2394a2eac97502cc931b8850825be9a5d4626d7d4cf926cb7ef39faf89ac3547"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.tcpHandlerForServeTCP (cognitive 21): LocalBackend.tcpHandlerForServeTCP has cognitive complexity 21 (threshold 15). Drivers by points: if/else 20, boolean chains 1 (nesting depth added 10). Most of this is not in the body itself: 5 of the 21 points are its own statements and the rest belongs to one function literal inside it that branches (line 671). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":647}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f5920a3132c79869d2209ebf6d8b154372126070362fd910e9a08a082ca1c86"}},{"ruleId":"D2","level":"warning","message":{"text":"localapi.init (cognitive 21): localapi.init has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17, boolean chains 4. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"3338cc8f7a7f21add2d3a20441837ccb0b4077aa3c936e5c5bcdbd069b0dae2f"}},{"ruleId":"D2","level":"warning","message":{"text":"logpolicy.LogsDir (cognitive 21): logpolicy.LogsDir has cognitive complexity 21 (threshold 15). Drivers by points: if/else 18, boolean chains 2, match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"638635f94c01c4e4c192aab40baedd08e84e56bd1a3f6f904a560d35e5ce4462"}},{"ruleId":"D2","level":"warning","message":{"text":"netmon.likelyHomeRouterIPWindows (cognitive 21): netmon.likelyHomeRouterIPWindows has cognitive complexity 21 (threshold 15). Drivers by points: if/else 16, boolean chains 4, loops 1 (nesting depth added 5). Of this number, 17 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_windows.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"d35908ba554904a45e338d4b6e2f04ca7d44bb8721f43e5f29a309849de02233"}},{"ruleId":"D2","level":"warning","message":{"text":"RouteManager.applyUpsert (cognitive 21): RouteManager.applyUpsert has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12, loops 6, boolean chains 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":741}}}],"partialFingerprints":{"codehealthFindingId/v1":"be9ca1cf8abc493940ccab1745f422ab46a6a8a13624a31ac609b993da694656"}},{"ruleId":"D2","level":"warning","message":{"text":"Authority.InformIdempotent (cognitive 21): Authority.InformIdempotent has cognitive complexity 21 (threshold 15). Drivers by points: if/else 19, boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tka.go"},"region":{"startLine":584}}}],"partialFingerprints":{"codehealthFindingId/v1":"bdfb7bb715ead5cfb90171b3e51c33d32bac76bdf50a1ef4f57fcc424cc96374"}},{"ruleId":"D2","level":"warning","message":{"text":"main.extractTags (cognitive 21): main.extractTags has cognitive complexity 21 (threshold 15). Drivers by points: if/else 18, boolean chains 2, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/gocross/autoflags.go"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b8313b593d6b54eddae61c32fedab842026516c2a540dc690d5e8e944e0affc"}},{"ruleId":"D2","level":"warning","message":{"text":"network.initStack (cognitive 21): network.initStack has cognitive complexity 21 (threshold 15). Drivers by points: if/else 20, loops 1 (nesting depth added 7). Of this number, 15 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"67bcc51076c27290197f369dcc894bcf25fe4a8b27fcbf359077bd35c3b0c8d0"}},{"ruleId":"D2","level":"warning","message":{"text":"endpoint.handlePongConnLocked (cognitive 21): endpoint.handlePongConnLocked has cognitive complexity 21 (threshold 15). Drivers by points: if/else 18, boolean chains 3 (nesting depth added 6). Of this number, 19 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1718}}}],"partialFingerprints":{"codehealthFindingId/v1":"fcc638b302fd4d9c37b98ca85a0904f2bfa41cf434a2ab15676442c66d3f5743"}},{"ruleId":"D2","level":"warning","message":{"text":"RebindingUDPConn.WriteWireGuardBatchTo (cognitive 21): RebindingUDPConn.WriteWireGuardBatchTo has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17, loops 4 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/rebinding_conn.go"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"da66238a5149459e296ac3ee3c8fb45f4316174d981e1805ef6358db76f3c90a"}},{"ruleId":"D2","level":"warning","message":{"text":"netstack.startPacketCopy (cognitive 21): netstack.startPacketCopy has cognitive complexity 21 (threshold 15). Drivers by points: if/else 18, match/switch 2, loops 1 (nesting depth added 13). Most of this is not in the body itself: 1 of the 21 points is its own statement and the rest belongs to one function literal inside it that branches (line 2120). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":2116}}}],"partialFingerprints":{"codehealthFindingId/v1":"4aa870e56ba1bc398c7a7ea8fc35a98939743f903911f34cbd0da388a76b4bf7"}},{"ruleId":"D2","level":"warning","message":{"text":"Updater.getUpdateFunction (cognitive 20): Updater.getUpdateFunction has cognitive complexity 20 (threshold 15). Drivers by points: if/else 12, match/switch 7, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d4a90d8bc0d1d9df0b49d9211e71f07b816eba6027212103009515dd7811022"}},{"ruleId":"D2","level":"warning","message":{"text":"main.configFromEnv (cognitive 20): main.configFromEnv has cognitive complexity 20 (threshold 15). Drivers by points: if/else 16, boolean chains 2, loops 2 (nesting depth added 7). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/settings.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4b3f0f31fc85ee6ec562da37d98c8b2af232bd86e01ba16a036e3822e35ee39"}},{"ruleId":"D2","level":"warning","message":{"text":"main.getCredentials (cognitive 20): main.getCredentials has cognitive complexity 20 (threshold 15). Drivers by points: boolean chains 10, if/else 10 (nesting depth added 3). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 230). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/gitops-pusher/gitops-pusher.go"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"82bcd5c23f7d603587b1de869c78d47f3f301b7bca75618b5b7f32f01a637361"}},{"ruleId":"D2","level":"warning","message":{"text":"main.nodeHandlerForProxyGroup (cognitive 20): main.nodeHandlerForProxyGroup has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, boolean chains 1, loops 1 (nesting depth added 9). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 1135). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1134}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c3bc4e72580ecb4af315790ac3ec8ce48c7bd6032de4dfd6ca0aa2f95b31197"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 20): main.main has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10, loops 10 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/omitsize/omitsize.go"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e6cc80c69b1fac209852bac2f6d65b2d244f942bfaa1feb8cacbab847a6e367"}},{"ruleId":"D2","level":"warning","message":{"text":"main.measureSTUNRTTKernel (cognitive 20): main.measureSTUNRTTKernel has cognitive complexity 20 (threshold 15). Drivers by points: if/else 16, boolean chains 2, loops 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp_linux.go"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8a67666c26ad5640a0d4411f582a9dc273a8416e12a656199e95749d446c875"}},{"ruleId":"D2","level":"warning","message":{"text":"serveEnv.removeWebServe (cognitive 20): serveEnv.removeWebServe has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, loops 3, boolean chains 2 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1529}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf3b4dcbe4cc16b8dda1adfa8cff3a6eae2aa59a56bdec152a5aa0d4285a39f0"}},{"ruleId":"D2","level":"warning","message":{"text":"main.startIPNServer (cognitive 20): main.startIPNServer has cognitive complexity 20 (threshold 15). Drivers by points: if/else 12, match/switch 4, boolean chains 3, loops 1 (nesting depth added 5). Most of this is not in the body itself: 8 of the 20 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 601, 573). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":554}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3ddae51c54629bcc0ade617d16e528e9b057cf17f328a10c94d19e905dd08cd"}},{"ruleId":"D2","level":"warning","message":{"text":"main.uninstallSystemDaemonDarwin (cognitive 20): main.uninstallSystemDaemonDarwin has cognitive complexity 20 (threshold 15). Drivers by points: if/else 20 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/install_darwin.go"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"830431de66de75d20b1c5685b4da71b9cadc927e2e348e8a7130168f3d4e51f1"}},{"ruleId":"D2","level":"warning","message":{"text":"main.runOneTest (cognitive 20): main.runOneTest has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, boolean chains 2, match/switch 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ed82fcda75d16333b06ee23a1f02757ad8fd942195166e8d0b5de4c4fbdb852"}},{"ruleId":"D2","level":"warning","message":{"text":"main.generateServeIndex (cognitive 20): main.generateServeIndex has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, loops 5 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsconnect/serve.go"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"83543fa43294fb44890cec7aa6ad98306f1de8f0b695dfb1f251e9923cd2e05f"}},{"ruleId":"D2","level":"warning","message":{"text":"main.flattenExtraClaims (cognitive 20): main.flattenExtraClaims has cognitive complexity 20 (threshold 15). Drivers by points: loops 10, if/else 7, match/switch 3 (nesting depth added 11). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":718}}}],"partialFingerprints":{"codehealthFindingId/v1":"dea2673fbaea4789f11c96bc0ba1c211c9ec77913c52e30ccc519a5663b5466d"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 20): main.main has cognitive complexity 20 (threshold 15). Drivers by points: if/else 16, loops 4 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/viewer/viewer.go"},"region":{"startLine":712}}}],"partialFingerprints":{"codehealthFindingId/v1":"71cb2c14ded2c64beb6a771c11c5d6004261eb02ee10304d94663312fa3b1237"}},{"ruleId":"D2","level":"warning","message":{"text":"Extension.checkCaptivePortalLoop (cognitive 20): Extension.checkCaptivePortalLoop has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, match/switch 4, loops 1 (nesting depth added 8). Of this number, 17 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/captiveportal/captiveportal.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"d22c63393a833c40577f470a1ab6a998c300189539a516e869ed01faffd27665"}},{"ruleId":"D2","level":"warning","message":{"text":"wakeonlan.handleC2NWoL (cognitive 20): wakeonlan.handleC2NWoL has cognitive complexity 20 (threshold 15). Drivers by points: if/else 12, loops 7, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/wakeonlan/wakeonlan.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b34160618c395826a10dfb88ddd3cdbccd54ba68e460231d003ff3511f244d1"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.suggestExitNodeUsingTrafficSteering (cognitive 20): ipnlocal.suggestExitNodeUsingTrafficSteering has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, boolean chains 1, loops 1 (nesting depth added 3). Most of this is not in the body itself: 9 of the 20 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 8973, 9006). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":8958}}}],"partialFingerprints":{"codehealthFindingId/v1":"14ba5b4c7195834902caebeec79bb7af3afbd0dcab71a0328d3eeacd514e25e9"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.TCPHandlerForDst (cognitive 20): LocalBackend.TCPHandlerForDst has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14, boolean chains 4, match/switch 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/netstack.go"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"e649461c96ef5dbd3c6bb37ca63dce74aaaa02e8462d05e96ed658157fa0b401"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.getServeHandler (cognitive 20): LocalBackend.getServeHandler has cognitive complexity 20 (threshold 15). Drivers by points: if/else 19, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":803}}}],"partialFingerprints":{"codehealthFindingId/v1":"29ccbdd15aed528b036e42d145472ee212a52d994f6696727d3c735c68058373"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.checkConnIdentityLocked (cognitive 20): Server.checkConnIdentityLocked has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, loops 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnserver/server.go"},"region":{"startLine":255}}}],"partialFingerprints":{"codehealthFindingId/v1":"520161b3f95ecbfe6776242347c19bd5e80ff18c147e2e4513d37373bce1db62"}},{"ruleId":"D2","level":"warning","message":{"text":"Logger.drainPending (cognitive 20): Logger.drainPending has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14, match/switch 4, boolean chains 1, loops 1 (nesting depth added 10). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":449}}}],"partialFingerprints":{"codehealthFindingId/v1":"6aa75bb17007ab60d1b2fb4aeac809dcc1f21ddf55e813b1653a0c09c3815edc"}},{"ruleId":"D2","level":"warning","message":{"text":"Logger.appendTextOrJSONLocked (cognitive 20): Logger.appendTextOrJSONLocked has cognitive complexity 20 (threshold 15). Drivers by points: if/else 16, boolean chains 3, loops 1 (nesting depth added 3). Most of this is not in the body itself: 8 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 921). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":910}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a8019353eb19dd096ba49503a3026d412e8708f57ddbd7fd289b61d7f22febe"}},{"ruleId":"D2","level":"warning","message":{"text":"dnsTCPSession.handleReads (cognitive 20): dnsTCPSession.handleReads has cognitive complexity 20 (threshold 15). Drivers by points: if/else 13, match/switch 5, boolean chains 1, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager.go"},"region":{"startLine":592}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ffa265c2b406df333a3d161136c34757befddef620611f5e7fb6efdde155df9"}},{"ruleId":"D2","level":"warning","message":{"text":"resolver.resolversWithDelays (cognitive 20): resolver.resolversWithDelays has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, loops 2, boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":383}}}],"partialFingerprints":{"codehealthFindingId/v1":"b77cfefae37c121f972802ea782ddf9191194e30348b245c71df946b98538f3a"}},{"ruleId":"D2","level":"warning","message":{"text":"forwarder.sendUDP (cognitive 20): forwarder.sendUDP has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, boolean chains 1, match/switch 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":787}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee432d842e4206a22ddfc587cd8619c4075ecd9963f28a2e05477d4d20703b28"}},{"ruleId":"D2","level":"warning","message":{"text":"MessageCache.AddCacheEntry (cognitive 20): MessageCache.AddCacheEntry has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, boolean chains 1, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dnscache/messagecache.go"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"08ac10a8d19d0bd18b5038db42cd47c5334f9d04806b2734b9727efaceb09f1b"}},{"ruleId":"D2","level":"warning","message":{"text":"prober.validateConnState (cognitive 20): prober.validateConnState has cognitive complexity 20 (threshold 15). Drivers by points: if/else 19, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/tls.go"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cece41de6565a18ea23c860d1d9bb4015b20812c05daf4463fc98e7e884b039"}},{"ruleId":"D2","level":"warning","message":{"text":"main.run (cognitive 20): main.run has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, boolean chains 2, loops 1 (nesting depth added 4). Of this number, 16 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/updateflakes/updateflakes.go"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb7b1d09332725dcc23a5f5ea8e83573ee4d6ef30df9552779b05e08e3dd33b7"}},{"ruleId":"D2","level":"warning","message":{"text":"chonktest.RunCompactableChonkTests (cognitive 20): chonktest.RunCompactableChonkTests has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, loops 2 (nesting depth added 3). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 258, 214, 170, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/chonktest/chonktest.go"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c8955a9c11b76800cc2b16b2a9ace71c29313547efeb151a867cf4017009624"}},{"ruleId":"D2","level":"warning","message":{"text":"Config.AddNetwork (cognitive 20): Config.AddNetwork has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, match/switch 2, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/conf.go"},"region":{"startLine":180}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cf39a0d908526003f6832c7123745a634b0f8fd1273541881351d242fe071f4"}},{"ruleId":"D2","level":"warning","message":{"text":"typewalk.MatchingPaths (cognitive 20): typewalk.MatchingPaths has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, loops 2, match/switch 1 (nesting depth added 9). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 32). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/typewalk/typewalk.go"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"7213638d66ee11d20d656e036d0c999ba3ba0bf8611cf11ea8f516c90ef50012"}},{"ruleId":"D2","level":"warning","message":{"text":"logger.RateLimitedFnWithClock (cognitive 20): logger.RateLimitedFnWithClock has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, boolean chains 2, loops 1 (nesting depth added 5). Most of this is not in the body itself: 2 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 180). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/logger/logger.go"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e849cb08c461cfd771ae820a23a4b946b0f6c71ceaa018327c1616132b20df3"}},{"ruleId":"D2","level":"warning","message":{"text":"clientmetric.EncodeLogTailMetricsDelta (cognitive 20): clientmetric.EncodeLogTailMetricsDelta has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/clientmetric/clientmetric.go"},"region":{"startLine":344}}}],"partialFingerprints":{"codehealthFindingId/v1":"af9e8c85f8246ed3f851e7e903e356c58266fe2cafad148018b4b03da13a794b"}},{"ruleId":"D2","level":"warning","message":{"text":"deephash.makeStructHasher (cognitive 20): deephash.makeStructHasher has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14, boolean chains 3, loops 3 (nesting depth added 7). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 567, 592). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/deephash/deephash.go"},"region":{"startLine":557}}}],"partialFingerprints":{"codehealthFindingId/v1":"62fae63413023be27036b098a1a4e64aedd27fc0e5ba29edf7e681aecb459f5b"}},{"ruleId":"D2","level":"warning","message":{"text":"source.getPolicyValue (cognitive 20): source.getPolicyValue has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, loops 3, boolean chains 2 (nesting depth added 8). Of this number, 17 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/policy_store_windows.go"},"region":{"startLine":344}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f4aebdb0e4ec8c63ce171d2610b2282639c79fb2d6b9a1cb80c35b4a8f9fe9a"}},{"ruleId":"D2","level":"warning","message":{"text":"magicsock.printEndpointHTML (cognitive 20): magicsock.printEndpointHTML has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14, loops 4, boolean chains 2 (nesting depth added 7). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/debughttp.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"741313da845f22ca48b68f6d3be8515ad0cb7a6c277bfffe4ca53ac1c83bb3d6"}},{"ruleId":"D2","level":"warning","message":{"text":"endpoint.handleCallMeMaybe (cognitive 20): endpoint.handleCallMeMaybe has cognitive complexity 20 (threshold 15). Drivers by points: if/else 13, loops 6, boolean chains 1 (nesting depth added 6). Of this number, 15 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1939}}}],"partialFingerprints":{"codehealthFindingId/v1":"e40ab2e7f625188d77a6171f503d0658236a8a66de6d6867ffdf248a9b0f13ff"}},{"ruleId":"D2","level":"warning","message":{"text":"Logger.addNewVirtConnLocked (cognitive 20): Logger.addNewVirtConnLocked has cognitive complexity 20 (threshold 15). Drivers by points: if/else 15, boolean chains 4, match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netlog/netlog.go"},"region":{"startLine":261}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5344b4809ef62871c2e4ba5030e4f7377c97d6228cf430c850ed85cf9183cee"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.inject (cognitive 20): Impl.inject has cognitive complexity 20 (threshold 15). Drivers by points: if/else 19, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1047}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd8400eed388fc21300cf7b324e9df52c5f49ac8bcc094a8d367e1a5eb0cd556"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.forwardTCP (cognitive 20): Impl.forwardTCP has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, loops 1, match/switch 1 (nesting depth added 3). Of this number, 11 points are the body\u0027s own statements and 9 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1714}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab5b9f5ea48f62030eb77455106cce788ccb61361965a196220dfae4904a545b"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.getDefaultRouteMTU (cognitive 20): osrouter.getDefaultRouteMTU has cognitive complexity 20 (threshold 15). Drivers by points: if/else 18, loops 2 (nesting depth added 8). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"c31900a2556a3b9e4cf8e90cde8cf04286bdb51f8284c5e3a7f1dfa5d7917210"}},{"ruleId":"D2","level":"warning","message":{"text":"plistDict.UnmarshalXML (cognitive 20): plistDict.UnmarshalXML has cognitive complexity 20 (threshold 15). Drivers by points: if/else 17, match/switch 2, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance_darwin.go"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"807cbe9127806b3e214ba0956c54ed606075014be052b743ea60e3d2ab382b94"}},{"ruleId":"D2","level":"warning","message":{"text":"AppConnector.updateRoutes (cognitive 19): AppConnector.updateRoutes has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11, loops 6, boolean chains 1, jumps 1 (nesting depth added 8). Of this number, 15 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"appc/appconnector.go"},"region":{"startLine":349}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ca0b09eca75be312feae00f114993961a0934fc5b7d2c925856da78fb802ba3"}},{"ruleId":"D2","level":"warning","message":{"text":"Updater.unpackLinuxTarball (cognitive 19): Updater.unpackLinuxTarball has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, match/switch 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":1055}}}],"partialFingerprints":{"codehealthFindingId/v1":"9521ded6466218d8391f0cf6c0909649d4f03324f31cfd7f50867fbd2768e7fc"}},{"ruleId":"D2","level":"warning","message":{"text":"main.writeMapValueClone (cognitive 19): main.writeMapValueClone has cognitive complexity 19 (threshold 15). Drivers by points: if/else 17, boolean chains 1, match/switch 1 (nesting depth added 7). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/cloner/cloner.go"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"5aaa9450d8ff541c39423f98d378e8d143608d55db666b3d1b3186dde9a98605"}},{"ruleId":"D2","level":"warning","message":{"text":"main.watchTailscaledConfigChanges (cognitive 19): main.watchTailscaledConfigChanges has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, match/switch 2, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/tailscaled.go"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"e6a34ac38311c7bdcf596d63781ee2fda7f54d45ad027e3061a0699c32917a4a"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.getRunningProxies (cognitive 19): ProxyGroupReconciler.getRunningProxies has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13, loops 4, boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":1322}}}],"partialFingerprints":{"codehealthFindingId/v1":"82e1086fef168c7d6c70f551bd66601e5de3676b0b826f4502c73e31407b18a4"}},{"ruleId":"D2","level":"warning","message":{"text":"RecorderReconciler.maybeProvision (cognitive 19): RecorderReconciler.maybeProvision has cognitive complexity 19 (threshold 15). Drivers by points: if/else 14, loops 3, match/switch 2 (nesting depth added 3). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"353b362c07f5a2ecfadc833431a7904b44f593477526f6349131ddf4ef7d652d"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.progressPrinter (cognitive 19): cli.progressPrinter has cognitive complexity 19 (threshold 15). Drivers by points: if/else 15, match/switch 2, boolean chains 1, loops 1 (nesting depth added 9). Of this number, 16 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":331}}}],"partialFingerprints":{"codehealthFindingId/v1":"a228567fc45a3c08fe997ebf77b90d801b264e0151b41684351cd2f25532beb6"}},{"ruleId":"D2","level":"warning","message":{"text":"main.getURL (cognitive 19): main.getURL has cognitive complexity 19 (threshold 15). Drivers by points: if/else 18, boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/debug.go"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"14bd5c9407f7a1c28fe77586a4b7f0f7c38a7adc528d40542743a3d3d2775630"}},{"ruleId":"D2","level":"warning","message":{"text":"main.wgServerUpLinux (cognitive 19): main.wgServerUpLinux has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, loops 2, boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tta/wgserver_linux.go"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5af19e0ff51c30899ea5ee10c4e9c4d8664571d67c694a11a662c535795bd79"}},{"ruleId":"D2","level":"warning","message":{"text":"mapSession.removeUnwantedDiscoUpdatesFromFullNetmapUpdate (cognitive 19): mapSession.removeUnwantedDiscoUpdatesFromFullNetmapUpdate has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":545}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e87aec84912f10939ad0ee87eeafb68551acef6996b5976ddbd63149fd4a1b6"}},{"ruleId":"D2","level":"warning","message":{"text":"controlhttpserver.acceptHTTP (cognitive 19): controlhttpserver.acceptHTTP has cognitive complexity 19 (threshold 15). Drivers by points: if/else 19 (nesting depth added 4). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/controlhttpserver/controlhttpserver.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"319201f84296b8a3cb13a8144035bdce7b5a7be266eaac3724f91b5e2e879b6f"}},{"ruleId":"D2","level":"warning","message":{"text":"derpserver.parseSSOutput (cognitive 19): derpserver.parseSSOutput has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, loops 3 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":2557}}}],"partialFingerprints":{"codehealthFindingId/v1":"62cec55c31826277f4bbc24ce3256cf136aaa58a4e10578dfc16203db4e64bea"}},{"ruleId":"D2","level":"warning","message":{"text":"extension.getCertPEMWithValidity (cognitive 19): extension.getCertPEMWithValidity has cognitive complexity 19 (threshold 15). Drivers by points: if/else 19 (nesting depth added 6). Of this number, 15 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/acme/cert.go"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"88ec9fe606f6a3c9f4160243c16094a9a67a3ac28c9d6ad95f0de4e57a015b54"}},{"ruleId":"D2","level":"warning","message":{"text":"conn25.rewriteHTTPSResponse (cognitive 19): conn25.rewriteHTTPSResponse has cognitive complexity 19 (threshold 15). Drivers by points: if/else 17, loops 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1385}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2aff29c0339b1ab57ee9dc52f804fb864f34b32cbb573a7c0f38b3985ddacb8"}},{"ruleId":"D2","level":"warning","message":{"text":"manager.PutFile (cognitive 19): manager.PutFile has cognitive complexity 19 (threshold 15). Drivers by points: if/else 15, boolean chains 3, match/switch 1 (nesting depth added 3). Of this number, 17 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/send.go"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c0c2538c4955fce65289a51240443918ca80c9684a2007efafc9f11ca7a47fa"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.enterStateLocked (cognitive 19): LocalBackend.enterStateLocked has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12, boolean chains 3, loops 3, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":6739}}}],"partialFingerprints":{"codehealthFindingId/v1":"14032241957964dc283a72dabeb94134d449823f7b50286dfea3037b281e43de"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveDebugBusEvents (cognitive 19): Handler.serveDebugBusEvents has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13, loops 4, match/switch 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"01bf56bf92cdf895e7e146c9229d638392d68d295c6bcdb5bb6842c6e5dd9a65"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveProfiles (cognitive 19): Handler.serveProfiles has cognitive complexity 19 (threshold 15). Drivers by points: if/else 14, match/switch 5 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":1534}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f1f612d8640d895daf2e7dbe33befc6991385e7dfe18a36b34fe25ad7b03430"}},{"ruleId":"D2","level":"warning","message":{"text":"githook.WriteHooks (cognitive 19): githook.WriteHooks has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12, loops 3, boolean chains 2, match/switch 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"misc/git_hook/githook/install.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"89dd96fe9c2c274a81669eac1f320ca6c7661528084e5969dc5fd549a22f10b0"}},{"ruleId":"D2","level":"warning","message":{"text":"captivedetection.availableEndpoints (cognitive 19): captivedetection.availableEndpoints has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13, boolean chains 3, loops 3 (nesting depth added 8). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/captivedetection/endpoints.go"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd8b9f4efc1fe2b0828fa97d8bc00710f67a8cf27e849260e824828a8613e345"}},{"ruleId":"D2","level":"warning","message":{"text":"dns.setTailscaleHosts (cognitive 19): dns.setTailscaleHosts has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12, loops 6, boolean chains 1 (nesting depth added 5). Of this number, 15 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_windows.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9808305483a2882cf37193a9480319528a788fb90241d6b239a927865e46ad4"}},{"ruleId":"D2","level":"warning","message":{"text":"ChangeDelta.StateDesc (cognitive 19): ChangeDelta.StateDesc has cognitive complexity 19 (threshold 15). Drivers by points: if/else 18, boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/netmon.go"},"region":{"startLine":212}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b5ac909030364d00857f194747d0315c80e62134508891f25f35d5eaa73557f"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runBuild (cognitive 19): cli.runBuild has cognitive complexity 19 (threshold 15). Drivers by points: if/else 17, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"release/dist/cli/cli.go"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"66f58326d0cffcebb13e403de4df84dd7803684339a040b081074b5fb56c2146"}},{"ruleId":"D2","level":"warning","message":{"text":"sessionrecording.connectV2 (cognitive 19): sessionrecording.connectV2 has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13, match/switch 4, loops 2 (nesting depth added 8). Most of this is not in the body itself: 3 of the 19 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 298, 325). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"sessionrecording/connect.go"},"region":{"startLine":275}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef90642a53f2d30354d1f9fcf9220f5b0b41db5ba914f193dbd728e3e3695a17"}},{"ruleId":"D2","level":"warning","message":{"text":"Authority.findParentForRewrite (cognitive 19): Authority.findParentForRewrite has cognitive complexity 19 (threshold 15). Drivers by points: if/else 16, loops 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tka.go"},"region":{"startLine":752}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cbf0bcf53fd79d408e4f904727cc8fdb7a6317855b0d0384c56d77fa6aa3d53"}},{"ruleId":"D2","level":"warning","message":{"text":"Env.waitForPeerRoute (cognitive 19): Env.waitForPeerRoute has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12, loops 7 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/vmtest.go"},"region":{"startLine":1521}}}],"partialFingerprints":{"codehealthFindingId/v1":"46694dbdc89c217164ffd2047c6292c31ef199c1f911d083af34cef6f908a1b3"}},{"ruleId":"D2","level":"warning","message":{"text":"logHandler.ServeHTTP (cognitive 19): logHandler.ServeHTTP has cognitive complexity 19 (threshold 15). Drivers by points: if/else 15, boolean chains 2, match/switch 2 (nesting depth added 3). Most of this is not in the body itself: 6 of the 19 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 554, 578, 531). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/tsweb.go"},"region":{"startLine":498}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1125dcb0deb1d21e85b559f7bf9553e77b500d2417624f31e24399de5eb6095"}},{"ruleId":"D2","level":"warning","message":{"text":"nftablesRunner.DelConnmarkSaveRule (cognitive 19): nftablesRunner.DelConnmarkSaveRule has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12, loops 7 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":2348}}}],"partialFingerprints":{"codehealthFindingId/v1":"28cfa439b6b3918b96e0f83e4083811c5f494f66c410570ee93d9fadf4950e8e"}},{"ruleId":"D2","level":"warning","message":{"text":"Reader.reload (cognitive 19): Reader.reload has cognitive complexity 19 (threshold 15). Drivers by points: if/else 14, boolean chains 4, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/policy_reader.go"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa93a03f1a3cace5d0bfa5e13267cfa3ee0553576625edb3c00306decf8968d6"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.setDERPMap (cognitive 19): Conn.setDERPMap has cognitive complexity 19 (threshold 15). Drivers by points: if/else 17, loops 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":813}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba2b9e2d2263b3d5d3d877f934653212b38b906bb0ced5b1488b1fcae3f8526b"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.receiveIP (cognitive 19): Conn.receiveIP has cognitive complexity 19 (threshold 15). Drivers by points: if/else 15, boolean chains 3, match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1830}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a1c84d96a26c3f1ef8d641a0ed1e43cb81c9f18d9cffec582535100f0f8247d"}},{"ruleId":"D2","level":"warning","message":{"text":"systray.setRemoteIcon (cognitive 18): systray.setRemoteIcon has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":388}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ffaf57cfae96dc869f8b981599f37d24791fb2026366b809d5d3b6e0c12cef6"}},{"ruleId":"D2","level":"warning","message":{"text":"egressProxy.waitTillSafeToShutdown (cognitive 18): egressProxy.waitTillSafeToShutdown has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11, loops 3, match/switch 3, boolean chains 1 (nesting depth added 9). Most of this is not in the body itself: 5 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 684). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":669}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4d1a0ad1e63677c3e931f6adfaa5a98507e6e02b531e1cfb1442aea0a2f0123"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.ensureNodePortServiceCreated (cognitive 18): ProxyGroupReconciler.ensureNodePortServiceCreated has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, loops 2, boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":606}}}],"partialFingerprints":{"codehealthFindingId/v1":"531eef327627c5711cb4dc61f8007b2bf45ca7e324af276865ea3392622a95ba"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.getAuthKey (cognitive 18): ProxyGroupReconciler.getAuthKey has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":937}}}],"partialFingerprints":{"codehealthFindingId/v1":"74a97c6f63cd2c13740b482d5a41e82a44fa972996a37674818195a7c1281bf1"}},{"ruleId":"D2","level":"warning","message":{"text":"tailscaleSTSReconciler.Cleanup (cognitive 18): tailscaleSTSReconciler.Cleanup has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, match/switch 3, loops 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":255}}}],"partialFingerprints":{"codehealthFindingId/v1":"22c9d4d3d85845178eb758c566b92abaefd0f87e853184dd34786b55a08b5600"}},{"ruleId":"D2","level":"warning","message":{"text":"RecorderReconciler.maybeCleanupSecrets (cognitive 18): RecorderReconciler.maybeCleanupSecrets has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, match/switch 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/tsrecorder.go"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"af057466d456efabec7768846ee361d4e7c54f390937e8e7713bdafd9b3471b6"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 18): main.main has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12, boolean chains 2, loops 2, match/switch 2 (nesting depth added 3). Most of this is not in the body itself: 8 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 35). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/nginx-auth/nginx-auth.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"91cdf55dc7d3014c29a0bbd935ee8a201a4c15e3be2202e16e05ab6f4abc9434"}},{"ruleId":"D2","level":"warning","message":{"text":"main.getConns (cognitive 18): main.getConns has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, loops 5 (nesting depth added 9). Of this number, 9 points are the body\u0027s own statements and 9 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":528}}}],"partialFingerprints":{"codehealthFindingId/v1":"f279c163115f43f3fa73c76a1d708826456d751f6e668ed32e6a782d6e2e7c4b"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runConfigureSynology (cognitive 18): cli.runConfigureSynology has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 2 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-synology.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e745ed9fefc36f85fa38325fa71879d820a8ab738d0f878466f7bd0b42999ee"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.printServiceStatusTree (cognitive 18): cli.printServiceStatusTree has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, boolean chains 3, loops 2 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_status.go"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"767bdf2115e9de7cdadc4a5d150e3b94a0ed9f0cc5da9e0b306e2aed28e5f03d"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.switchProfile (cognitive 18): cli.switchProfile has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, match/switch 4, loops 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/switch.go"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1230dcecbe45fa19aef8a381b5f96a3742e0d3173f45ee7bab551e439b72eea"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.printWhoIs (cognitive 18): cli.printWhoIs has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, loops 2, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/whois.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a2a7743acbfb6785324889c8f7e25e48663005b55e6c12111590dabc334c791"}},{"ruleId":"D2","level":"warning","message":{"text":"mapSession.tryHandleIncrementally (cognitive 18): mapSession.tryHandleIncrementally has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, boolean chains 2, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":417}}}],"partialFingerprints":{"codehealthFindingId/v1":"d49da3be3dc5a422ad35f1579f583a30882d7f670dd5fc3c80ea75c7312a54d5"}},{"ruleId":"D2","level":"warning","message":{"text":"ts2021.NewClient (cognitive 18): ts2021.NewClient has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/ts2021/client.go"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"49af60f2d43d2655163eb8e2880945faa373d18604720965c812a956e12939b1"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.handleC2NDebugNetMap (cognitive 18): ipnlocal.handleC2NDebugNetMap has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 1, loops 1 (nesting depth added 7). Of this number, 15 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/c2n.go"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec69d3a9656539b9ea3dcbd8de3a37c19e1e2acd374ff9857f8e82dbe5493990"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.nodeAddrForNetwork (cognitive 18): ipnlocal.nodeAddrForNetwork has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, boolean chains 3, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/resolve.go"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8af7577af9c1eb376ea34e32fdb56c8472ce73c66c86fce3e55926858559a1e"}},{"ruleId":"D2","level":"warning","message":{"text":"expiryManager.nextPeerExpiry (cognitive 18): expiryManager.nextPeerExpiry has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, boolean chains 3, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/expiry.go"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"77d2fd605fadeee7fa1121a4e2f05711b8f1cfaad3b8dbe74b8fca90f1207c5c"}},{"ruleId":"D2","level":"warning","message":{"text":"nodeBackend.updatePeersLocked (cognitive 18): nodeBackend.updatePeersLocked has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10, loops 7, boolean chains 1 (nesting depth added 5). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":858}}}],"partialFingerprints":{"codehealthFindingId/v1":"c30aae79dfab5148b7e1bcb57b47832966b17964150d32fca0ae089d795accd2"}},{"ruleId":"D2","level":"warning","message":{"text":"prefsMetricsEditEvent.record (cognitive 18): prefsMetricsEditEvent.record has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8, match/switch 4, boolean chains 3, loops 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/prefs_metrics.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"51c57fcdd41f6cd640b29687388b5052ebc69db78457a82ca5e3d376bffbbd42"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.serveServeConfig (cognitive 18): Handler.serveServeConfig has cognitive complexity 18 (threshold 15). Drivers by points: if/else 17, match/switch 1 (nesting depth added 9). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/serve.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"2261d2d3c414e93e65a2a00acc37a36df59d8276f06ca402cb80e4cf09aa9fe9"}},{"ruleId":"D2","level":"warning","message":{"text":"Hijacker.setUpRecording (cognitive 18): Hijacker.setUpRecording has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, match/switch 2 (nesting depth added 4). Of this number, 13 points are the body\u0027s own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/hijacker.go"},"region":{"startLine":138}}}],"partialFingerprints":{"codehealthFindingId/v1":"856bdd61852a048e904bddd19997d8cdafaeb5e7d831b358c2290786832d415b"}},{"ruleId":"D2","level":"warning","message":{"text":"logtail.newLogger (cognitive 18): logtail.newLogger has cognitive complexity 18 (threshold 15). Drivers by points: if/else 17, boolean chains 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9e49901e8c396fd2d09d91cacfd2d6839f6d5164aec7b6242708faa6b9440d0"}},{"ruleId":"D2","level":"warning","message":{"text":"filch.New (cognitive 18): filch.New has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, boolean chains 2, match/switch 1 (nesting depth added 4). Of this number, 13 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/filch/filch.go"},"region":{"startLine":423}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a6ba388f1478958f78f7ba1351e884836c12da4a91c305d8a34b4d84ef1db17"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxBatchingConn.WriteBatchTo (cognitive 18): linuxBatchingConn.WriteBatchTo has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11, boolean chains 4, loops 2, jumps 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/batching/conn_linux.go"},"region":{"startLine":275}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0591355b013a07a89ab8daf7acbd5b9f576cbf5f6bf883667a231b785ed3975"}},{"ruleId":"D2","level":"warning","message":{"text":"OSConfig.Equal (cognitive 18): OSConfig.Equal has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, loops 4 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/osconfig.go"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd168d3a20f5cc7368229ea0cd9eb3fa77a8a3dd5e720d51f8f76a974ad1364f"}},{"ruleId":"D2","level":"warning","message":{"text":"netmon.GetWindowsDefault (cognitive 18): netmon.GetWindowsDefault has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12, match/switch 4, boolean chains 1, loops 1 (nesting depth added 6). Of this number, 11 points are the body\u0027s own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/interfaces_windows.go"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bb1f6c4465c07caf3699ce5f2364196b5ba389714f51545f7ad271ee27e300e"}},{"ruleId":"D2","level":"warning","message":{"text":"tlsdial.SetConfigExpectedCertHash (cognitive 18): tlsdial.SetConfigExpectedCertHash has cognitive complexity 18 (threshold 15). Drivers by points: if/else 17, loops 1 (nesting depth added 8). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to one function literal inside it that branches (line 326). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tlsdial/tlsdial.go"},"region":{"startLine":316}}}],"partialFingerprints":{"codehealthFindingId/v1":"036998e727079142d6ecace25872239b5e30f152cf414e186829482c312b4925"}},{"ruleId":"D2","level":"warning","message":{"text":"Prober.StatusHandler (cognitive 18): Prober.StatusHandler has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, loops 5 (nesting depth added 8). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to one function literal inside it that branches (line 62). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/status.go"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"9027421b12218c73f787424c7bc0b1eeb57864642a09dfc8ea5f494850d0e996"}},{"ruleId":"D2","level":"warning","message":{"text":"SNAT44.HandleForward (cognitive 18): SNAT44.HandleForward has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 1, match/switch 1 (nesting depth added 9). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/nat.go"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"81f96c18ed9d8a1168100a5a49de1badd5fbd8ad1e47d059179383f12a11fdc2"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.createDHCPResponse (cognitive 18): Server.createDHCPResponse has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, loops 3, boolean chains 1, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2274}}}],"partialFingerprints":{"codehealthFindingId/v1":"7953df615d88498e4f38514aede775bbd46135d35cd2a38e6bfa9baf40bd82ca"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.shouldInterceptTCP (cognitive 18): Server.shouldInterceptTCP has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, boolean chains 3, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2434}}}],"partialFingerprints":{"codehealthFindingId/v1":"d77429c18a6078e8285faf7dba48be0b8566c1e128f8cb9258f389daa982be0e"}},{"ruleId":"D2","level":"warning","message":{"text":"jsonx.MakeInterfaceCoders (cognitive 18): jsonx.MakeInterfaceCoders has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, match/switch 4, loops 1 (nesting depth added 3). Most of this is not in the body itself: 6 of the 18 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 109, 133). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/jsonx/json.go"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"41a1f6c9ede3a5a12469d09b81645fc7990e8a2268b3162aa102f9b772c2cdb2"}},{"ruleId":"D2","level":"warning","message":{"text":"osuser.lookup (cognitive 18): osuser.lookup has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/osuser/user.go"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba3528584722b1b6626ed9214795e64ac84d5edcfdfa55e4a6918bef2f58660d"}},{"ruleId":"D2","level":"warning","message":{"text":"version.parse (cognitive 18): version.parse has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/cmp.go"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d0d86b7a0f5ec4e26f05b697919c8da83250e013a60961da53ba55987244136"}},{"ruleId":"D2","level":"warning","message":{"text":"matches.matchIPsOnly (cognitive 18): matches.matchIPsOnly has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10, loops 8 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/match.go"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"556de93210189b40c8eaacd49abff1247a45846c5aebb2b124794a66f6e8681c"}},{"ruleId":"D2","level":"warning","message":{"text":"relayManager.handleRxDiscoMsgRunLoop (cognitive 18): relayManager.handleRxDiscoMsgRunLoop has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, match/switch 4 (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":584}}}],"partialFingerprints":{"codehealthFindingId/v1":"5008c7dfd89013469d00d124a152d8beba2a5477a70ffd0bc71dee1b957bb1a8"}},{"ruleId":"D2","level":"warning","message":{"text":"Impl.acceptUDP (cognitive 18): Impl.acceptUDP has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, match/switch 2, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1920}}}],"partialFingerprints":{"codehealthFindingId/v1":"96b6ddc2e7921a70a2264b030928a21190522fe1731f76caad5c0cffa6aa6203"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.cidrDiff (cognitive 18): osrouter.cidrDiff has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, loops 4 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":1856}}}],"partialFingerprints":{"codehealthFindingId/v1":"816ce3f37febb3239e5df3afeb68faa2511a60f337bb34bfb92552a95c3ba0d2"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.setPrivateNetwork (cognitive 18): osrouter.setPrivateNetwork has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16, boolean chains 1, loops 1 (nesting depth added 7). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":165}}}],"partialFingerprints":{"codehealthFindingId/v1":"736ab49e247e9f1a2c6fa76a61b8573d3ff22cfe1f5a9f05f1c6fa0136c6ef9e"}},{"ruleId":"D2","level":"warning","message":{"text":"windowsImpl.AppendListeningPorts (cognitive 18): windowsImpl.AppendListeningPorts has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14, loops 3, boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"portlist/portlist_windows.go"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"08bc169b033333bb84d9bdf2a7c13d4ac3285b30032017aa8b60f2b8cdf26664"}},{"ruleId":"D2","level":"warning","message":{"text":"UniqueProcess.AsRestartableProcess (cognitive 18): UniqueProcess.AsRestartableProcess has cognitive complexity 18 (threshold 15). Drivers by points: if/else 15, loops 2, boolean chains 1 (nesting depth added 3). Of this number, 17 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/restartmgr_windows.go"},"region":{"startLine":296}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d6e0dbc0c08928fdc88b7842f049287d9f38f1d8fc0e57e238d063de0920c66"}},{"ruleId":"D2","level":"warning","message":{"text":"StartupInfoBuilder.Resolve (cognitive 18): StartupInfoBuilder.Resolve has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, match/switch 3, loops 2 (nesting depth added 9). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/startupinfo_windows.go"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe0edb8563569c609810cf40145c086110f7e725d93fb72393a0f32aaaca696f"}},{"ruleId":"D2","level":"warning","message":{"text":"darwinConfigurator.SetDNS (cognitive 18): darwinConfigurator.SetDNS has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, loops 4, boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_darwin.go"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7471888ff5e4e21bdc793d6d07a6ee28c69923a0ebbd87f2685f2c6e1e4551d"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.serve (cognitive 17): Server.serve has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11, boolean chains 4, match/switch 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":334}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e03118527a17cbedfd3138a339f677a4785f4b4fa44fe33d5028733e3906d1b"}},{"ruleId":"D2","level":"warning","message":{"text":"Updater.updateDebLike (cognitive 17): Updater.updateDebLike has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":473}}}],"partialFingerprints":{"codehealthFindingId/v1":"4da861e86680559557c1541b6d0b2300ac18397914dd85aad9ffe3e443fe230b"}},{"ruleId":"D2","level":"warning","message":{"text":"ipCertManager.obtainCert (cognitive 17): ipCertManager.obtainCert has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, loops 2, boolean chains 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/ipcert.go"},"region":{"startLine":380}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0b7dbc7a1f994ababbd9d8d9e669edfc4c650e9cc67c287cb22b012a9c74358"}},{"ruleId":"D2","level":"warning","message":{"text":"main.ensureWatcherForKubeConfigMap (cognitive 17): main.ensureWatcherForKubeConfigMap has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, match/switch 2, loops 1 (nesting depth added 9). Most of this is not in the body itself: 2 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 343). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-nameserver/main.go"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"f12c310f7ac299f00c10e5726112759c5790203376722bd900e89bfa641784e2"}},{"ruleId":"D2","level":"warning","message":{"text":"KubeAPIServerTSServiceReconciler.maybeDeleteStaleServices (cognitive 17): KubeAPIServerTSServiceReconciler.maybeDeleteStaleServices has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, boolean chains 3, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/api-server-proxy-pg.go"},"region":{"startLine":265}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf8e72e3c7cd526b8bbc951378549eee06f2a74a2c4d8107641cd41520beaafb"}},{"ruleId":"D2","level":"warning","message":{"text":"dnsRecordsReconciler.maybeProvision (cognitive 17): dnsRecordsReconciler.maybeProvision has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 2 (nesting depth added 2). Of this number, 15 points are the body\u0027s own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/dnsrecords.go"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d290de5ec643843aa41a196822e71c0c2d055611108759b59ecfd1b1f9f3811"}},{"ruleId":"D2","level":"warning","message":{"text":"HAServiceReconciler.validateService (cognitive 17): HAServiceReconciler.validateService has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":816}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bf1347169a168929759ac803c395c66dcf36ab3911ad1bfb789bae79a6f2b96"}},{"ruleId":"D2","level":"warning","message":{"text":"main.proxyTCPConn (cognitive 17): main.proxyTCPConn has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, loops 4 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/natc/natc.go"},"region":{"startLine":544}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3c0fea1a5cb820915a7164098c5e83640130ccf23e037760e2c3a0dc5194be4"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runFlashAppliance (cognitive 17): cli.runFlashAppliance has cognitive complexity 17 (threshold 15). Drivers by points: if/else 17 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"182635ee86821a0ea2b2c2da1b901b51e86b9e9350768be09c95982fa55b82c7"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runWatchIPN (cognitive 17): cli.runWatchIPN has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, loops 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":664}}}],"partialFingerprints":{"codehealthFindingId/v1":"032e9f3e568ca301f33ab43e2eb56ce1e3897c6165d89ad44bca04394776256a"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runVia (cognitive 17): cli.runVia has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, match/switch 1 (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":989}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a8791c63164810882e420af1431080e83d29d85312148bca2fb714849d85648"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.prefValue (cognitive 17): cli.prefValue has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11, loops 4, boolean chains 1, match/switch 1 (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/get.go"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"217bf11aa6c1de4189f4e5c112b8646015ab3a25dbed2654cec895bdf0e3f695"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.parseTLArgs (cognitive 17): cli.parseTLArgs has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":418}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae044a5add306dce9edcf97afbf4dfd9282b48f6e587216369b3d9333da9f6eb"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.nlDescribeUpdate (cognitive 17): cli.nlDescribeUpdate has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12, loops 4, match/switch 1 (nesting depth added 5). Of this number, 14 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":631}}}],"partialFingerprints":{"codehealthFindingId/v1":"ecc443c8f1c7f1f2b06bd43355974e72bfb537afd7d4b6bf5e549744eabe8d70"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.parseDiskutilInfoPlist (cognitive 17): cli.parseDiskutilInfoPlist has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance_darwin.go"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"03e70b95d59e378a49348161879e301d28487351790c96d91dc8a618fa1848bc"}},{"ruleId":"D2","level":"warning","message":{"text":"main.retryFailedTest (cognitive 17): main.retryFailedTest has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":580}}}],"partialFingerprints":{"codehealthFindingId/v1":"59a7feea294ce55d9c7f8bc253003589ebd00670b0f47c56aef270af8cb83045"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 17): main.main has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsnet-proxy/tsnet-proxy.go"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc63eb9fc8f9df89fc9bdf95e4744fa1d83b9dfbf137820bdfe256f3e0f4a64d"}},{"ruleId":"D2","level":"warning","message":{"text":"Sink.LogPacket (cognitive 17): Sink.LogPacket has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12, loops 4, match/switch 1 (nesting depth added 5). Of this number, 12 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/capture/capture.go"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"b63172e5b99c1a85f20262c77bb233e00095d354c043db9f4fe3eb963ec2c804"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn25.handleConnectorTransitIPRequest (cognitive 17): Conn25.handleConnectorTransitIPRequest has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10, loops 4, boolean chains 3 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7d60ba30aab42f312df5f5eee4d77f01208df36e7f4a1b5a321070281168c23"}},{"ruleId":"D2","level":"warning","message":{"text":"Tracker.stringsLocked (cognitive 17): Tracker.stringsLocked has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, loops 2, boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"health/health.go"},"region":{"startLine":1041}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a70e813e2e5c833b2861eb830aca9faa05c5c77d772df17aa9d4069ca76068f"}},{"ruleId":"D2","level":"warning","message":{"text":"Notify.String (cognitive 17): Notify.String has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, boolean chains 1. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/backend.go"},"region":{"startLine":548}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e954658bf787326924b92d84e312debbe2406ea9ae20f6b3f7485f49d2e5b17"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.wireguardExitNodeDNSResolvers (cognitive 17): ipnlocal.wireguardExitNodeDNSResolvers has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10, loops 6, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":7890}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4f0d16ef03b6e09abd7e5ee5f0e960f6314248d6171978fa1e28cbc85e9a780"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.SetComponentDebugLogging (cognitive 17): LocalBackend.SetComponentDebugLogging has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, match/switch 1 (nesting depth added 4). Of this number, 11 points are the body\u0027s own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":853}}}],"partialFingerprints":{"codehealthFindingId/v1":"71f8fa32975a2c49c53598edbfea38c5c697ce4a89935eca97d0dbaefbc761a3"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.checkEditPrefsAccessLocked (cognitive 17): LocalBackend.checkEditPrefsAccessLocked has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, boolean chains 4 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":5185}}}],"partialFingerprints":{"codehealthFindingId/v1":"8783b473497d74973544aa5da12147eb11ea2787fa1f2241804939ddb5dafc6b"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.TailnetLockAffectedSigs (cognitive 17): LocalBackend.TailnetLockAffectedSigs has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1055}}}],"partialFingerprints":{"codehealthFindingId/v1":"4bd5524b1020e2c20c8fe56e0539cb70a4ddf894076b891f81d6d1ace989794b"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.probeLocks (cognitive 17): LocalBackend.probeLocks has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9, boolean chains 8. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/watchdog.go"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fec99ef82a9a6eca285d93347bfa586b4c12a0707ebee3d4382221aa4208dd8"}},{"ruleId":"D2","level":"warning","message":{"text":"peerAPIHandler.handleServeSockStats (cognitive 17): peerAPIHandler.handleServeSockStats has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8, loops 7, boolean chains 2 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":478}}}],"partialFingerprints":{"codehealthFindingId/v1":"aed754e3118fa027733ba685f041910ec2a3b93f9c5870f4d087a65e59003c5d"}},{"ruleId":"D2","level":"warning","message":{"text":"peerAPIHandler.handleDNSQuery (cognitive 17): peerAPIHandler.handleDNSQuery has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":756}}}],"partialFingerprints":{"codehealthFindingId/v1":"276a4be426934542c86cfba5c7ab3f3862a82e5ae891c52b413266acee91e400"}},{"ruleId":"D2","level":"warning","message":{"text":"awsstore.ParseARNAndOpts (cognitive 17): awsstore.ParseARNAndOpts has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11, match/switch 3, loops 2, boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/awsstore/store_aws.go"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"811f9f90812029d8428bb4ab33317cfcef0508102c2d9632b193577578688ba9"}},{"ruleId":"D2","level":"warning","message":{"text":"APIServerProxy.recordRequestAsEvent (cognitive 17): APIServerProxy.recordRequestAsEvent has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/api-proxy/proxy.go"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"e01e6e2419bea5e04ce3b3c0cd980d1e3b6585897e3881cbd0ec623a34ce8bb6"}},{"ruleId":"D2","level":"warning","message":{"text":"conn.handleData (cognitive 17): conn.handleData has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, match/switch 3 (nesting depth added 9). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/ws/conn.go"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"d78d1eb7874da079849296f21f467983ad9d35ad9ace0a148232f6636421c6da"}},{"ruleId":"D2","level":"warning","message":{"text":"Filch.Write (cognitive 17): Filch.Write has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 2 (nesting depth added 6). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/filch/filch.go"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cd864f568c4bdf44163069045fb27561ef81c6ecfc7ba9ef04fdd2d9263b050"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxBatchingConn.splitCoalescedMessages (cognitive 17): linuxBatchingConn.splitCoalescedMessages has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, loops 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/batching/conn_linux.go"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"300be3156a420dd7bd51d2a5d57899d122bb9a0d92142c2720d136cf7888a3b0"}},{"ruleId":"D2","level":"warning","message":{"text":"Client.getUPnPPortMapping (cognitive 17): Client.getUPnPPortMapping has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12, boolean chains 3, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/upnp.go"},"region":{"startLine":465}}}],"partialFingerprints":{"codehealthFindingId/v1":"7501c41a13c9aa45a13491ce1cf9afc32e12f3df37716e33c0281660cf6784bf"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.getOrDialTargetConn (cognitive 17): Conn.getOrDialTargetConn has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, match/switch 2, boolean chains 1, loops 1 (nesting depth added 9). Most of this is not in the body itself: 2 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 371). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/socks5/socks5.go"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ffd94c6ddecca709dd4ca78dc62e0180171017895be9538af86f84428ccafe5"}},{"ruleId":"D2","level":"warning","message":{"text":"stun.ParseResponse (cognitive 17): stun.ParseResponse has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, match/switch 1 (nesting depth added 4). Most of this is not in the body itself: 8 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 218). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/stun/stun.go"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8cf1f3440a9f440341418053c6130958b06f78b617628a31404455a79348117"}},{"ruleId":"D2","level":"warning","message":{"text":"STUNServer.Serve (cognitive 17): STUNServer.Serve has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/stunserver/stunserver.go"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ba4017ea8f031e065bdc8fc47a2b59f7001bf8a3c79d103bc630627e1ca5320"}},{"ruleId":"D2","level":"warning","message":{"text":"tlsdial.SetConfigExpectedCert (cognitive 17): tlsdial.SetConfigExpectedCert has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, loops 2 (nesting depth added 3). Most of this is not in the body itself: 2 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 259). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tlsdial/tlsdial.go"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"e62ebb27136db04dd7c30d917a7ffc10c11a43257f0043dbf6c3c6e99e7101a7"}},{"ruleId":"D2","level":"warning","message":{"text":"prober.derpProbeUDP (cognitive 17): prober.derpProbeUDP has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":649}}}],"partialFingerprints":{"codehealthFindingId/v1":"13e270617a1ff3ec776e6b9bf7c3e803be4795a3b24011a466db6198c74bf3e0"}},{"ruleId":"D2","level":"warning","message":{"text":"FS.scanHashes (cognitive 17): FS.scanHashes has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, loops 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/tailchonk.go"},"region":{"startLine":513}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb3181f77aa7fcab03347bce4371ff44f1d7303aac3afbf3b87c6561f64331b7"}},{"ruleId":"D2","level":"warning","message":{"text":"main.computeAffected (cognitive 17): main.computeAffected has cognitive complexity 17 (threshold 15). Drivers by points: loops 10, if/else 7 (nesting depth added 6). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool/listpkgs/listpkgs.go"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"05875bdb381f316c65a987b46b0aed3ea8cc53a01b4112e388142bdcb98a1c68"}},{"ruleId":"D2","level":"warning","message":{"text":"views.unorderedSliceEqualAnyOrderSmall (cognitive 17): views.unorderedSliceEqualAnyOrderSmall has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11, loops 4, boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/views/views.go"},"region":{"startLine":507}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee4a57a54ebb786b9ba5052b08e41639e7f7246724ac725d95f2ac69d1ad593f"}},{"ruleId":"D2","level":"warning","message":{"text":"CloudInfo.getAWS (cognitive 17): CloudInfo.getAWS has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12, loops 5 (nesting depth added 4). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/cloudinfo/cloudinfo.go"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"96926039bcf532c7cbcd4f589076966d1a0f91838bf0faa9eb18657d110aadfb"}},{"ruleId":"D2","level":"warning","message":{"text":"subscribeState.pump (cognitive 17): subscribeState.pump has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, match/switch 3, loops 1 (nesting depth added 9). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/eventbus/subscribe.go"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ce12a56d7766c200250c82fb13cb19891d31745242627cc9ac3a37d114c2e87"}},{"ruleId":"D2","level":"warning","message":{"text":"nftablesRunner.AddChains (cognitive 17): nftablesRunner.AddChains has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":931}}}],"partialFingerprints":{"codehealthFindingId/v1":"afafa71922f488011170a3701d08efd30f353f98b830e20269eca54416ab454f"}},{"ruleId":"D2","level":"warning","message":{"text":"Filter.runIn6 (cognitive 17): Filter.runIn6 has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, boolean chains 2, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/filter.go"},"region":{"startLine":564}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ea9165a979097b94740c0c439c70c581f5ada1160c6bb13e66d5e92dada5fb6"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.ServeHTTPDebug (cognitive 17): Conn.ServeHTTPDebug has cognitive complexity 17 (threshold 15). Drivers by points: loops 9, if/else 8 (nesting depth added 6). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/debughttp.go"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ac43dbb7c004a4554496a53ddaee74d00d6b9157735dc5e08d3eb334807e280"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.unambiguousNodeKeyOfPingLocked (cognitive 17): Conn.unambiguousNodeKeyOfPingLocked has cognitive complexity 17 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":2506}}}],"partialFingerprints":{"codehealthFindingId/v1":"cad71b24e425bfba260f3000dab872a9a97f5ef65d52511dea39e1b97d01b063"}},{"ruleId":"D2","level":"warning","message":{"text":"netstack.Create (cognitive 17): netstack.Create has cognitive complexity 17 (threshold 15). Drivers by points: if/else 15, boolean chains 2. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1b8f3aacc08b96f240a7cdc23e538258da80f2d6ac6e852f2fd4b6bae9c034f"}},{"ruleId":"D2","level":"warning","message":{"text":"linuxRouter.addIPRulesWithIPCommand (cognitive 17): linuxRouter.addIPRulesWithIPCommand has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14, loops 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":1693}}}],"partialFingerprints":{"codehealthFindingId/v1":"089b75886f603c77871381ea15feb9d5d828008d4428df7ecd927a959416a2f6"}},{"ruleId":"D2","level":"warning","message":{"text":"darwinConfigurator.removeResolverFiles (cognitive 17): darwinConfigurator.removeResolverFiles has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/manager_darwin.go"},"region":{"startLine":260}}}],"partialFingerprints":{"codehealthFindingId/v1":"005ff840498764ce390e2c8028263848918e060387324fcd478104677f8f6c9c"}},{"ruleId":"D2","level":"warning","message":{"text":"clientupdate.checkOutdatedAlpineRepo (cognitive 16): clientupdate.checkOutdatedAlpineRepo has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":770}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c57cee3e352f87e95acedc7fa063f32c5f027c7fa4ea05cd702776242cc81b8"}},{"ruleId":"D2","level":"warning","message":{"text":"uiState.render (cognitive 16): uiState.render has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, boolean chains 2, loops 2, match/switch 2 (nesting depth added 3). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"3134cc7ea6de9ebec81b5352bcbcb4d1dcd37a4dc98ecf1c9c01dd2250a7dc75"}},{"ruleId":"D2","level":"warning","message":{"text":"ACLGitopsTestError.Error (cognitive 16): ACLGitopsTestError.Error has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8, loops 7, boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/gitops-pusher/gitops-pusher.go"},"region":{"startLine":385}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee3ee2c3a748815e94f93ba4c2f343277807575b33064cdf9a7ccbee75319dd8"}},{"ruleId":"D2","level":"warning","message":{"text":"main.reconcileMetricsResources (cognitive 16): main.reconcileMetricsResources has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 2 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/metrics_resources.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b5dbf1b077743a91d164c3926c5e83c22c0853d0f8c4c05a1b98feb39016cb4"}},{"ruleId":"D2","level":"warning","message":{"text":"main.pgStatefulSet (cognitive 16): main.pgStatefulSet has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, loops 2, boolean chains 1 (nesting depth added 1). Most of this is not in the body itself: 7 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 166, 114, 144). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup_specs.go"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"44b793d3c8b5974d1cd34344b698a7babd34a41c0f0f5bf23e2d010af2989d8d"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyGroupReconciler.allocatePorts (cognitive 16): ProxyGroupReconciler.allocatePorts has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, loops 5 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":570}}}],"partialFingerprints":{"codehealthFindingId/v1":"51686480ba79f9f1b0b83329543c1c58d9552ff2e27ebcd341492a5a77ff1c9e"}},{"ruleId":"D2","level":"warning","message":{"text":"main.main (cognitive 16): main.main has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, match/switch 3, loops 2, boolean chains 1 (nesting depth added 3). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunc/stunc.go"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e1606162b66bed5302d2bd86926f9270ef37dbacc3ef12e8a2af07345b71090"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.serviceDNSRecordFromDNSConfig (cognitive 16): cli.serviceDNSRecordFromDNSConfig has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-kube.go"},"region":{"startLine":330}}}],"partialFingerprints":{"codehealthFindingId/v1":"b31df14b79dc9c82032c7974f773124d238ac0c07839452042263e7e3750073a"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.fixTailscaledConnectErrorImpl (cognitive 16): cli.fixTailscaledConnectErrorImpl has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 2, match/switch 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/diag.go"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"165a04766d4850df3208f5cfc192eb303fb4dc020caf4e3bd4f6878ac13a80fa"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runTailnetLockSign (cognitive 16): cli.runTailnetLockSign has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, boolean chains 3, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":494}}}],"partialFingerprints":{"codehealthFindingId/v1":"27b1c79d98ea40ab9272f2e05fa6fc11bc06961e4d24bb3472dfb8e7268f5185"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.prefsToFlags (cognitive 16): cli.prefsToFlags has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 2, loops 2, match/switch 1 (nesting depth added 4). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1147, 1136). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":1133}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7787c8263beece4e7d66ce3dbe462d07f16f2d04dda1258cf72d3f950bfb59d"}},{"ruleId":"D2","level":"warning","message":{"text":"cli.runVersion (cognitive 16): cli.runVersion has cognitive complexity 16 (threshold 15). Drivers by points: if/else 16 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/version.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"a05d90b87f820c4b8592ab592ac2c8d5b8388356f4f573d464a859cefb7215e9"}},{"ruleId":"D2","level":"warning","message":{"text":"idpServer.serveUserInfo (cognitive 16): idpServer.serveUserInfo has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":617}}}],"partialFingerprints":{"codehealthFindingId/v1":"f886137a87721faa8b03bcc0a90de5bbbb9fbb5bb0662f723aba3c5f62c63145"}},{"ruleId":"D2","level":"warning","message":{"text":"subtestnames.checkCallExpr (cognitive 16): subtestnames.checkCallExpr has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, boolean chains 3, loops 1 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/vet/subtestnames/analyzer.go"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"460ab49d284052eca1f21b2458c49eac816572dac078baf1215642423740c4b2"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.readNLocked (cognitive 16): Conn.readNLocked has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlbase/conn.go"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9fad1a249140f7d9cd1fcdfa665dc7cc9104b483d8380f21a82123dbd856595"}},{"ruleId":"D2","level":"warning","message":{"text":"controlclient.upgradeNode (cognitive 16): controlclient.upgradeNode has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"f557910eca886e340dfca27510b0d68167233a4f029c4d8cc102c7e1ce1880f1"}},{"ruleId":"D2","level":"warning","message":{"text":"Direct.answerPing (cognitive 16): Direct.answerPing has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, match/switch 3, boolean chains 2, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":1618}}}],"partialFingerprints":{"codehealthFindingId/v1":"55715b46afe7e98227599abac43c76a0ec7a3ec5294edc5556d7d9868322c3cb"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.ConsistencyCheck (cognitive 16): Server.ConsistencyCheck has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":2479}}}],"partialFingerprints":{"codehealthFindingId/v1":"307a7f7f754ef8209f2683296336678fd86a531443ea87870b1982a24229c99e"}},{"ruleId":"D2","level":"warning","message":{"text":"envknob.ApplyDiskConfig (cognitive 16): envknob.ApplyDiskConfig has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 1 (nesting depth added 4). Of this number, 12 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"envknob/envknob.go"},"region":{"startLine":547}}}],"partialFingerprints":{"codehealthFindingId/v1":"92aa52c583c2a97969a8f802648c2020f0bbc6ffa097d3044e39d4f6a1baf7e2"}},{"ruleId":"D2","level":"warning","message":{"text":"netLogger.Reconfig (cognitive 16): netLogger.Reconfig has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 8, if/else 8 (nesting depth added 2). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/netlog/netlog.go"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"0fdbc83776a9705958e9bf54661125fe50be0f8c2a1cb2776904639b0a57823b"}},{"ruleId":"D2","level":"warning","message":{"text":"taildrop.serveFilePut (cognitive 16): taildrop.serveFilePut has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 1, loops 1, match/switch 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/taildrop/localapi.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"47d378d652b35ed0998ff0c114d3a0dcbed8b2148fb0826adf8d7c7313c083f7"}},{"ruleId":"D2","level":"warning","message":{"text":"wakeonlan.handlePeerAPIWakeOnLAN (cognitive 16): wakeonlan.handlePeerAPIWakeOnLAN has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, loops 3, boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/wakeonlan/wakeonlan.go"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ab2cc7bf3de7e784f2084c32bccd07866473a943e183606156243531a0bb668"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.newExtensionHost (cognitive 16): ipnlocal.newExtensionHost has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, loops 1 (nesting depth added 6). Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/extension_host.go"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"8afd3442cfbc6d338943a9326054272f2933a606aca7c54d1c9d7872254d755f"}},{"ruleId":"D2","level":"warning","message":{"text":"ipnlocal.packetFilterPermitsUnlockedNodes (cognitive 16): ipnlocal.packetFilterPermitsUnlockedNodes has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, loops 6 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":3503}}}],"partialFingerprints":{"codehealthFindingId/v1":"92f14418e383742e0fb2adc4d773f1dd2f03a49c60d5a895b049907071c475d2"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.applySysPolicyLocked (cognitive 16): LocalBackend.applySysPolicyLocked has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 3, loops 1, match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":2186}}}],"partialFingerprints":{"codehealthFindingId/v1":"57e038fc34cfa2492b974ef29c61e58740e3d3c95917d08d547159ee904d48bf"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.SetUseExitNodeEnabled (cognitive 16): LocalBackend.SetUseExitNodeEnabled has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":5096}}}],"partialFingerprints":{"codehealthFindingId/v1":"08b3d6b962e253c96f66d2769f1da3cffa2574b83b49cf4c6cec938d2ef278ae"}},{"ruleId":"D2","level":"warning","message":{"text":"LocalBackend.tkaSyncLocked (cognitive 16): LocalBackend.tkaSyncLocked has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, loops 2 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":436}}}],"partialFingerprints":{"codehealthFindingId/v1":"e6a2caeb1859e7529cbdb6edc2c35c2e816e667251ff776f0ae5b337e23d4a69"}},{"ruleId":"D2","level":"warning","message":{"text":"peerAPIServer.listen (cognitive 16): peerAPIServer.listen has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"39bef97445b6be1173df47c0ddf83bb98a12abee036b4ae35ef3453ef55d078c"}},{"ruleId":"D2","level":"warning","message":{"text":"kubestore.newWithClient (cognitive 16): kubestore.newWithClient has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 2 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/kubestore/store_kube.go"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"315ff58fe9fe1262618616eed94680a0da9b89b9512cf86b2703424d52b395b5"}},{"ruleId":"D2","level":"warning","message":{"text":"store.New (cognitive 16): store.New has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/stores.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"77374faaced73610c27830a9b51ba941af80a809814baaaa59e2576b019c4315"}},{"ruleId":"D2","level":"warning","message":{"text":"Reconciler.deleteDevicesFrom (cognitive 16): Reconciler.deleteDevicesFrom has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, boolean chains 3, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/peerrelay/device.go"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"c86bbebd7e454e53e628dd8db846f1cc042ced78a128e9916dc19a310f5d932c"}},{"ruleId":"D2","level":"warning","message":{"text":"main.genGoDoc (cognitive 16): main.genGoDoc has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, boolean chains 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"misc/genreadme/genreadme.go"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"36f5f46323e04ed7b5c76325077b270cda2f5831acf1e0640a21ca1d19788a15"}},{"ruleId":"D2","level":"warning","message":{"text":"directManager.rename (cognitive 16): directManager.rename has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/direct.go"},"region":{"startLine":278}}}],"partialFingerprints":{"codehealthFindingId/v1":"a277044dada3a034475bf23f4aeaed11fea1555fa11fe0d9d0c834edc561a2d0"}},{"ruleId":"D2","level":"warning","message":{"text":"resolver.applySchemes (cognitive 16): resolver.applySchemes has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":1024}}}],"partialFingerprints":{"codehealthFindingId/v1":"150a9d7d9f8e5683a9a7164dd50f00c4e04e4dd34ab452e9bce0dec10c15672b"}},{"ruleId":"D2","level":"warning","message":{"text":"State.Equal (cognitive 16): State.Equal has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, boolean chains 4, loops 2 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"5efcd097bd9ca22ab206d8c3a71bd79e207c592b33b5e9bd2e94a648963de310"}},{"ruleId":"D2","level":"warning","message":{"text":"InterfaceList.ForeachInterfaceAddress (cognitive 16): InterfaceList.ForeachInterfaceAddress has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, loops 3, match/switch 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"137fe93b42c30cc28133e46a7d31e26fa0bd0cf03aa960b721e9ddf91c4b0543"}},{"ruleId":"D2","level":"warning","message":{"text":"InterfaceList.ForeachInterface (cognitive 16): InterfaceList.ForeachInterface has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, loops 3, match/switch 3 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netmon/state.go"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"faf16a340311e5e19af8e68fb09067cf1bd97319d7af9bcc773bdee9e285e800"}},{"ruleId":"D2","level":"warning","message":{"text":"netns.tailscaleInterface (cognitive 16): netns.tailscaleInterface has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, loops 3, boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netns/netns_darwin.go"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbd2c2719008ef41d9000867e6e5f2017c0fe5f10ccad2322d95cb54e45fc5cd"}},{"ruleId":"D2","level":"warning","message":{"text":"Parsed.decode6 (cognitive 16): Parsed.decode6 has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":268}}}],"partialFingerprints":{"codehealthFindingId/v1":"62fe89bb9c498b2dd739bc56063a849e03713f36344a99de46583a1160de080d"}},{"ruleId":"D2","level":"warning","message":{"text":"RouteManager.rebuildAll (cognitive 16): RouteManager.rebuildAll has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8, loops 6, match/switch 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":980}}}],"partialFingerprints":{"codehealthFindingId/v1":"23d0af5bc1395f36dee849aac717215b76ce25a687d8ba555b34167cbfec570b"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.transferUDP (cognitive 16): Conn.transferUDP has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, loops 2, match/switch 2 (nesting depth added 9). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to one function literal inside it that branches (line 315). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/socks5/socks5.go"},"region":{"startLine":310}}}],"partialFingerprints":{"codehealthFindingId/v1":"fcae53b3e06c37cb289eec8d73b342a52943b6608cfc7d29a4760d5797398073"}},{"ruleId":"D2","level":"warning","message":{"text":"Dialer.userDialResolveAll (cognitive 16): Dialer.userDialResolveAll has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 1, loops 1 (nesting depth added 4). Of this number, 12 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tsdial/tsdial.go"},"region":{"startLine":402}}}],"partialFingerprints":{"codehealthFindingId/v1":"2210e9602f0b8480490580e65d0ed64062466524ce82011b92b7a8ffc5e06b54"}},{"ruleId":"D2","level":"warning","message":{"text":"UpdateBuilder.Finalize (cognitive 16): UpdateBuilder.Finalize has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/builder.go"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"adb017aa43b591dddebb8c8e2e984f4b9baae2146cd9835bf8b0970aa1bd37e8"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.listen (cognitive 16): Server.listen has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":2028}}}],"partialFingerprints":{"codehealthFindingId/v1":"7aebb043e8f27f3e7bc737c235e696fea3b560917012c010890d60475ae8dad1"}},{"ruleId":"D2","level":"warning","message":{"text":"Config.AddNode (cognitive 16): Config.AddNode has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, match/switch 5, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/conf.go"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"c54eba1706e813e6b8bf22755c63c7649764a77010e3f708e012ad9bd5af400c"}},{"ruleId":"D2","level":"warning","message":{"text":"Server.takeAgentConn (cognitive 16): Server.takeAgentConn has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 2, match/switch 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2906}}}],"partialFingerprints":{"codehealthFindingId/v1":"f08be1e3ede9f45904aef2537b82d820fcccd15d6332cf0ddbcd24c10312a04e"}},{"ruleId":"D2","level":"warning","message":{"text":"cmpver.Compare (cognitive 16): cmpver.Compare has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12, match/switch 2, boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/cmpver/version.go"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffe17e750e290cadf751a028e7d089c28cc24de57710ca91242a4adb7694d852"}},{"ruleId":"D2","level":"warning","message":{"text":"nftablesRunner.AddConnmarkSaveRule (cognitive 16): nftablesRunner.AddConnmarkSaveRule has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, loops 5 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":2265}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0421170caec5bf405af2d24c7fd64d86f2825e99f15a9c9671595817466118a"}},{"ruleId":"D2","level":"warning","message":{"text":"IntSet.Values (cognitive 16): IntSet.Values has cognitive complexity 16 (threshold 15). Drivers by points: if/else 9, loops 7 (nesting depth added 9). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to one function literal inside it that branches (line 43). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/set/intset.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b1fe25aa8af7d99acb8f0e78dea65e0d563dabab58f2a11d7ce8a8f469aa21b"}},{"ruleId":"D2","level":"warning","message":{"text":"source.newReader (cognitive 16): source.newReader has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, match/switch 5 (nesting depth added 6). Of this number, 13 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/policy_reader.go"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"3db9d2f6ead1179ceb165805ae321468f3cd5eea18e11c4c015a2dc3fd483d26"}},{"ruleId":"D2","level":"warning","message":{"text":"source.readPolicySettingValue (cognitive 16): source.readPolicySettingValue has cognitive complexity 16 (threshold 15). Drivers by points: if/else 15, match/switch 1 (nesting depth added 9). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/policy_reader.go"},"region":{"startLine":362}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d037d9fddb099a6983a86f228d7529a565efba48288ce33ea42c28058ac5886"}},{"ruleId":"D2","level":"warning","message":{"text":"version.isValidLongWithTwoRepos (cognitive 16): version.isValidLongWithTwoRepos has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, boolean chains 4, loops 2 (nesting depth added 3). Of this number, 9 points are the body\u0027s own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/version.go"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7fff0151c2c1ed5ef8c9187e4765656d24734f7010887c440688d3108c053fb"}},{"ruleId":"D2","level":"warning","message":{"text":"mkversion.infoFromCache (cognitive 16): mkversion.infoFromCache has cognitive complexity 16 (threshold 15). Drivers by points: if/else 16 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/mkversion/mkversion.go"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd75db2379da31d557915380d49acbab487d028649af88e7f3f663c01d2338f3"}},{"ruleId":"D2","level":"warning","message":{"text":"Filter.runIn4 (cognitive 16): Filter.runIn4 has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 1, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/filter.go"},"region":{"startLine":502}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4706bd308061cb4a1d6591e73a8afde12a2f0d843932c73ea7da4a8ae1b933e"}},{"ruleId":"D2","level":"warning","message":{"text":"magicsock.NewConn (cognitive 16): magicsock.NewConn has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, match/switch 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":644}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3e1bfb39dcbb6631327f3fd58379ba1b9380bb8545b2447bb8b8e3a2528e36d"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.setNetworkMapInternal (cognitive 16): Conn.setNetworkMapInternal has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 5 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":3024}}}],"partialFingerprints":{"codehealthFindingId/v1":"3bc8fb88871f1de9f4084bd91921a094615c020ca2cb94de0333838d09b70554"}},{"ruleId":"D2","level":"warning","message":{"text":"Conn.listenRawDisco (cognitive 16): Conn.listenRawDisco has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, loops 1, match/switch 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock_linux.go"},"region":{"startLine":171}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f49e833c9e4457197d8bc9af3d55c6e40e094e6daf127c995b0fbdf9f15b55a"}},{"ruleId":"D2","level":"warning","message":{"text":"osrouter.syncAddresses (cognitive 16): osrouter.syncAddresses has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, loops 3 (nesting depth added 7). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/ifconfig_windows.go"},"region":{"startLine":587}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e44d803570ee47351811120892f3fe8feefad24d2345180b5783eb07b81d097"}},{"ruleId":"D2","level":"warning","message":{"text":"wglog.NewLogger (cognitive 16): wglog.NewLogger has cognitive complexity 16 (threshold 15). Drivers by points: if/else 13, boolean chains 2, loops 1 (nesting depth added 3). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to one function literal inside it that branches (line 50). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/wglog/wglog.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"7484b3cf8140af651023d473b67225ccbf63d6c6c1a0f40befe7e409be4f2038"}},{"ruleId":"D2","level":"warning","message":{"text":"nrptRuleDatabase.WriteSplitDNSConfig (cognitive 16): nrptRuleDatabase.WriteSplitDNSConfig has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, loops 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nrpt_windows.go"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"456b957bb297ce925cfd03a05822da2b6fd80da4ee8c3c956e90a1b2106f18dd"}},{"ruleId":"D2","level":"warning","message":{"text":"protocol.getLayers (cognitive 16): protocol.getLayers has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10, boolean chains 6 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wf/firewall.go"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"805472680ab3d7b4ac2b554bac509a5dad639004c12c4a0c7552bcce3fae8c47"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: LocalBackend: TooManyMethods \u2014 391 methods, declared across 14 files: ipnlocal/local.go (263), ipnlocal/tailnet-lock.go (44), ipnlocal/serve.go (32), ipnlocal/drive.go (12), \u002B10 more file(s). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":225}}}],"partialFingerprints":{"codehealthFindingId/v1":"f54e6fbd3a28040f25630e5aea01735cc1a23d7ba7fcf690cf7fcd8781ca3d15"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/local.go: FileTooLong \u2014 4749 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a637ad3f4b410c10785a38a8a5c14c07c69a9075870cab0b9ff47c40dcb3f803"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: magicsock/magicsock.go: FileTooLong \u2014 2386 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2b14f3418c9cdca7bf5687507f80f50df07e0caded9053e4e3acd92b875cf81"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Conn: TooManyMethods \u2014 135 methods, declared across 7 files: magicsock/magicsock.go (91), magicsock/derp.go (33), magicsock/peermtu.go (4), magicsock/magicsock_linux.go (3), \u002B3 more file(s). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"78bcd7aa56afdce0464d797140972b82a3ac120d5e44fd7152596e2cf3ba9aa5"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Client: TooManyMethods \u2014 128 methods, declared across 8 files: local/local.go (88), local/tailnetlock.go (26), local/cert.go (5), local/routecheck.go (2), \u002B4 more file(s). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/local/local.go"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"e594908a557033f1d655782710b920640f497fb6fd6f1244faeae3a9fe5027c4"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: vnet/vnet.go: FileTooLong \u2014 1908 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d9b18ac238efb2084212e5521a15d371e892bccd9f3b1c3ca4659cf7282e354"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: derpserver/derpserver.go: FileTooLong \u2014 1510 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4143c6341b421d94132dd281dc4d49dbbd09d9a44a1dab0ddeae09e1bb01c6a7"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Handler: TooManyMethods \u2014 87 methods, declared across 8 files: localapi/localapi.go (55), localapi/debug.go (13), localapi/tailnetlock.go (13), localapi/localapi_drive.go (2), \u002B4 more file(s). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":207}}}],"partialFingerprints":{"codehealthFindingId/v1":"6029d5b2eb08ee29379c360525e07df3524c76b8210bfa34ebc8dcb5860092bc"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: linuxfw/nftables_runner.go: FileTooLong \u2014 1352 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e63ab5252d2f7d5122156bc462803dbbb87acf71fbd7a7dbca68c4bae77bd37a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: netstack/netstack.go: FileTooLong \u2014 1282 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"303dc759e9c9f78fd1abc1be65c8af09282359dbff0b667376a0a3ae4a5544e6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: localapi/localapi.go: FileTooLong \u2014 1251 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c943843ab233555b510a7eea06e6a4c9e2be3ac171eac13e618ad300ec9fac9d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: controlclient/direct.go: FileTooLong \u2014 1216 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a03a15e3ccb5c2033232d5792420463fb6ed5c71dc31d352d5bda7dad65edac8"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tsnet/tsnet.go: FileTooLong \u2014 1200 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"571cc45fd7656bab0e7de1794b0b164da5eb646276b1fca064fb7a214828193f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: testcontrol/testcontrol.go: FileTooLong \u2014 1153 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c29b1cd4c04bd6061ce73c87d92caf2e3397f5c9cb95ab2058be1b99367129d6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: k8s-operator/operator.go: FileTooLong \u2014 1151 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fe508aa5f9ad77ba1db5a042d85d07eec54fb9dcad1e1b6c3f223dc664f8705"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: nodeBackend: TooManyMethods \u2014 67 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"a54babace249296d61fec120a86bdb69f5f8aebed6e9619f571a4c370a27253b"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Server: TooManyMethods \u2014 66 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"703e53a8a5071d3749c3b6551f14ccd6be93513b0b4231c6f0216bfe91a227ab"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/serve.go: FileTooLong \u2014 1082 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/serve.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ef640bb09be2c15815cbc0ec36c4c657878bfd646c3c9471e0588b383f3cfd2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: magicsock/endpoint.go: FileTooLong \u2014 1076 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"25b6f9eec10c019db2f4d5fe8fed25731fbd1ddf851c9d564053e3cdb733e118"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/serve_v2.go: FileTooLong \u2014 1050 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_v2.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a84d3a9f64f9d5450f8dc59527d2c7a84e9d1530bd8d2c70458143af759e42a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/debug.go: FileTooLong \u2014 1044 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab3c14d1d357ddb8ebba693d102efaa5e174574c9c01efa9c1c7d8d8a448dae1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: osrouter/router_linux.go: FileTooLong \u2014 1041 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"04942013238e9173470d0f89467ec4f3342750420bac07364094ea5d29766a11"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Tracker: TooManyMethods \u2014 62 methods, declared across 3 files: health/health.go (59), health/state.go (2), health/usermetrics.go (1). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"health/health.go"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f8dcaf2a56ca72a7f67861d9c58898e9f2feb615e45c2628b29aa904cdf16f7"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tailcfg/tailcfg.go: FileTooLong \u2014 999 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tailcfg/tailcfg.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"196f536148f99c5f5d58bb3808acb92d5cf6f173dada9f9a7b7a026b649ea06f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tsidp/tsidp.go: FileTooLong \u2014 972 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dedc1e1da6b81f2649abef95b5dddbdf40e1be04642e09df7d777025573eeaab"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tailssh/tailssh.go: FileTooLong \u2014 968 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/tailssh.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b36f5c9fba1f8c4d332c060f0a682c669030a5d6856d53302b12647d64c1c12"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/tailnet-lock.go: FileTooLong \u2014 958 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"572fe8414990c95760c24180802cae3e1ff2c790198920a9419f1740d00756c9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: netcheck/netcheck.go: FileTooLong \u2014 941 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb7e7e4073bc83aa6877dfe4d4c6871b9743a2e5f8ddc17f0cf1fafe91d8fd90"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: conn25/conn25.go: FileTooLong \u2014 912 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5bc64cb54dca7cfdb85a3caa107183e49319abdc7358a4990b39626621609d26"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: resolver/tsdns.go: FileTooLong \u2014 889 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/tsdns.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"01fd1fa28ea58dbc97b64e6ffc30eabb7b2c2e383ed7cec96a0a780b80fe428c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: endpoint: TooManyMethods \u2014 53 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/endpoint.go"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"54d044866613bf3cbd6788b82437b1a24c64d7055f9de22e2c1e5449fd2501a3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: wgengine/userspace.go: FileTooLong \u2014 869 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9f6292afcddec9d6714859c1d833b78cc8e45ed2beb92a424f94c9845cdbd06"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: k8s-operator/proxygroup.go: FileTooLong \u2014 853 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6bab6332ca0b11ecde064c3f3c103bd82436c4921a1bc321d73dfb2ff237f7e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: resolver/forwarder.go: FileTooLong \u2014 816 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/resolver/forwarder.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b3a60fc6daf06f7e2401ac32db7630ef4da4d68e609c2c88c82bc9b5cb82491"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: integration/integration.go: FileTooLong \u2014 812 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/integration.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66fd4a812ef4944e9ff9a302cae2fb14aafd2a220a7933476a6601c5d0b03e6f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: local/local.go: FileTooLong \u2014 811 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/local/local.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d603cca2e08eacafe0da0daf8248fceeb51caba382df8b5a89dfe3d1b03ccfc"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: clientupdate/clientupdate.go: FileTooLong \u2014 810 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"clientupdate/clientupdate.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"40e8e13d529fbcff0756ecc77184d41dd45b6adab8e491149bbdb5131331965b"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/node_backend.go: FileTooLong \u2014 805 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3b99482526450115d4ea010d25c62c28dc6c764a04e2a02d2bdb6d28fbcce01"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: linuxRouter: TooManyMethods \u2014 48 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d740097d2cec29f07269d2b8d8768ead8873e03d82365834c8977565f534e62"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tstun/wrap.go: FileTooLong \u2014 796 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca211fd4fd325b9a78c1b6a19c006be46b52822db9a662af1968906b2ef39636"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: web/web.go: FileTooLong \u2014 790 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/web.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ecafd8f1308a638da0049123c267e09c1771f8df07c92483efa8114459552c3"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: profileManager: TooManyMethods \u2014 47 methods, declared across 2 files: ipnlocal/profiles.go (45), ipnlocal/profiles_notwindows.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/profiles.go"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"037ed62ab5e7563c097c11f1914c075bbfac06bd51284ca32625bee7dc2748df"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Server: TooManyMethods \u2014 46 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsnet/tsnet.go"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a267cd4f2d617064171d8dd9083b17121ee4f526b6d47f13337a0ea914d8532"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: controlclient/map.go: FileTooLong \u2014 763 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d5d7da9147731712656f7a26aec77c868fd3cd049a25d5d9e2cd7fc8e3ca762"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: k8s-operator/sts.go: FileTooLong \u2014 751 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/sts.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f73e2894d8fb8cf794f5254ad04cfa545eaf1197ff66f368aaad841aa159ada"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Server: TooManyMethods \u2014 45 methods, declared across 2 files: derpserver/derpserver.go (44), derpserver/fortest.go (1). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8ec32ec10a6cdcb810e6df1e818eb95c79ca48e4d2af413cae44587bd8c890a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/up.go: FileTooLong \u2014 750 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/up.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e32ea5fcfe67c1ca5c11525f7dbf4a01436ffb1f95a73cd09efbfde3535d7ac8"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: health/health.go: FileTooLong \u2014 750 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"health/health.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3c6cabad06ff88efb2c65ae9831d8163fcd877edfe122197cbef0282c4b9e5f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: stunstamp/stunstamp.go: FileTooLong \u2014 738 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/stunstamp/stunstamp.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1484ba58893001f72a104943d9c83803c7bb702a8b7b814145a8030d6c638eca"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Wrapper: TooManyMethods \u2014 44 methods, declared across 2 files: tstun/wrap.go (42), tstun/wrap_linux.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/tstun/wrap.go"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"89b97f791dbd361480a13564a1f2450a23cb9fd0b6eafe9e47b4ccf2c93aaf7f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: userspaceEngine: TooManyMethods \u2014 44 methods, declared across 2 files: wgengine/userspace.go (38), wgengine/pendopen.go (6). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"8972541f7d7ad78bbe2dbdf6f1bc4f80583a96e8ef77f0854d78595de8d984c2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: prober/derp.go: FileTooLong \u2014 730 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8791a24546b733e6e7513f699248ae950151fc2ebbf3849bdccf98a43df863c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Client: TooManyMethods \u2014 43 methods, declared across 7 files: tailscale/acl.go (11), tailscale/dns.go (10), tailscale/tailscale.go (8), tailscale/devices.go (6), \u002B3 more file(s). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/tailscale.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbaecd7467fde618ccdc34c5d574cbe76eb6a1df46899c4e7d8f1c1c8219bf33"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: portmapper/portmapper.go: FileTooLong \u2014 707 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/portmapper.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7082fc0987b923794e03c3327db9f81512518c2abc4b6dec099726d9b8a9f2a2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: udprelay/server.go: FileTooLong \u2014 688 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"25b5f964f847dfc14541beaaae6242422ef1718135a1dd99463a03b5064d39d3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: derphttp/derphttp_client.go: FileTooLong \u2014 687 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e10f63e305c69321a86b2be4f958d06e546aa238a6d667a01d84d295e7556fd2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tailssh/incubator.go: FileTooLong \u2014 680 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ssh/tailssh/incubator.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a596877be4fa2641c27363893f41032e46eb4cff89b6f5237dec688d0bda17cb"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Client: TooManyMethods \u2014 40 methods, declared across 2 files: derphttp/derphttp_client.go (39), derphttp/mesh_client.go (1). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"208d5ad3726e400417249fccf9d1e5f801b11402f17a7f914a91d3cc1f6d3669"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: magicsock/relaymanager.go: FileTooLong \u2014 666 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"57f08792edf7634bf5e16eebc89ae2948e1221b91c104fe9c682397af5dd52a4"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: nftablesRunner: TooManyMethods \u2014 39 methods, declared across 2 files: linuxfw/nftables_runner.go (32), linuxfw/nftables_for_svcs.go (7). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. Most of these members implement linuxfw.NetfilterRunner (31 of 39 members), so moving them onto a smaller type would remove them from that contract rather than reduce it. To reduce it, split the contract instead: give each cohesive group of operations its own smaller interface and its own implementing type. Where the contract has to stay whole, move the work behind these members into collaborator types, so what is left here is a forward per member rather than a responsibility per member."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e29fb63493e96ff498517a47bb83f06b6b13393ae6d886cae1d2cd16bc52335"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/peerapi.go: FileTooLong \u2014 647 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/peerapi.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0321f31e4efc58bfba565ee6981333d2eab10f7219e8168e54173117509ef34e"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: network: TooManyMethods \u2014 38 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":673}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6dc0ae2ceb91e7095c6e5f17b79d366d69636c32708526393f7e67ad2e1bd82"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Impl: TooManyMethods \u2014 38 methods, declared across 2 files: netstack/netstack.go (37), netstack/netstack_userping.go (1). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"962f25126073b4b0bac5949f3f258528c300fb6f6abf071349435aff59e9215e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: logtail/logtail.go: FileTooLong \u2014 627 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd3aa178c39e21cf5da81ed0e0df1b86b64b8ddbf978b29f6604a7b26c7d32ca"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Server: TooManyMethods \u2014 37 methods, declared across 2 files: vnet/vnet.go (36), vnet/conf.go (1). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":913}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4c58181d78fa5dd31d3e08097558f2a5b05b115a293c9363f0e81b6792f3fac"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tailscaled/tailscaled.go: FileTooLong \u2014 602 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac8a5b40ede13fb0f1c3cf0a887dbbefe93784c254d3d6b738a879a51aab9dde"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: TestNode: TooManyMethods \u2014 36 methods, declared across 3 files: integration/integration.go (27), integration/service_windows.go (7), integration/service_notwindows.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/integration.go"},"region":{"startLine":620}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ffee8fdbb2f59d68fa7e106ca0f7aef5544b043e66483ff787aff3a671206b8"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: iptablesRunner: TooManyMethods \u2014 36 methods, declared across 2 files: linuxfw/iptables_runner.go (31), linuxfw/iptables_for_svcs.go (5). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. Most of these members implement linuxfw.NetfilterRunner (31 of 36 members), so moving them onto a smaller type would remove them from that contract rather than reduce it. To reduce it, split the contract instead: give each cohesive group of operations its own smaller interface and its own implementing type. Where the contract has to stay whole, move the work behind these members into collaborator types, so what is left here is a forward per member rather than a responsibility per member."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/iptables_runner.go"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"942144e53c9bc05296c707ee7a2cc12651ba1e712f86d7d9f5b21c8daf1a2a2e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: magicsock/derp.go: FileTooLong \u2014 587 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/derp.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"68d68cc188224b46967763ad2c943ea021181b9771889ee9afd0890a8f5eeb80"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: controlclient/auto.go: FileTooLong \u2014 570 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/auto.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7932e7222e64c8e846faff12cf409838dcae4e3b851f8561f735240ab6e0da4f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: serveEnv: TooManyMethods \u2014 34 methods, declared across 3 files: cli/serve_v2.go (21), cli/serve_legacy.go (11), cli/funnel.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"b648fa1a69b2836fc2767af85355e8a148772f8ea6a7f4e00294310f66a426f6"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Auto: TooManyMethods \u2014 34 methods, declared across 2 files: controlclient/auto.go (32), controlclient/direct.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/auto.go"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebc47de1d9c4e2739363104e2407770e664af80cb6e53fdfc77ef5437162a04f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: winutil/winutil_windows.go: FileTooLong \u2014 566 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/winutil_windows.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"260facb7474a56fc9142018315183f3bad16ccaaf2efcb20089c2fde88dde785"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: logpolicy/logpolicy.go: FileTooLong \u2014 551 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logpolicy/logpolicy.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4a4be8b1273994034d6afe0cbe82fef8482110919286e0d5df957f0a616e21c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: sclient: TooManyMethods \u2014 33 methods, declared across 2 files: derpserver/derpserver.go (31), derpserver/derpserver_linux.go (2). That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derpserver/derpserver.go"},"region":{"startLine":1823}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c203bbe16d295c0d7fb4c9c10c7f0cf47b6058f60b012d4b655093e34b6b96c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FakeNetfilterRunner: TooManyMethods \u2014 33 methods. Most of these members implement linuxfw.NetfilterRunner (31 of 33 members), so moving them onto a smaller type would remove them from that contract rather than reduce it. To reduce it, split the contract instead: give each cohesive group of operations its own smaller interface and its own implementing type. Where the contract has to stay whole, move the work behind these members into collaborator types, so what is left here is a forward per member rather than a responsibility per member."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/fake_netfilter.go"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb2e8e839b3552850ce76f3a31baf5b856f38a34fef2c0e5d098bc01375d5734"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/tailnet-lock.go: FileTooLong \u2014 548 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/tailnet-lock.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cefa45091d7b1aea0128a6ef7cfb5baba95de6d780e21cd102c5168ed2cc084b"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipn/prefs.go: FileTooLong \u2014 539 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/prefs.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a92c1d5ea2285f67c201098e78f20b722dd165b5c45f6d9e7fbec388bc72ddf"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/file.go: FileTooLong \u2014 521 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/file.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3aa021ac0783fd9ff9646b7625e50beec4077fddc490ae09ea543f1b2e41b1e7"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: s4u/s4u_windows.go: FileTooLong \u2014 521 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/winutil/s4u/s4u_windows.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"30a2b80cd0206f61d98c19ab6436bcc3c4f59b1d4999cd39a754408c193efb05"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: testwrapper/testwrapper.go: FileTooLong \u2014 519 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/testwrapper/testwrapper.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a07c6bb3836d47ee6ec427d8a747625799401b29faf4ddb5d8f48437e5bfda9"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Direct: TooManyMethods \u2014 31 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/direct.go"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"e91e4d7b9c494f7b9f11cbc65949bf84712560921fb0e143f71e9ac52fb636cb"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: relayManager: TooManyMethods \u2014 31 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/relaymanager.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb01e68d78736b4b84ea0acb9039d8b832df93718763653c669f8011426c104d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: k8s-operator/svc-for-pg.go: FileTooLong \u2014 514 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"955c76db6506ce0ec62f0a25ba38ed803defeb4050a2b5f11fbfbc22f633a872"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: routemanager/routemanager.go: FileTooLong \u2014 514 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/routemanager/routemanager.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0769c8940bed0a8edda7d3b2275df90503a4b6e351566f877696210910a60cb2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: fbstatus/fbstatus.go: FileTooLong \u2014 511 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/fbstatus/fbstatus.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bdf0251f977186452076569b032f5b577eecb4ea342cc8ebd23279a961226b2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: systray/systray.go: FileTooLong \u2014 507 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/systray/systray.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4ee463711284762a76d55910d6b80c435a2280497da49603ca599f04266ca42"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: k8s-operator/egress-services.go: FileTooLong \u2014 507 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e339fc296a7cc8bd75be9139b0d05e382c1bee86101fcff974828fe66bc6d4f6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ipnlocal/profiles.go: FileTooLong \u2014 504 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/profiles.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"68858ce8f13d503dc4567a5f9ccf70433a0e9fa937aa3acd5fd905ab425d1b73"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tsweb/tsweb.go: FileTooLong \u2014 503 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tsweb/tsweb.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6feed3965d4f757da3285666908a4c84c449fe7caf514f87eef0c5f31af6ce5b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): k8s-operator/sessionrecording/spdy/conn.go:35-54 | k8s-operator/sessionrecording/ws/conn.go:34-53 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060k8s-operator/sessionrecording/spdy/conn.go:35\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/sessionrecording/spdy/conn.go"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"88c4e2b8ba9851f582f2e0873ff03227f5465421fb17e67768032fc1ad056491"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): feature/conn25/datapath.go:175-191 | feature/conn25/datapath.go:242-258 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060feature/conn25/datapath.go:175\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/datapath.go"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"f53f270c13273c65bcb5e7cb2c76c205d7b1ee104ccbb461cb4f4d5296283c7f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): net/portmapper/legacy_upnp.go:49-65 | net/portmapper/legacy_upnp.go:188-204 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/portmapper/legacy_upnp.go:49\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/legacy_upnp.go"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"38dd2bf512edb1dc33210b9180c1fed569b903942e271902d41e0a642da5960b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): prober/derp.go:386-402 | prober/derp.go:708-724 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060prober/derp.go:386\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"prober/derp.go"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b064d564faf241a59fecd291d54ac6ef8b08e61b9b42d4d778749b3404a68ac"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): wgengine/bench/bench.go:198-214 | wgengine/bench/bench.go:229-245 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/bench/bench.go:198\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/bench/bench.go"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"b273f2e88e60243b7a8acdbc6d2206d5629bc750ba8ac457806c4ce29f1faf38"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): client/tailscale/devices.go:252-267 | client/tailscale/devices.go:280-295 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/tailscale/devices.go:252\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/devices.go"},"region":{"startLine":252}}}],"partialFingerprints":{"codehealthFindingId/v1":"9562cb7277e620047f9b509eb9c534382bf484e4d595d7c701e82db03ea24ae6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): cmd/gitops-pusher/gitops-pusher.go:60-75 | cmd/gitops-pusher/gitops-pusher.go:105-120 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/gitops-pusher/gitops-pusher.go"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"060c1a519a984247aeab1cbd07a4e01a4cec6504f3d61ea1600ff903b8b2cc7f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): net/dns/nm.go:199-214 | net/dns/nm.go:237-253 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/dns/nm.go:237\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/dns/nm.go"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c4a1a4082b31d949609002ed1821b3b14c4b8c6ff1d912e0fae85f091fc9937"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): k8s-operator/reconciler/proxygrouppolicy/proxygrouppolicy.go:231-245 | k8s-operator/reconciler/proxygrouppolicy/proxygrouppolicy.go:292-306 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060k8s-operator/reconciler/proxygrouppolicy/proxygrouppolicy.go:231\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/reconciler/proxygrouppolicy/proxygrouppolicy.go"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"03b62267a76a7da94bf9f67e85d5875a140d2c725ebb97257308b80750e53951"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): cmd/omitsize/omitsize.go:124-137 | cmd/omitsize/omitsize.go:161-174 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/omitsize/omitsize.go:124\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/omitsize/omitsize.go"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2a659044af4200bc4eef7c7be6c3c9c977a545226ac58c9d53c513b734243b6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): net/portmapper/legacy_upnp.go:100-113 | net/portmapper/legacy_upnp.go:239-252 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/portmapper/legacy_upnp.go:100\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/legacy_upnp.go"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"961b6e42d05b077c63d4ca43157aaeff77c6ae35ecb80dc72256dcce7f54ce87"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): util/linuxfw/iptables_runner.go:196-210 | util/linuxfw/iptables_runner.go:416-429 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/iptables_runner.go:196\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/iptables_runner.go"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"05fbbb8e4b5697cb3a4897282142f1ff8e6623632dfc07835e773d950c979f32"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): client/tailscale/keys.go:45-57 | client/tailscale/keys.go:131-143 | client/tailscale/routes.go:36-50 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/tailscale/keys.go:45\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/keys.go"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"46404dd528e15cfd311d6b58d389c83da696243a849ee4b4d065aedffc373ea4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): cmd/k8s-operator/ingress.go:110-122 | cmd/k8s-operator/svc.go:173-185 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/ingress.go:110\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"f734886bc64cff64d35686b475a26ffdbbd6891eff36fba034cb08bc5595c6d3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): cmd/tsp/tsp.go:292-304 | cmd/tsp/tsp.go:378-390 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tsp/tsp.go:292\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsp/tsp.go"},"region":{"startLine":292}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef1ba64cf68bb851c0f7bdd49f3462ff990342f5096fc0b8e2827d617ed8e955"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): ipn/localapi/debug.go:53-66 | ipn/localapi/localapi.go:1267-1279 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/localapi/debug.go:53\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d7ded8376319f990dc77f3c8ceb2ccea1938a5f81101d64072e0637b8d837bc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): util/linuxfw/nftables_runner.go:1566-1578 | util/linuxfw/nftables_runner.go:1594-1606 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/nftables_runner.go:1566\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":1566}}}],"partialFingerprints":{"codehealthFindingId/v1":"11691208bbad9d7b59b9c0a18728ed924da47757ee149c34bf3ea93f7921d747"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 7): cmd/k8s-operator/operator.go:1492-1503 | cmd/k8s-operator/operator.go:1551-1562 | cmd/k8s-operator/operator.go:1586-1597 | cmd/k8s-operator/operator.go:1656-1667 | cmd/k8s-operator/operator.go:1687-1698 | cmd/k8s-operator/operator.go:1719-1730 | cmd/k8s-operator/operator.go:1757-1768 \u2014 all 7 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1492\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1492}}}],"partialFingerprints":{"codehealthFindingId/v1":"09e75e9b3ea8044d958ad76f23848481b4bd8b2ee07907e113f37d9b31ab0226"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): client/tailscale/devices.go:147-158 | client/tailscale/devices.go:186-197 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/tailscale/devices.go:147\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/devices.go"},"region":{"startLine":147}}}],"partialFingerprints":{"codehealthFindingId/v1":"18e748db823e46db1e34685873e6fe2ce4a64c6e8aca16f33c06bc0a4ef3942a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): cmd/derper/derper.go:221-232 | cmd/derpprobe/derpprobe.go:143-154 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/derper/derper.go:221\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/derper.go"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f9a2bc3a3a6415393e2a3b048e8fd89d143df8ac908eb18bc7d3185d390ac06"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): cmd/sniproxy/server.go:275-286 | cmd/sniproxy/server.go:296-307 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/sniproxy/server.go:275\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/sniproxy/server.go"},"region":{"startLine":275}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddddd93b04fa6425021eb95bb928d142225713c11eab1103b1ef3628dd324aad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): internal/client/tailscale/vip_service.go:101-113 | internal/client/tailscale/vip_service.go:121-132 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"internal/client/tailscale/vip_service.go"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a7e8893973922abf2e9fefc4f076855786ed65a51e3fcfef29960780ebdf330"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): ipn/localapi/debug.go:300-311 | ipn/localapi/debug.go:317-328 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/localapi/debug.go:300\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":300}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e5626504b5f905664d25084b8ddcf72faf8854250e7284699420b1b66f1dd81"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): tka/aum.go:250-261 | tka/sig.go:221-232 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tka/aum.go:250\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tka/aum.go"},"region":{"startLine":250}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc8d3aa7dc3342eadb34898fa0b6f2d744053a595e1b2f1a355af5f40f9eebda"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): tstest/clock.go:279-290 | tstest/clock.go:297-308 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/clock.go"},"region":{"startLine":279}}}],"partialFingerprints":{"codehealthFindingId/v1":"f234456af743cb1ce0e033b8c7adf07847e2f3ce5dd262b2b70fdc1b5049e21c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): tstest/natlab/vnet/vnet.go:1963-1974 | tstest/natlab/vnet/vnet.go:2062-2073 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vnet/vnet.go:1963\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1963}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba0da62d2a02dcaef0e32819cc9a965e89a4b48af4f537ff44aee4bc1a23e2c5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): util/linuxfw/nftables_runner.go:1260-1271 | util/linuxfw/nftables_runner.go:1330-1341 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/nftables_runner.go:1260\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":1260}}}],"partialFingerprints":{"codehealthFindingId/v1":"f27fafe3941866d40c0b8b9ef041a28e75b7a6589bba685b9279d0bfe6645fbf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): util/linuxfw/nftables_runner.go:2266-2278 | util/linuxfw/nftables_runner.go:2349-2360 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/nftables_runner.go:2266\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_runner.go"},"region":{"startLine":2266}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c078834c8471f91a45d59b18d9a0d88f52af1e20b3694a5953e8751602fdbda"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): client/tailscale/dns.go:48-60 | client/tailscale/keys.go:130-140 | client/tailscale/routes.go:35-47 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/tailscale/dns.go:48\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/dns.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"b358033d9c408a0fa06bb83931fa81f76b5a785ba5687952a4afa001d0a83298"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): ipn/ipnlocal/drive.go:93-103 | ipn/ipnlocal/drive.go:151-161 | ipn/ipnlocal/drive.go:211-221 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/drive.go:93\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/drive.go"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"30a0c05c8e4a98178afb838766d6929a45bf7b39e9f8ef4839b2314461d9488a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): util/linuxfw/nftables_for_svcs.go:65-75 | util/linuxfw/nftables_for_svcs.go:100-110 | util/linuxfw/nftables_for_svcs.go:148-158 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_for_svcs.go"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"d087f2d4b04645496ccba3c3bc2cc16dddc686db2c5257cd035d1b00a86dc8f0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): client/tailscale/tailscale.go:172-182 | internal/client/tailscale/tailscale.go:74-85 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/tailscale/tailscale.go:172\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/tailscale/tailscale.go"},"region":{"startLine":172}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ed67c7a6b95c20643e39890ce155bf4b1f769e0f28d223823aed02242168940"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): cmd/derper/derper.go:205-215 | cmd/derpprobe/derpprobe.go:126-137 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/derper/derper.go:205\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/derper/derper.go"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a4266e7fe64b417c830b649d36b09ed4ef7fd778887eb0dd5f7934a232a28fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): cmd/k8s-operator/egress-services.go:691-701 | cmd/k8s-operator/svc-for-pg.go:760-770 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/egress-services.go:691\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/egress-services.go"},"region":{"startLine":691}}}],"partialFingerprints":{"codehealthFindingId/v1":"228a142fc098b2f2278f1dc278c4fe9e9861762a92719446b50224f51ed7459f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): cmd/tailscale/cli/debug.go:1308-1318 | cmd/tailscale/cli/debug.go:1384-1394 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tailscale/cli/debug.go:1308\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/debug.go"},"region":{"startLine":1308}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebc2bce08b14dcbdbfe8756cf1025558469d08cbecfdba00cf690921985b1128"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): cmd/tsidp/tsidp.go:488-498 | cmd/tsidp/tsidp.go:535-545 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tsidp/tsidp.go:488\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"b55b763ab4644d9f235483ce0e10ab2aab68fbf2a3cf9eb0615c8fae3eb54bc2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): derp/derphttp/derphttp_client.go:417-427 | derp/derphttp/derphttp_client.go:563-573 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060derp/derphttp/derphttp_client.go:417\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derphttp/derphttp_client.go"},"region":{"startLine":417}}}],"partialFingerprints":{"codehealthFindingId/v1":"1182439d45c98ce7071adf8515f9af771a58764d526ae817f8fedc505bd734e7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): feature/conn25/conn25.go:1333-1345 | feature/conn25/conn25.go:1389-1399 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060feature/conn25/conn25.go:1333\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1333}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a3198368cf296f39e1c5b95d9bd97cebbc29ae27b193eb3132ff5680c8e2324"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): feature/wakeonlan/wakeonlan.go:61-71 | feature/wakeonlan/wakeonlan.go:131-141 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060feature/wakeonlan/wakeonlan.go:61\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/wakeonlan/wakeonlan.go"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf355833e0a3359f778e0c63c960f859dfe9c00d8d46907bb59c86dd94ea36d8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): internal/client/tailscale/vip_service.go:48-58 | internal/client/tailscale/vip_service.go:71-81 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060internal/client/tailscale/vip_service.go:48\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"internal/client/tailscale/vip_service.go"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"29d4ba5873fa706c7a72db3049c3a22229ea1dbdbb9a1e6e072227e52c3eb0be"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): ipn/localapi/debug.go:412-422 | ipn/localapi/debug.go:458-468 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/localapi/debug.go:412\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/debug.go"},"region":{"startLine":412}}}],"partialFingerprints":{"codehealthFindingId/v1":"d01fbff1411bf077e143dcbd4b8fdbf299e7c4c99e79ed481e7b8a91ac259ce4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): ipn/localapi/localapi.go:1695-1705 | ipn/localapi/localapi.go:1742-1752 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/localapi/localapi.go:1695\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":1695}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d27d61e9e0932dfab5e0395c91d8eea2344843e5ff1e42dc810a7002e437cd6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): ipn/serve.go:282-292 | ipn/serve.go:295-305 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/serve.go:282\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/serve.go"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbf412a1b83ef2893ca244825ef87c0c1a6ff2fc89334fa29dbf44161e48bbf2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): sessionrecording/connect.go:391-401 | sessionrecording/connect.go:416-426 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060sessionrecording/connect.go:391\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"sessionrecording/connect.go"},"region":{"startLine":391}}}],"partialFingerprints":{"codehealthFindingId/v1":"b68fe3eb1885991e828b80c82e7b9e728d1a4bbcd28dd2e25bd49f25da836fe1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): tstest/natlab/vnet/vnet.go:1656-1666 | tstest/natlab/vnet/vnet.go:2078-2089 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vnet/vnet.go:1656\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1656}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1071e42b787cbeb9ada5ba66640fa9ddd9839400955d10627a720270320464c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): tstest/natlab/vnet/vnet.go:1677-1687 | tstest/natlab/vnet/vnet.go:2060-2071 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1677}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa872bcf58a8a4bc0b591a92a71da06bf7e3a5e20271cd0c91f03cad105702ff"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): tstest/natlab/vnet/vnet.go:1736-1746 | tstest/natlab/vnet/vnet.go:1961-1972 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1736}}}],"partialFingerprints":{"codehealthFindingId/v1":"b705c79f27207e470e2e8634694945c16dffff7bdc92c00976d46873bb042208"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): util/linuxfw/nftables_for_svcs.go:84-94 | util/linuxfw/nftables_for_svcs.go:167-177 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/nftables_for_svcs.go:84\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_for_svcs.go"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab73b05476ed9b4955dd37b805bf4144e8433823a1de596c4ce60f178828bd1a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): version/mkversion/mkversion.go:371-381 | version/mkversion/mkversion.go:428-438 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060version/mkversion/mkversion.go:371\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"version/mkversion/mkversion.go"},"region":{"startLine":371}}}],"partialFingerprints":{"codehealthFindingId/v1":"0eb728ac4c11289b4596a13df1093491ebf65d0527a61129591c54b584d86468"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): wgengine/netstack/netstack.go:951-961 | wgengine/netstack/netstack.go:988-998 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/netstack/netstack.go:951\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":951}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f81bd78139151980a986ca8d55bd9fd362f487929bfef9b569e123f5db4423f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/connector-gen/aws.go:56-65 | cmd/connector-gen/github.go:77-86 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/connector-gen/aws.go"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b0eb3b7902d4626d232aa48ecaffa419c2bb11eb2fb3e0553f96d086410729a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/k8s-operator/operator.go:1020-1029 | cmd/k8s-operator/operator.go:1091-1100 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1020\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1020}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfa680bcb0bf9e20b23d56a36d4be0dc9f8ee43d40413929862691e10de19995"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/k8s-proxy/internal/config/config.go:174-185 | cmd/k8s-proxy/internal/config/config.go:214-223 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-proxy/internal/config/config.go:174\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-proxy/internal/config/config.go"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dd6ea838e9d9ccbdad09ba0d07feb845714623feff3a2c90145201702fe9e48"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/tailscale/cli/configure-flash-appliance.go:500-509 | gokrazy/mkfs/mkfs.go:317-326 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tailscale/cli/configure-flash-appliance.go:500\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/configure-flash-appliance.go"},"region":{"startLine":500}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ff9c0413972f730b378c9da9127370428f95b174b3f68c63f4ec55031a24156"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/tailscale/cli/serve_legacy.go:445-454 | cmd/tailscale/cli/serve_v2.go:1631-1641 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tailscale/cli/serve_legacy.go:445\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":445}}}],"partialFingerprints":{"codehealthFindingId/v1":"0eef328c2081ac149b48c227aaef7012f691716ed41a9e5b2e76aaf7a320a447"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/tailscale/cli/switch.go:167-176 | cmd/tailscale/cli/switch.go:226-237 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tailscale/cli/switch.go:167\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/switch.go"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"9be0c4b6770c4f8fed6e84beaaba15ce2ca6a090d81a73a83e95dce6dda034c8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): cmd/tsidp/tsidp.go:510-519 | cmd/tsidp/tsidp.go:580-589 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tsidp/tsidp.go:510\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tsidp/tsidp.go"},"region":{"startLine":510}}}],"partialFingerprints":{"codehealthFindingId/v1":"f18a1cb83cd2f49bf8a2d53c130acaffa3477694d40bad31e66a5a5de4b65b27"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): derp/derp_client.go:256-265 | derp/derp_client.go:288-297 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060derp/derp_client.go:256\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"derp/derp_client.go"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc8d645c50398e7f73cea2c5bc045988d2078a1fc076ee0c774af17bc24d9892"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): feature/tap/tap_linux.go:267-277 | feature/tap/tap_linux.go:300-309 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060feature/tap/tap_linux.go:267\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/tap/tap_linux.go"},"region":{"startLine":267}}}],"partialFingerprints":{"codehealthFindingId/v1":"107b75b2ad443ed74d64856654a70f8d4000291ec847e5b17dc4d89f55470ac6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): ipn/localapi/localapi.go:378-387 | ipn/localapi/localapi.go:1650-1660 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/localapi/localapi.go"},"region":{"startLine":378}}}],"partialFingerprints":{"codehealthFindingId/v1":"00d5f21b75337ca236d270a3975f06a39c1cb44ecfe740a0d2f93b72ea6699ab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): logtail/logtail.go:241-250 | logtail/logtail.go:534-546 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060logtail/logtail.go:241\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"logtail/logtail.go"},"region":{"startLine":241}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbbcfd2017952e90badc7be3d757b15f50fd8b868eca5b85e74ac88c67906d3b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): net/packet/packet.go:206-215 | net/packet/packet.go:328-337 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"c749dbf9ed873b8cefd17d8342f9cf219913ca3b5194e0dc726b802bd98cde26"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): net/portmapper/legacy_upnp.go:151-160 | net/portmapper/legacy_upnp.go:290-299 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/portmapper/legacy_upnp.go:151\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/portmapper/legacy_upnp.go"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"54ba1fa40a022ab3e6d35e5a07b4bc2f8f73e8237e04bcfe8f192032577bf43e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): tstest/natlab/vnet/vnet.go:1716-1725 | tstest/natlab/vnet/vnet.go:1979-1988 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":1716}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cf8264d9ce1b7abeb1bc9606d768f9e56e852b4259294acfca72b5306f3d202"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): wgengine/bench/wg.go:38-47 | wgengine/bench/wg.go:64-73 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/bench/wg.go:38\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/bench/wg.go"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"0184edadf98454bf80e035196203de3630d422c4fd3e641529ea79ae407c599a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): wgengine/filter/filter.go:539-548 | wgengine/filter/filter.go:601-610 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/filter/filter.go:539\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/filter.go"},"region":{"startLine":539}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7864ebb5008d89a941bba62aff14574a9b46b50341c470202198a63b92f44a1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 8): ipn/ipnlocal/tailnet-lock.go:1306-1314 | ipn/ipnlocal/tailnet-lock.go:1343-1351 | ipn/ipnlocal/tailnet-lock.go:1391-1399 | ipn/ipnlocal/tailnet-lock.go:1435-1443 | ipn/ipnlocal/tailnet-lock.go:1484-1492 | ipn/ipnlocal/tailnet-lock.go:1526-1534 | ipn/ipnlocal/tailnet-lock.go:1562-1570 | ipn/ipnlocal/tailnet-lock.go:1598-1606 \u2014 all 8 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/tailnet-lock.go:1306\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1306}}}],"partialFingerprints":{"codehealthFindingId/v1":"04167bb5fa659f52347e5f81685e67d65b9b48e1ae914fe9934fcd605f529e16"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): control/controlclient/auto.go:493-504 | control/controlclient/auto.go:530-538 | control/controlclient/auto.go:559-567 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060control/controlclient/auto.go:493\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/auto.go"},"region":{"startLine":493}}}],"partialFingerprints":{"codehealthFindingId/v1":"d23901679b7404989068457ec1b2d25f495ce6995f26bbccb4aac936d7e8b4b8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/containerboot/egressservices.go:307-315 | cmd/containerboot/egressservices.go:325-333 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/containerboot/egressservices.go:307\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"1db47d6657087f156c65fc4ac39b9ac1a5302a0834ed98d1b93e97e33555306e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/ingress.go:84-92 | cmd/k8s-operator/svc.go:125-133 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/ingress.go"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2a2e1071b75eadce69747ba3169addd568ba2351ce3bd65876e8eba62c150c7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/operator.go:1119-1127 | cmd/k8s-operator/operator.go:1200-1208 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1119\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1119}}}],"partialFingerprints":{"codehealthFindingId/v1":"a87ca20947a401b193352a56c4a426abc3274b3cd03495d529943c3a88cbb3dc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/operator.go:1279-1287 | cmd/k8s-operator/operator.go:1811-1819 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1279\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1279}}}],"partialFingerprints":{"codehealthFindingId/v1":"4df10be2360723e89f20150a1e3f67a47650ec0dc7b58895555273da707f6142"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/operator.go:1299-1307 | cmd/k8s-operator/operator.go:1830-1838 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1299\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1299}}}],"partialFingerprints":{"codehealthFindingId/v1":"913e6ea1961ff81544e07d743176d3316fd6a13cbe40d475e7a0885e0273bb34"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/proxygroup.go:1036-1044 | cmd/k8s-operator/tsrecorder.go:546-554 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/proxygroup.go:1036\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":1036}}}],"partialFingerprints":{"codehealthFindingId/v1":"a49865aae896ee9e55604c2a903e69bca706d742b7933b786825d0d7b86f4856"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/k8s-operator/svc-for-pg.go:165-173 | cmd/k8s-operator/svc.go:206-217 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/svc-for-pg.go:165\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc-for-pg.go"},"region":{"startLine":165}}}],"partialFingerprints":{"codehealthFindingId/v1":"64cd8a5b8fa1dae0ac4d0fd7c6dc1056cc1972fecf451e045d470d9e8fc61801"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): cmd/tailscale/cli/serve_legacy.go:238-246 | cmd/tailscale/cli/serve_v2.go:380-388 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/serve_legacy.go"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebe3430aadd2c9b192035105b73df552a3bf77a1186c1f0a063a20af2c7935b5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): feature/tpm/tpm.go:241-249 | ipn/store/stores.go:212-220 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060feature/tpm/tpm.go:241\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/tpm/tpm.go"},"region":{"startLine":241}}}],"partialFingerprints":{"codehealthFindingId/v1":"80dba57a01bf38cb92a2208871c84f2310f657d89d3e32380d8fb36bb7324265"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): ipn/ipnlocal/local.go:8902-8910 | ipn/ipnlocal/local.go:8942-8950 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/local.go:8902\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":8902}}}],"partialFingerprints":{"codehealthFindingId/v1":"e73bee6261d4d75df5fdb9a300471236a55fa0fc47ef210483c5f6ee6aa4bf2c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): k8s-operator/api-proxy/proxy.go:218-226 | k8s-operator/api-proxy/proxy.go:288-296 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060k8s-operator/api-proxy/proxy.go:218\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/api-proxy/proxy.go"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ecff770962c51fa627893a904635b1537c5c788925cc2710fda3ecb1da0a851"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): net/netcheck/netcheck.go:549-557 | net/netcheck/netcheck.go:579-587 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/netcheck/netcheck.go:549\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":549}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e8bcc935207415af3c21e5912b781868ae4f83d5b12797768841f6f3d4ac681"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): tailcfg/tailcfg.go:1653-1661 | tailcfg/tailcfg.go:1695-1703 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tailcfg/tailcfg.go:1653\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tailcfg/tailcfg.go"},"region":{"startLine":1653}}}],"partialFingerprints":{"codehealthFindingId/v1":"0777b58aea9f2d690113bc814ab2689732eed1e401777aff6a95ad4d509f73a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): tstest/natlab/vnet/easyaf.go:54-62 | tstest/natlab/vnet/nat.go:256-264 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vnet/easyaf.go:54\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/easyaf.go"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"a08442dd00385c5f9ad8f8772ba363f49f54b2cf2e2c65d49a5b448583254708"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): tstest/natlab/vnet/vnet.go:2060-2068 | tstest/natlab/vnet/vnet.go:2078-2086 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vnet/vnet.go:2060\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":2060}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ab5ed40f5cfdb1e53c3e55c77acf721eb17da9e4c3b5cc636d5be1c998c388e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): types/views/views.go:742-750 | types/views/views.go:761-769 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060types/views/views.go:742\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"types/views/views.go"},"region":{"startLine":742}}}],"partialFingerprints":{"codehealthFindingId/v1":"739b16e0f9c057ae2eb082ed6165b39e8fbee83812ca5f38b270f618f0d0c08f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): wgengine/router/osrouter/router_linux.go:804-812 | wgengine/router/osrouter/router_linux.go:844-852 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/router/osrouter/router_linux.go:804\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/router/osrouter/router_linux.go"},"region":{"startLine":804}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf4d5a6f6b299a65e18838f87d445b4767f9f0dbfb5426e3fcb86b40098ffe1c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 4): util/syspolicy/source/test_store.go:328-335 | util/syspolicy/source/test_store.go:347-354 | util/syspolicy/source/test_store.go:366-373 | util/syspolicy/source/test_store.go:385-392 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/syspolicy/source/test_store.go:328\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/source/test_store.go"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd2d36a6f6ce46cec543bbb487b53707252a188913b153494c0cbae575adf9f7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): ipn/ipnlocal/tailnet-lock.go:1319-1326 | ipn/ipnlocal/tailnet-lock.go:1448-1455 | ipn/ipnlocal/tailnet-lock.go:1497-1504 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/tailnet-lock.go:1319\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1319}}}],"partialFingerprints":{"codehealthFindingId/v1":"f931bb236a903c9e681abb7657c82a7fb8fda792641508238e6c3623c448a22f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): client/local/local.go:366-373 | client/local/local.go:386-393 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060client/local/local.go:366\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/local/local.go"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"411a673ed9e10a95dc7f45f1c8e51d09b6b8ebf088d84fe223bd8983121f27b4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): cmd/containerboot/egressservices.go:94-103 | cmd/containerboot/ingressservices.go:52-59 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/containerboot/egressservices.go:94\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"57b157a8a9a055ae49e344c885576b8cc20e2b95793770a6c2f4da9172de069a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): cmd/containerboot/egressservices.go:437-444 | cmd/containerboot/ingressservices.go:186-193 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/containerboot/egressservices.go:437\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/containerboot/egressservices.go"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"07c75ccab25651edff28ff39b161224575db58d73c885049d01ed8d363b92cf1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): cmd/k8s-operator/operator.go:1008-1015 | cmd/k8s-operator/operator.go:1078-1085 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1008\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1008}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe09619049c7dd80ab0c6be5a50104cf1ed3d776cdc89daec0473c76503b9f2e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): cmd/k8s-operator/svc.go:155-162 | cmd/k8s-operator/svc.go:191-198 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/svc.go:155\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/svc.go"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4200f6f45153c333b7e115c9e698d3a5c7f2078e79934df7c300860385e8b9a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): ipn/ipnlocal/tailnet-lock.go:1122-1129 | ipn/ipnlocal/tailnet-lock.go:1160-1167 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/tailnet-lock.go:1122\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1122}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d859e344fc5a98cb28503de03271f2e4b416fe6fb1e2517c7eae225106a4b2b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): ipn/ipnlocal/tailnet-lock.go:1427-1434 | ipn/ipnlocal/tailnet-lock.go:1476-1483 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1427}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6390da736d031137518652867d88cbc904978a92cc77c2d70ed8aa61e330b61"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): k8s-operator/api-proxy/proxy.go:228-235 | k8s-operator/api-proxy/proxy.go:298-305 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060k8s-operator/api-proxy/proxy.go:228\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/api-proxy/proxy.go"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ce604f9d740b2b17645fde4e4c7b7f7a5ab3a8f445ea55d0644403e419f651a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): net/netcheck/netcheck.go:1112-1119 | net/netcheck/netcheck.go:1121-1128 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/netcheck/netcheck.go:1112\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1112}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65924862251ac845fc543df79f4441be73009341217b615fce95b330952aa12"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): net/packet/checksum/checksum.go:31-38 | net/packet/checksum/checksum.go:59-66 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/packet/checksum/checksum.go:31\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/checksum/checksum.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"c102370ffef2ce20eae60b00a2da51903085a28e021e2a755a3ed11569c747a9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): net/udprelay/server.go:1036-1048 | net/udprelay/server.go:1072-1079 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/udprelay/server.go:1036\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/udprelay/server.go"},"region":{"startLine":1036}}}],"partialFingerprints":{"codehealthFindingId/v1":"daeaecf769ec25415cbc2b14dfe9aa9668467b6ee09fdc5eb738033e306b681d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): util/linuxfw/nftables_for_svcs.go:259-266 | util/linuxfw/nftables_runner.go:79-86 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060util/linuxfw/nftables_for_svcs.go:259\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/linuxfw/nftables_for_svcs.go"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"c21f95641831f80d9ebebe2fb99b34bdf77817d7aaed44764830ed11d6a03787"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): wgengine/netstack/netstack.go:917-924 | wgengine/netstack/netstack.go:1416-1423 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/netstack/netstack.go:917\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":917}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f6b5ad3799763a8acec78864eb812c80258b8dd93b1764d74402d3576e76e21"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): wgengine/netstack/netstack.go:1257-1264 | wgengine/netstack/netstack.go:1297-1304 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060wgengine/netstack/netstack.go:1257\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netstack/netstack.go"},"region":{"startLine":1257}}}],"partialFingerprints":{"codehealthFindingId/v1":"a621bba48118e74cb6963b17f1f0ecc34eb4b34efaefed5313bdf327eec1c117"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): cmd/k8s-operator/operator.go:1135-1142 | cmd/k8s-operator/operator.go:1193-1199 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/operator.go:1135\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1135}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb3cb1e3d17efbf05534707d26373f2204622907162c76f917f2931d3c3802c8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): cmd/k8s-operator/proxygroup.go:748-754 | cmd/k8s-operator/tsrecorder.go:569-575 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/k8s-operator/proxygroup.go:748\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/proxygroup.go"},"region":{"startLine":748}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d6d17bd5de056d44402c143408b3e68eda8fc762a5ad79add7d4719d56bea55"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): cmd/tailscale/cli/set.go:112-118 | cmd/tailscale/cli/up.go:123-129 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tailscale/cli/set.go:112\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/cli/set.go"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"c23cf8c9df5fd1076ff04b022fec87808c0e77512828c751452f3f00e043b3d2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): ipn/ipnlocal/node_backend.go:1126-1132 | ipn/ipnlocal/node_backend.go:1151-1157 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1126}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb834103ab34e3059d2e47e530dfe0c1079e9c73a9f60d1ae7ef801bc5d7feaf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): ipn/ipnlocal/tailnet-lock.go:1380-1386 | ipn/ipnlocal/tailnet-lock.go:1476-1482 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":1380}}}],"partialFingerprints":{"codehealthFindingId/v1":"5545a67d0c786ec7d6644b176211b51401e4fa1a1bf11db94043318b516fc4b6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): k8s-operator/utils.go:71-77 | net/dns/resolver/tsdns.go:863-870 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060k8s-operator/utils.go:71\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"k8s-operator/utils.go"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"e35cae0dc61d4f24a39e36f2e7d0dc5373f02c87ba31c25f437d95f641dced0e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): net/packet/packet.go:219-225 | net/packet/packet.go:340-346 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/packet/packet.go:219\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/packet.go"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6460c2e3ccd040ce839c095e4bd699913ba996099b4f9fb54f3c9ce105d9bee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): util/syspolicy/internal/metrics/metrics.go:125-131 | util/syspolicy/internal/metrics/metrics.go:153-159 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"util/syspolicy/internal/metrics/metrics.go"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d31821aa73856dd47c3c24a93a71a7ec6273bb2ef37cd79dbedc7f94bc35974"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): cmd/k8s-operator/operator.go:1391-1398 | cmd/k8s-operator/operator.go:1411-1416 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/operator.go"},"region":{"startLine":1391}}}],"partialFingerprints":{"codehealthFindingId/v1":"010dc2e82e7011ecd654680a918eb4d7c6e55c3ff6e10363825ddcb8443cfcc7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): net/packet/udp4.go:41-46 | net/packet/udp6.go:37-42 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/packet/udp4.go"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"10f68efe89b68c9b7f0546ed6da31aad65ff3170bae7130c67addc633bb65993"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): tstest/natlab/vmtest/qemu.go:154-159 | tstest/natlab/vmtest/qemu.go:208-213 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vmtest/qemu.go:154\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vmtest/qemu.go"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b0b03f533e1b2a0e06b28a57b627654a781c819f9772c4cc714dce6149a8e18"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): tstest/natlab/vnet/vnet.go:208-213 | tstest/natlab/vnet/vnet.go:227-232 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tstest/natlab/vnet/vnet.go:208\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/natlab/vnet/vnet.go"},"region":{"startLine":208}}}],"partialFingerprints":{"codehealthFindingId/v1":"161424dae8140e63c7fe6e3a5db741961cb706cbd08d0cbbf1405db5e391518e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): wgengine/netlog/netlog.go:267-272 | wgengine/netlog/netlog.go:351-356 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/netlog/netlog.go"},"region":{"startLine":267}}}],"partialFingerprints":{"codehealthFindingId/v1":"0299d10b0911b68066c0857db294ec6eeb59fe61538f8bdc07809539c815153f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): cmd/k8s-operator/connector.go:249-253 | cmd/k8s-operator/connector.go:302-306 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/k8s-operator/connector.go"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"657d490ef9ea87fd347778203dc32f47ae67bad4d7f986105a8e9bd2e20b9f20"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): cmd/tta/tta.go:192-196 | cmd/tta/tta.go:211-215 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060cmd/tta/tta.go:192\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tta/tta.go"},"region":{"startLine":192}}}],"partialFingerprints":{"codehealthFindingId/v1":"90b74e70739085f1068965126e2bf519b1c298fcf725823f48932429341beecc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): ipn/ipnlocal/tailnet-lock.go:900-904 | ipn/ipnlocal/tailnet-lock.go:1199-1203 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/tailnet-lock.go:900\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":900}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5058a27b6c3aca997bd6838408c68e8ad06e4769ceb3785257f6ba3f22b9e03"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): ipn/ipnlocal/tailnet-lock.go:979-984 | ipn/ipnlocal/tailnet-lock.go:1058-1062 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/ipnlocal/tailnet-lock.go:979\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/tailnet-lock.go"},"region":{"startLine":979}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fb0c10d869f2dae4eb52f807b6e2e9de589d66c2d5b0aebe6051305a585e79f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): ipn/store/kubestore/store_kube.go:178-183 | ipn/store/kubestore/store_kube.go:237-241 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060ipn/store/kubestore/store_kube.go:178\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/store/kubestore/store_kube.go"},"region":{"startLine":178}}}],"partialFingerprints":{"codehealthFindingId/v1":"6076c0ee654aee86b58710f8b3aedba4aec939a6adc849d6eee86fdd1349e6af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): net/netcheck/netcheck.go:1025-1029 | net/netcheck/netcheck.go:1244-1248 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060net/netcheck/netcheck.go:1025\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"net/netcheck/netcheck.go"},"region":{"startLine":1025}}}],"partialFingerprints":{"codehealthFindingId/v1":"4203e7960199346485aef2afbb91367de738a8562ef82e675552c161cb24396c"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: ipn/ipnlocal/local.go: ipn/ipnlocal/local.go changed 70 times in last 90 days, max complexity 57. 2 of those changes were fix/bug commits, and the other 68 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, cover the area it touches with tests, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/local.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"991e5d861e38c9787bafaef7b3621c00d53af46324c91ddfe19ed40cd8ea5f7e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: wgengine/userspace.go: wgengine/userspace.go changed 27 times in last 90 days, max complexity 48. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, behind tests written first."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/userspace.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee1a79c99f807138858ff1595147ca33904972e05ae535b93df7375f3948ae7f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: wgengine/magicsock/magicsock.go: wgengine/magicsock/magicsock.go changed 21 times in last 90 days, max complexity 54. 2 of those changes were fix/bug commits, and the other 19 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, cover the area it touches with tests, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/magicsock/magicsock.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d99278a87c58a5934af016b280d372036e3ccab91293ff48e45771f6cc047b30"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: feature/conn25/conn25.go: feature/conn25/conn25.go changed 27 times in last 90 days, max complexity 38. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, behind tests written first."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"feature/conn25/conn25.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8b8f65a98a0aa0e80cbb55e513a2f155e9096833d4f4959ff94a1f2d13f91cf"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: ipn/ipnlocal/node_backend.go: ipn/ipnlocal/node_backend.go changed 26 times in last 90 days, max complexity 34. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, behind tests written first."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnlocal/node_backend.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ad173a4a2ab4910ca74ca29d0929ae8407a3277bddc78d718a60b96b2a1fabe"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: tailcfg/tailcfg.go: tailcfg/tailcfg.go changed 17 times in last 90 days, max complexity 38. 1 of those changes was a fix/bug commit, and the other 16 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, cover the area it touches with tests, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tailcfg/tailcfg.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f60e7d7a2de5e5bfc079b20b9956c07cfa0f7f2efdad264d1d7beb45d5d96c69"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: control/controlclient/map.go: control/controlclient/map.go changed 5 times in last 90 days, max complexity 93. 2 of those changes were fix/bug commits, and the other 3 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, cover the area it touches with tests, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlclient/map.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0f99d9a4a08bf5bf50276478792a9a73bd23bc5b3523421e09f3e15f024cdd5"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: cmd/tailscaled/tailscaled.go: cmd/tailscaled/tailscaled.go changed 10 times in last 90 days, max complexity 42. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, behind tests written first."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscaled/tailscaled.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"95c01b3c612044d1b42664e17759bc6bccb3e5475d55ec7e9e3bc68a91d17cca"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: tstest/integration/testcontrol/testcontrol.go: tstest/integration/testcontrol/testcontrol.go changed 9 times in last 90 days, max complexity 45. 1 of those changes was a fix/bug commit, and the other 8 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, cover the area it touches with tests, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tstest/integration/testcontrol/testcontrol.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2c1de6de615525c99f5aea5e1df985b12ad5b0058f2f3a616d334156efe19c9"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: ipn/ipnstate/ipnstate.go: ipn/ipnstate/ipnstate.go changed 7 times in last 90 days, max complexity 44. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, behind tests written first."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ipn/ipnstate/ipnstate.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f41d4347e6eb5548e8c53d0e0d93317e50f0df50406ddc80caed0d4aa04ea910"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 38 significant file(s) lose their only recent owner: cmd/fbstatus/fbstatus.go, tstest/natlab/vnet/fake_acme.go, cmd/tailscale/cli/configure-flash-appliance.go, control/tsp/map.go, tstest/tailmac/Swift/Host/HostCli.swift, tstest/tailmac/Swift/Host/VMController.swift, tool/listpkgs/listpkgs.go, wgengine/wgengine.go (\u002B30 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7a929864799ebe7c699bcaa8993e69d537a63156e6eac8fbd456fd2341b96a7a"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #2: If anonymized user #2 becomes unavailable, 9 significant file(s) lose their only recent owner: net/routecheck/routecheck.go, net/routecheck/probe.go, feature/routecheck/routertracker.go, log/filelogger/log.go, feature/routecheck/routecheck.go, net/routecheck/report.go, net/traffic/traffic.go, util/qrcodes/qrcodes_linux.go (\u002B1 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a8d0a35a34fe01d3e8861ad6306062f6f1590a20b07504badc966f2ed185fdcb"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #3: If anonymized user #3 becomes unavailable, 6 significant file(s) lose their only recent owner: tsconsensus/tsconsensus.go, cmd/natc/ippool/consensusippool.go, feature/conn25/addrAssignments.go, net/packet/icmp6.go, cmd/natc/ippool/ippool.go, net/packet/icmp.go. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f0e13b18a5f625a782770549ae7c200de549f9b800de0a578e7d4dc88490de8d"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #4: If anonymized user #4 becomes unavailable, 4 significant file(s) lose their only recent owner: tka/sync.go, tailcfg/tka.go, tka/disabled_stub.go, version/cmp.go. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2ea30b0126c3a34c501c4a888bb88397b4a1c78893e3dbb709b977fae595b254"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #5: If anonymized user #5 becomes unavailable, 3 significant file(s) lose their only recent owner: k8s-operator/reconciler/tailnet/tailnet.go, k8s-operator/reconciler/reconciler.go, k8s-operator/apis/v1alpha1/types_tailnet.go. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ac9b5a758c0c05f51b21ce777b9fe3c6a5c2c290625c8d98d5ea49b03820eb22"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #6: If anonymized user #6 becomes unavailable, 3 significant file(s) lose their only recent owner: misc/git_hook/githook/install.go, cmd/tsnet-proxy/tsnet-proxy.go, tstest/natlab/vmtest/qemu_wrapper.go. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0409994a04ee8f3b0ce4b8679fc9fc264e265fb4408a28539d3a0c8c453ee25c"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 16 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (83 single-owned of 798 analysed files in total, counted over production source files of roughly 100 lines or more, excluding tests, vendored, generated and example/demo trees, largest first). They are anonymized user #7 (2 file(s)), anonymized user #8 (2 file(s)), anonymized user #9 (2 file(s)), anonymized user #10 (2 file(s)), anonymized user #11 (1 file(s)), anonymized user #12 (1 file(s)) (\u002B10 more) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D19","level":"note","message":{"text":"The overview mentions that the iOS and Android apps use this repo\u0027s code but also states the mobile GUI code lives elsewhere; the reader cannot tell whether the mobile code is open source from the text alone.: Add a brief sentence confirming the mobile GUI on non-open-source platforms is not open source, so it is clear the repository does not own the GUI."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d00e94f615e325d744ff803d77ec05d437ea9cfa88343a1123c1af9affd1f7f"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59b27f74d38f5c1d727443efb1f6bde4f94da846090300121a2b554adacf1b63"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28d4aa633d270396ca66bbb0844632fab2977e0ee46a75e619e3ac15af7e8082"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cb6e138ea3cf428951f1d9898f366975b580210091e7a6b3bbee96e83e4f387"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba82c2aaa8705b40921c347ba9d7b2148c4b4b3069e1d781c410e7174b82d3b3"},"taxa":[{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e3b09ca22f34db9b1d587f541b684680b60242640c23dca26fd4963a69d8314d"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"941941c943a68484589f3fcaf413758ced83dac6cd4918a2d4381c439bb15a87"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7148b60bd4d5b800c6e57ed29159319c05d4729dfd6d803bddeba389c892191"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f05ecebf80b62db2b6b2ab2494a52523f4cbeed4565c62204e06d365835369b7"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ba5ce034e4cbfafcaf2d2fde4bb009fa8252b096b37c937fdc9e65c3678d42a"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"02fd85d8be0756f67bccf423c312acffc1aa1916fbdb831f60a932c15065d0a0"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c551a81a09fa74084269440aa5fb9c42412e87ed68b30a7a3e00faf5ab791d0f"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75b203c999ee302a7ea96d3c11e92d27ee0c916e3dc0319da2f8aac15c7d5e3d"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5bd9ea74e2d4f6a83221e29e03361a21b800c88dd0b5cfe9f4a09b833af027eb"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c21c3cd304d8a25f12a64b65019b3742a464389fb43d0614d3809b339168ea05"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"33777e657a4b82685571b791738631202a61eb4d2df030e34c8b340960526030"},"taxa":[{"id":"CWE-327","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"44436e6eaf50360fbef70fe3f3a8989df010b2a0175dbb06bca19730e69e6dc3"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"089476fed0b97d6ec6857ff2a94dbdfcc79a6ed38322f8bb20e8fa7b8883e5ca"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f460e0126f02eb979c7275df57caab5ea9881e00f7cdcd727a322322b8ae8173"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2249e4eb0623d415c715d732b432bf8aeb8e4a13e6ca1f9bb1de7201d0968e66"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c24c3581309dd84073de7b7576883e379da9f781b6efcc444d33e336e2769177"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"08ae64fcf0a112ad4691a5d3861584e401f1a63a2e029a19d0c3fc1212858331"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"69cac516efe24d8a25059e03ab1ce2dc3db7066a3829d3da5bcd1cca9721b627"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"caff818dee03e66fcd200f37c42adae4288679f8436cad17caab4b70632dbf99"},"taxa":[{"id":"CWE-400","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e82f0414810443ff16b692f5b86b19a82e22215c9615a213f9a13709ba09f8e"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"150c6648639efe34f9d573debd64f1224f332558079b8c12c60d142f81a34628"},"taxa":[{"id":"CWE-918","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cc6ee8f6aceb511e40c35acd23789ad96e43195272141e55d503b60a2be56a1"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"18a205feefbcc6b86570e6938374bef710dec2b5c0f07472dc19d734c0d5f552"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4c01165de38596b080be2b2f495dfa70e69339c2a556398b2bd743a9f96cb956"},"taxa":[{"id":"CWE-328","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4aca005200281369c1aeda27d991529ec450fe494b7f4e172ef2a4b75c4c0358"},"taxa":[{"id":"CWE-328","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fb358c57c40bf71fcd3978d6c585cac9ea0740ebde72202fbaf722ffe9ed69b9"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf5ba0dfd4bc3e1cdc40ac72b2a800873ab7933348513f52ebf3cccb6be32030"},"taxa":[{"id":"CWE-327","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2ea7fcdf353ed27e2bdfd280a9ca454b69e07a0c070e75cd231d893464c4d05f"},"taxa":[{"id":"CWE-327","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"57db017dab9bea49e3aa313899c34ab8d46b3fbf980eaf68f04ec0321267fef7"},"taxa":[{"id":"CWE-328","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cb87ddc682f1aa7e11fc0838904386a96a981151643bb73ab0cc965ec3ded101"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d054793245234386a0947e4374114b610d29befed0dde04299303fd34dca1a7f"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1e68e0dc67fdf13efb9ca496daf2a6fe38ba0f01e2aac227354be5e5c8703181"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bd1789c0e1046fa9efc5cefd02b6a7a9ef23e5dc782534668fd86926625cb3be"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ddc196b019870eb12249dbf9e6e6e6e78609e3f45cdad0c108b91b359c1e552b"},"taxa":[{"id":"CWE-400","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df96caf711bf4968493d056ad5b0ed31b4406dfd39b68c70987d45ca4e0d7ea7"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a75877d79ecaf0ab7e23b9599ddafc06e6a028e74c491216e4c6974c85df94a0"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"21c44156abb96b13fcf1e8ce23ae051e36d323338c98a6488bf32feaa4e19897"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc09e950a8630db0c8e4bb74dc0670550f1ae0f7a7bcfcbff2abb833502ac4ac"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4a6128dc440b490429c0660e37fd4297aaf77ada8b266578722f6cfd8ea4a154"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a32eedebf69f17ba20564287712216a2637b5b4960b4bc1925a0ced5e878c348"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1079b798d474ee70792d4dc1296ac69a4070b85d0fd0f684a6b04a1aa74a3cc5"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7c70280462aedba1ba65bd888a70676d0d6df5e1d83b3b1b7770c5151a06b5f3"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"36737db47b2e63f1553440014587939c7fee6a1d2b834e6060d9c59384fc0411"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a152d96f80c1d4484fc889b47a894ee9eaf51b1602d6da6228125ed53cba28b2"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7f195a7d6d3340a35ea54e8ad07d629716e4a42a5775633c331e3edbd95d403d"},"taxa":[{"id":"CWE-338","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"88b92d9ee752cff93ea7c5cacbe06a52662727a4888ae2132d8f4aa03d9bcea8"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d8b9bde30750f9151c0cecffa942be3613ed5d5fbebf3ae48d1d772dbe8d6468"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe2d688610b51e0a5a02c7c5dd1724a4986e40f2689fb84510e2ec0164c27d6a"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c584087366cd00dd4a6be8070f2a7c2f758092f6000418ff718a399dd412cc07"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"665d14ed59c94b9e6c64ddb16ce6a907145797f1d4d1d6ca730da3493002321f"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a05b63b3eacfba117ffe2f15697edbf41d39cb1d92b2e89a583133173b3959e3"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75bb90acecdbc0b5f5b23911e5d954bf57e6b4215f624908f2f78e3cb374a3fc"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14d732daebc55e1061cd193b5c54f22849e398963d9fdb2ed12df1de1d50b6f3"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3664de9215a21013c152e4d6f8d1d8c1dea405cd65e79aeb34daa143cd7b49c0"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c80e65bb3b031deb43718d8621a87484fe073a19c4a09f005c00f7fa3e53cef2"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2476bcb00f455d820d09d843c2a7d22e9697f012141d969b2c566e185425ef08"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5aaf4d61186f3b2d41ea4e61c2e11e3f5af747ab4d8f91c2dcc9c5da18d6afb7"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aaeeb77ca8e7d77dbbb82ec9ef49cd79c61fe0f28ed54908d66916282d62398d"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"31999bb4a968fdefe3bbe038faaa74cfee6c3808327a26574013fbf6e54438b9"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5f643b584181c60b69d23768850856ef856173767137a84ca67b232c19d090f2"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a7e08fa85c2c279164f2c18e4b6e88692198f05fe553cc00dc493b19dce9afec"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5acbdd3160dfb9ec372b8720d85d660bfe8fa64e4ba94f575ae7d55d28c1cdb0"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3f2bb2aa885a147cfac35cedb9b4951dc51c7362cdfbafc43bcb7c8e71d3d7b6"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"61d760376bf366934dd6659872fcb6b77c861785b93102357e5b8e9d22b43dac"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8de9cbdebbbb6a1b02fe5583e905d22c51f1234aec0f63b84a65d080c0543801"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0f79b8fe9c1b46addfd36044cd81f25c84fd186dc195e1875c00d0ea03faca4"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab2c01dc7e76b99924cb702ee973936bffef5055d0effe468ff4ffb4292a65b0"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a5421b265ef624408f9d8decd7fe6d9adcb3c158d10da8d3c92b84a8e8342272"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25c6cfa19019105b17cff2ca3076b49c9c8f93bbfab63e0660953e90b0871849"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c575c4dcb3ea4b611df2dc20cbe5423a7a56c8e88104fe18ff6ff7c49f4c58b5"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"98aa9f5d63fbcc51687a8d9b4558083ae5c4a3c3484ff9af7c5e438eb216808f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c81d2412d7b1da65d45e7c45380c2ec699276c04ea547e4d4efa8609c0aff5b"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6af6b865d3fb0b0ea34c120330562dc1e8e559bae75ede854ef1b2a77bdff3a0"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"13a56972db7d0f66c1a71fa5558cad9024cd8673928360b2142708cd899cc11e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1ca32abaaea7a3a3d1c41b6cc52da0f73eb31fe8a78eb00041413313e19ae758"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d7ecde7efc6daf4e0da8b9aff7413d345cfd0f13636197bd35b67d413ef82bcd"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9125dc3202c4357cc6356c55546b41c597e6dbd7565946d9477b3b723793ac9b"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a817f90fd9863e2440e0eb653a939dcd39d0c56aac27271173380c8b24a7e7bc"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a274193da90c7c574cd46bc73847dbcf8d15b660b3d04dd4886ed4210ef7d15e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"506cba9aabf249152aa5e6d50e9ca9467b6b4ede266a16b58f514de89806f1fc"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c64e4a95837f9fa89fd7d08e65cb6b5f4c8cd82a69c7119fac92889137e24092"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"193717128f45463e1baa803f96f795bd0b172b9caad09ea50789e4d04a5cc47d"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4cae45bbcce3eb9934f59b134d2aa07b61a5c82135ebf41b64573a4ece68459f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b67787f58bbdcde79a43cc08af597219f8bc8ccd5a82b8588a8f7af6b62ec402"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f00b30263fce6c4b84e8e20af99791b6b34ae8837f5066e35dbec4e72a35d728"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3471f00761f187a7d970afab3c17000c39d28add1b13a586e212046734128b21"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"011636e56ad9ae4bc622601d0e5919e9588a49fc13ae0860b852bc1ba9854233"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 72 of 798 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 100 lines or more, excluding tests, vendored, generated and example/demo trees, largest first). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 largest first: kube/kubeclient/client.go, control/controlbase/handshake.go, net/dns/nm.go (and 69 more). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: tailnet-lock-log.go \u2194 tailnet-lock-status.go: \u0060cmd/tailscale/tslockjsonv1/tailnet-lock-log.go\u0060 and \u0060cmd/tailscale/tslockjsonv1/tailnet-lock-status.go\u0060 change together 80% of the time (8 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well). They sit in the same directory, and in this ecosystem sibling files there normally share one namespace/package \u2014 so a direct reference between them needs no import and this pass cannot see whether one exists. Read the pair before acting: if one file only DECLARES what the other consumes (a constants/types file beside its user), the co-change is definitional and the question is whether the split earns its keep; if they duplicate structure, extract the common part into a shared function or type they both call; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cmd/tailscale/tslockjsonv1/tailnet-lock-log.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cb314c6e3289336d3dd7086c74cf5c5c0e4bc1323f1dc3cead70c06464b05fd"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: client_js.go \u2194 controlhttpserver.go: \u0060control/controlhttp/client_js.go\u0060 and \u0060control/controlhttp/controlhttpserver/controlhttpserver.go\u0060 change together 54% of the time (7 of the 13 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"control/controlhttp/client_js.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f05599225fbe393d527352447aa3cec158ca67e6aa3c8bce0d5964c9defcfbb"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: match.go \u2194 tailcfg.go: \u0060wgengine/filter/match.go\u0060 and \u0060wgengine/filter/tailcfg.go\u0060 change together 50% of the time (9 of the 18 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well). They sit in the same directory, and in this ecosystem sibling files there normally share one namespace/package \u2014 so a direct reference between them needs no import and this pass cannot see whether one exists. Read the pair before acting: if one file only DECLARES what the other consumes (a constants/types file beside its user), the co-change is definitional and the question is whether the split earns its keep; if they duplicate structure, extract the common part into a shared function or type they both call; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"wgengine/filter/match.go"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ceaf971e8ed809d189bbdf4008efa2957885f333b4bdd7a0eb11ac5669dde6d0"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: device-details-view.tsx \u2194 home-view.tsx: \u0060client/web/src/components/views/device-details-view.tsx\u0060 and \u0060client/web/src/components/views/home-view.tsx\u0060 change together 50% of the time (9 of the 18 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/src/components/views/device-details-view.tsx"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"48942f76fab39223350ed8a3c6bc999e79468e4a88d6aedf3e22c3acca703517"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: app.tsx \u2194 exit-node-selector.tsx: \u0060client/web/src/components/app.tsx\u0060 and \u0060client/web/src/components/exit-node-selector.tsx\u0060 change together 50% of the time (8 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/web/src/components/app.tsx"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"28e5cef807e0f58a822f9fe5e0624177a160cad3c80f73f69c31788b755547de"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4b6b5d2627573c9a1561f1157a2d7fa44a4a439ad87ae1369661568fedaa7b18"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"281191311520ff1621ea49c56fbb2f3a6986f2c601227f6b42e59376c2120c49"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5eb159804a1b35574ed47c2ba61109527afb544003e459b00c0e2fee52648a1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"96d92e03d040954a5b5a03ae1305403daa43c97e26750645236f9aa207a5744d"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03084d5cf4e880012b1d1b14ed6cd85794075bc0d26a8d8c9e07b20f8286a803"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dce0d046cedc41327640d576f8f463b39064af0cfc9e5a337b5ac71ec24dbd2c"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ea7017f416fe6cddc87cbdec46a0de09766a8144e5171279240d1fc3cd391440"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6fe2dc42a2c9f679dc4a2b95ec221870d000584e0ff2ccbe8132a0242799911d"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b9da16d17f6b7a39d0a388efa6344bed17a033e02ce4b855f3561166b8896b0b"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"295de942fbe1c61d416380278a1aade2b2d8a8162856b91a19f0cca9a18ee4a2"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"45767d74c3f94e4709b6c22edea9985c035a02d929e6ef8796b950965e2ade87"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8eef6ff2e93423004c8e226d1ea52bdeb86ab763512312464e5c35a636bae536"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d8e0ec1fef71a3e724dfbc0369a1ab7fd2ea030d16ad885c1a104e758f1eac5f"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c740eb66b2dbfe17073818febab651fd5e79fc6492cdfc332b03c4c1ae768f45"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7d4ae2917d300d407ddabbf5a91f866448ac7fcd945605111da93d8c54e63bba"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e6974b395c1e3204aec49370675538ab1cb2577dc7bdcd8a06bf2a38c9223d2f"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ee1af1572e54bf27628d17216f6360df24734c41be215680727f54544a741733"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd561985491d2a0882c6e741822bf90822e99f688ee69aec53a60fe40e4208d5"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"427a0281cd0106f5ca4d00f35b9447b122f14fec1f9cda058e6f43b6697c91ec"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d447e0b7b5c67461096bcfe89654d1a677a00223eb764cb9f8ac18d9a8804a3e"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"161a4f35f00ba4a8e4564b2439d36598f48af74f91e8747f8d9402977e3df877"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ccb94d4d54455a1e842cecf5f5eefbaf52f1afb82f301da1454442b8f3e08c24"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6df77703aa31a5fe5df7e9d91262cc0ee9800ba05d186e0608be03e02586a55b"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"da476431451562b96f0df5cab5958a1fbdef25faf8c2b5fc5f7b3ede5b44023e"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3496f4c8dafb461b80fbd7e7610ffafac541b8656f349986d5522727dd1dd49"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fbe18008a77dddc292a95106fe49eb61edbd3be97dad049870143dba24821c20"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a5615491030b1c2d797614b7ea635bb9e57f31e8c95cf89d337308fa89f3b2f6"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7b499a25a77088a1fbb2c84d5fe23245ae3be73a1d14f5492c8386a0f5cc0313"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28182f2c124d7ba4cc5656b2cfb83a0bdd65415008f7e8bf750e1a8e0237f716"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50c379534161bb30611d421e82af3666b891a67b9a6a35df5a4fc4b4977e653b"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5cdf8e768e620a1c00298b557799acdadfbaa1dd146ce9c178cc8051c1fe828c"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac7fb10b03b9736b65e6ac72b8ffd498d414f90b2fb7cd37f60b9c5283dffa66"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6e39239cb06d1cc791af34984527f74e17b0fdd15b4bebba4358221d5d195ac5"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f994a541ce1264d63930cbdfb81403451d5102bb46c95154f4f16e9fcb5cdb26"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80f9376fe1189e92e8c28ea433beb36b79a6463e525996d82975cc218e2e056f"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bc121852ac845cffc1a3547e2f2c491679e5be30974158bce96e37dcc6eb5fa7"}},{"ruleId":"D38","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d577478942403abf442642ad1075d152f8b043ca78acb144dd92e335b4e4b8ee"}},{"ruleId":"D40","level":"note","message":{"text":"No network policy: No Kubernetes NetworkPolicy (or Cilium policy) found. Without one, every pod can talk to every other pod and reach out to the internet by default. Add a default-deny policy and open only the flows you need."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"295828650a2aaa1b03ae9b32ae6843a0c38011e5a70b1926442c4fa7187de5f0"}},{"ruleId":"D42","level":"note","message":{"text":"No runtime threat detection: No runtime threat-detection engine (Tetragon TracingPolicy / Falco) is committed. These observe process, file and network activity in-kernel and can alert or kill on malicious behaviour a static scan cannot catch."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"aade9827a37dfc7ee064f80a997f47b5d11e31bc09704e26b9252bef00aa0c58"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-319","guid":"7af97476-9f0d-4458-9163-3d2043918a1a","name":"CWE-319","shortDescription":{"text":"CWE-319"},"helpUri":"https://cwe.mitre.org/data/definitions/319.html"},{"id":"CWE-327","guid":"e51910ff-67b5-3c51-aa3d-92837d9eab90","name":"CWE-327","shortDescription":{"text":"CWE-327"},"helpUri":"https://cwe.mitre.org/data/definitions/327.html"},{"id":"CWE-328","guid":"f0ffc869-97c3-dc5c-8825-be1159f1fc5f","name":"CWE-328","shortDescription":{"text":"CWE-328"},"helpUri":"https://cwe.mitre.org/data/definitions/328.html"},{"id":"CWE-338","guid":"e89b7604-c3f7-8b53-bc8c-4d4718c28617","name":"CWE-338","shortDescription":{"text":"CWE-338"},"helpUri":"https://cwe.mitre.org/data/definitions/338.html"},{"id":"CWE-400","guid":"ca529a89-676d-8857-aac1-84359c77bb6c","name":"CWE-400","shortDescription":{"text":"CWE-400"},"helpUri":"https://cwe.mitre.org/data/definitions/400.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-918","guid":"2e9b9091-5a0f-dc57-b644-7ad04bd56e64","name":"CWE-918","shortDescription":{"text":"CWE-918"},"helpUri":"https://cwe.mitre.org/data/definitions/918.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":133,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}