This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 30 · Jul 21 – 27, 2025

os: stop manually setting sticky bit on file creation on *BSD, Solaris

Worth knowingstdlib

What changed
The Go runtime will no longer attempt to set the sticky bit after file or directory creation on *BSD and Solaris. If the OS does not support this natively, an error will be returned; if it does, the bit will be passed directly. The GODEBUG=insecurestickybits=1 flag restores the previous behavior.
Production impact
The source does not say.
Try it
Run a Go program that creates a file with os.OpenFile using os.ModeSticky on a *BSD or Solaris system and observe the error or the flag‑controlled behavior.
Source
github.com/golang/go/issues/68664

Understand it, then run it

When you create a file or directory in Go, the operating system sometimes sets a special flag called the sticky bit. On *BSD and Solaris systems, the Go runtime used to work around a bug by setting this flag manually after the file was created. That workaround could cause race conditions. The change removes that manual step. Now, if you ask for the sticky bit and the OS supports it, the flag is passed straight through; if the OS does not support it, an error is returned. You can still get the old behavior by setting GODEBUG=insecurestickybits=1.

Run it now

Todaygo
// This program demonstrates the new sticky‑bit handling on *BSD and Solaris.
// It attempts to create a file with the sticky bit set. On systems that
// support the sticky bit, the file is created successfully. On systems
// that do not, an error is returned. The GODEBUG flag can be set to
// restore the old behavior, but it is not used here.

package main

import (
	"fmt"
	"os"
)

func main() {
	// Attempt to create a file with the sticky bit.
	f, err := os.OpenFile("sticky_test.txt", os.O_CREATE|os.O_RDWR, os.FileMode(0o644|os.ModeSticky))
	if err != nil {
		fmt.Printf("Error creating file with sticky bit: %v\n", err)
		return
	}
	defer f.Close()
	fmt.Println("File created successfully with sticky bit set (if supported).")
}

What it printed when we ran it on Go 1.27.1

File created successfully with sticky bit set (if supported).

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed