Radar · Go · Archive · Week 17 · Apr 21 – 27, 2025
cmd/vet: flag using %s:%d to construct network addresses
Worth knowingtooling
- What changed
- The vet tool now warns when a format string like
"%s:%d"is used with arguments whose names containport,addr,host,listenorbind. - Production impact
- The source does not say.
- Try it
- Run
go vet ./...on a project that usesfmt.Sprintf("%s:%d", host, port)and observe the warning. - Source
- github.com/golang/go/issues/28308
Understand it, then run it
Run it now
// This program demonstrates the new vet warning. It uses fmt.Sprintf
// with a %s:%d format string and arguments named host and port,
// which the updated vet tool will flag when run with `go vet`.
package main
import (
"fmt"
)
func main() {
host := "localhost"
port := 8080
// The following line will trigger the vet warning in Go 1.27.1.
addr := fmt.Sprintf("%s:%d", host, port)
fmt.Println("Address:", addr)
}
What it printed when we ran it on Go 1.27.1
Address: localhost:8080
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed