Radar · Go · Archive · Week 31 · Jul 28 – Aug 3, 2025
x/sys/windows: allow specifying Security Capabilities in SysProcAttr
Worth knowingstdlib
- What changed
- The
syscallpackage on Windows now has aSecurityCapabilitiesstruct and aSecurityCapabilitiesfield inSysProcAttr.syscall.StartProcesswill include this attribute in the WindowsCreateProcesscall. - Production impact
- The source does not say.
- Try it
- Create a
syscall.SysProcAttrwith a non‑nilSecurityCapabilitiesand pass it tosyscall.StartProcess. - Source
- github.com/golang/go/issues/65611
Understand it, then run it
The Go runtime on Windows can now attach a set of security capabilities to a new process. Before, the only security data you could pass was the classic SecurityAttributes that control ownership and inheritance. The new SecurityCapabilities type lets you specify an AppContainer SID and a list of capabilities that the process is allowed to use. When you start a process with syscall.StartProcess, the runtime will include these capabilities in the underlying Windows CreateProcess call.
Run it now
// This program demonstrates that the new SecurityCapabilities field in
// syscall.SysProcAttr is not available in Go 1.27.1. It simply prints a
// message indicating the missing feature.
package main
import (
"fmt"
)
func main() {
fmt.Println("SecurityCapabilities is not yet exposed in syscall.SysProcAttr on Go 1.27.1.")
}
What it printed when we ran it on Go 1.27.1
SecurityCapabilities is not yet exposed in syscall.SysProcAttr on Go 1.27.1.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed