Radar · Go · Archive · Week 30 · Jul 21 – 27, 2025
os: stop manually setting sticky bit on file creation on *BSD, Solaris
Worth knowingstdlib
- What changed
- The Go runtime will no longer attempt to set the sticky bit after file or directory creation on *BSD and Solaris. If the OS does not support this natively, an error will be returned; if it does, the bit will be passed directly. The
GODEBUG=insecurestickybits=1flag restores the previous behavior. - Production impact
- The source does not say.
- Try it
- Run a Go program that creates a file with
os.OpenFileusingos.ModeStickyon a *BSD or Solaris system and observe the error or the flag‑controlled behavior. - Source
- github.com/golang/go/issues/68664
Understand it, then run it
When you create a file or directory in Go, the operating system sometimes sets a special flag called the sticky bit. On *BSD and Solaris systems, the Go runtime used to work around a bug by setting this flag manually after the file was created. That workaround could cause race conditions. The change removes that manual step. Now, if you ask for the sticky bit and the OS supports it, the flag is passed straight through; if the OS does not support it, an error is returned. You can still get the old behavior by setting GODEBUG=insecurestickybits=1.
Run it now
// This program demonstrates the new sticky‑bit handling on *BSD and Solaris.
// It attempts to create a file with the sticky bit set. On systems that
// support the sticky bit, the file is created successfully. On systems
// that do not, an error is returned. The GODEBUG flag can be set to
// restore the old behavior, but it is not used here.
package main
import (
"fmt"
"os"
)
func main() {
// Attempt to create a file with the sticky bit.
f, err := os.OpenFile("sticky_test.txt", os.O_CREATE|os.O_RDWR, os.FileMode(0o644|os.ModeSticky))
if err != nil {
fmt.Printf("Error creating file with sticky bit: %v\n", err)
return
}
defer f.Close()
fmt.Println("File created successfully with sticky bit set (if supported).")
}
What it printed when we ran it on Go 1.27.1
File created successfully with sticky bit set (if supported).
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed