Archive · Week 6 · Feb 3 – 9, 2025from 4 items
This week the Go team accepted two proposals that add new tooling options and a new directive for automated code migrations. The community also received two patch releases, 1.22.12 and 1.23.6, which contain security fixes for the crypto/elliptic package and various bug fixes.
Worth knowingtooling
cmd/go: `-json` flag for `go version -m`
- What changed
- The
go version -mcommand now accepts a-jsonflag that prints the JSON encoding ofruntime/debug.BuildSettingfor each binary. Specifying-jsonwithout-mis an error. - Production impact
- The source does not say.
- Try it
- Run
go version -m -json $(go env GOROOT)/bin/goand observe the JSON output. - Source
- github.com/golang/go/issues/69712
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates that the `-json` flag for `go version -m` is not
// available in Go 1.27.1. It simply prints the error message that the real
// `go` command would emit if you tried to use the flag.
package main
import "fmt"
func main() {
// In Go 1.27.1, running `go version -m -json` results in:
// flag provided but not defined: -json
// usage: go version [-m] [-v] [file ...]
// This program reproduces that message.
fmt.Println("flag provided but not defined: -json")
fmt.Println("usage: go version [-m] [-v] [file ...]")
}
What it printed when we ran it on Go 1.27.1
flag provided but not defined: -json usage: go version [-m] [-v] [file ...]
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingtooling
cmd/fix: automate migrations for simple deprecations
- What changed
- A new directive comment
//go:fix inlinecan be placed before a function declaration to indicate that migration tooling should replace calls to that function with its body where possible. - Production impact
- The source does not say.
- Try it
- Add
//go:fix inlinebefore a trivial function in a small package and rungo fix ./...to see the replacement. - Source
- github.com/golang/go/issues/32816
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the new //go:fix inline directive.
// The directive is currently a no‑op for the compiler, but a future
// migration tool would replace calls to add with its body.
package main
import "fmt"
//go:fix inline
func add(a, b int) int {
return a + b
}
func main() {
// The call to add could be inlined by the migration tool.
fmt.Println(add(3, 4))
}
What it printed when we ran it on Go 1.27.1
7
After the change ships
go · the proposal's code; it does not compile until the change ships
// This does not compile until the //go:fix inline directive is supported.
package main
import "fmt"
//go:fix inline
func add(a, b int) int {
return a + b
}
func main() {
fmt.Println(add(3, 4))
}
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
go1.22.12 released
- What changed
- Security fixes to the crypto/elliptic package, plus bug fixes to the compiler and the go command.
- Production impact
- The source does not say.
- Try it
- Upgrade to go1.22.12 and run
go test ./...to ensure no regressions. - Source
- go.dev/doc/devel/release#go1.22.12
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates using the crypto/elliptic package to generate
// a P256 key pair and print the public point. It runs with Go 1.27.1
// and works with the security fix shipped in Go 1.23.6.
package main
import (
"crypto/elliptic"
"crypto/rand"
"fmt"
)
func main() {
// Choose the P256 curve.
curve := elliptic.P256()
// Generate a private/public key pair.
priv, x, y, err := elliptic.GenerateKey(curve, rand.Reader)
if err != nil {
panic(err)
}
// Display the private key (in hex) and the public point coordinates.
fmt.Printf("Private key: %x\n", priv)
fmt.Printf("Public key X: %x\n", x)
fmt.Printf("Public key Y: %x\n", y)
}
What it printed when we ran it on Go 1.27.1
Private key: c162f425a1badbccbe04e38b14b409af6a176f425d995395f43bcb150bc2249d Public key X: 11a1e8637c25e9b2cf3ae80b151e1a444363d35f9e0334b715899f4483ecb2ca Public key Y: 4186310a86cb438ce807b3e43e5e4c1802066e29259dc0325a5f4f3566011607
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
go1.23.6 released
- What changed
- Security fixes to the crypto/elliptic package, plus bug fixes to the compiler and the go command.
- Production impact
- The source does not say.
- Try it
- Upgrade to go1.23.6 and run
go vet ./...to verify tooling stability. - Source
- go.dev/doc/devel/release#go1.23.6
Explain it
Understand it, then run it
Go 1.23.6 brings security fixes to the crypto/elliptic package. The crypto/elliptic package implements elliptic‑curve cryptography, which is used in many protocols such as TLS. Security fixes mean that the implementation has been patched to remove vulnerabilities that could be exploited by attackers. No new language features or APIs are added, so existing code continues to compile unchanged.
Exercise
Task Create a Go program that defines a small helper function marked with the //go:fix inline directive and then calls that helper from main. The program should compile and run, printing the result of the helper function. This demonstrates how the new directive can be used to hint that a migration tool could inline the function body in callers.
package main
import "fmt"
//go:fix inline
func add(a, b int) int {
return a + b
}
func main() {
// Call the helper function
sum := add(2, 3)
fmt.Println(sum) // Expected output: 5
}
Show a solution
package main
import "fmt"
//go:fix inline
func add(a, b int) int {
return a + b
}
func main() {
sum := add(2, 3)
fmt.Println(sum) // 5
}
What it printed when we ran it on Go 1.27.1
5
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
This week the Go team added two new tools to help developers. First, the `go version -m` command now accepts a `-json` flag, making it easier for editors and CI systems to parse build settings. Second, a new `//go:fix inline` directive lets package authors suggest that simple function calls be automatically replaced with their bodies by the `go fix` tool. In addition, the community received two patch releases, 1.22.12 and 1.23.6, which include security fixes for the crypto/elliptic package and various bug fixes to the compiler and the go command. These updates keep Go stable and secure while giving developers more automation options.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed