Archive · Week 33 · Aug 11 – 17, 2025from 6 items
The Go team accepted several proposals that extend tooling, cryptography, and the Windows syscall API, and released Go 1.25 with a number of new standard‑library packages and experimental features.
Worth knowingtooling
x/tools/go/analysis/structtag: stricter JSON tag checking
- What changed
- The structtag analyzer now checks for JSON tags that are a single dash (
"-") or containomitemptyand reports them as errors. - Production impact
- The source does not say.
- Try it
- Run
go vet ./...on a project that has a struct field tagged withjson:"-"to see the new error. - Source
- github.com/golang/go/issues/74376
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the new structtag analyzer behavior.
// It defines a struct with a JSON tag that is a single dash ("-").
// When run with `go vet`, the analyzer will report an error for this tag.
// The program itself compiles and runs fine; the error is only in static analysis.
package main
import (
"encoding/json"
"fmt"
)
type Example struct {
Secret string `json:"-"`
}
func main() {
e := Example{Secret: "hidden"}
b, _ := json.Marshal(e)
fmt.Println(string(b)) // prints {}
}
What it printed when we ran it on Go 1.27.1
{}
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
x/crypto/x509roots/fallback: export certificate bundle
- What changed
- A new
golang.org/x/crypto/x509roots/fallback/bundlepackage was added that exposes the NSS trust store root certificates as a read‑only sequence ofRootvalues. - Production impact
- The source does not say.
- Try it
- Import the package and iterate over
bundle.Roots()to list the DER‑encoded certificates. - Source
- github.com/golang/go/issues/69898
Explain it
Understand it, then run it
The Go standard library can verify TLS certificates, but it needs a list of trusted root certificates. On Linux the list comes from the NSS trust store, and Go ships a copy of that list inside the x/crypto/x509roots package. Before this change that list was only used internally; you could not access it from your own code. Now a new golang.org/x/crypto/x509roots/fallback/bundle package exposes the bundle as a read‑only sequence of Root values, so you can read the DER bytes of each root certificate.
Worth knowingecosystem
x/crypto/ssh: add SSHSIG support
- What changed
- The proposal to support encoding and decoding the SSHSIG signature format was accepted and is now in the active proposal column.
- Production impact
- The source does not say.
- Try it
- Read the proposal and experiment with the suggested
CreateBlob,Encode, andDecodefunctions in a local fork ofx/crypto/ssh. - Source
- github.com/golang/go/issues/68197
Worth knowingecosystem
syscall: add Open O_* flags for Windows FILE_FLAG_* flags
- What changed
- New constants such as
O_FILE_FLAG_OPEN_NO_RECALLwere added togolang.org/x/sys/windows, andsyscall.Openon Windows now accepts them and rejects unknown bits. - Production impact
- The source does not say.
- Try it
- On Windows, call
syscall.OpenwithO_FILE_FLAG_OPEN_NO_RECALLand observe that the flag is passed to the OS. - Source
- github.com/golang/go/issues/73676
Explain it
Understand it, then run it
On Windows, the syscall.Open function can now accept a set of flags that match the native FILE_FLAG_* options. These flags let you control how a file is opened, for example whether the file is opened for overlapped (asynchronous) I/O or whether the file should be deleted when the last handle is closed. The change adds constants such as O_FILE_FLAG_OPEN_NO_RECALL to the golang.org/x/sys/windows package, and syscall.Open will pass those flags straight to the operating system. If you try to pass a flag that the runtime does not understand, syscall.Open will return an error instead of silently ignoring the bit.
Worth knowingecosystem
go1.25.0 released
- What changed
- Go 1.25 was released, bringing container‑aware GOMAXPROCS, the
testing/synctestpackage, experimental GC, experimentalencoding/json/v2, and more. - Production impact
- The source does not say.
- Try it
- Run
go versionto confirm you are on 1.25 and explore the new packages in the standard library. - Source
- go.dev/doc/devel/release#go1.25.0
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the current GOMAXPROCS value.
// The new container‑aware behavior is not yet available in Go 1.27.1,
// so we simply print the value returned by runtime.GOMAXPROCS(0).
package main
import (
"fmt"
"runtime"
)
func main() {
// runtime.GOMAXPROCS(0) returns the current maximum number of CPUs
// that can execute simultaneously. In a container this is the
// container's CPU quota if the feature is enabled.
max := runtime.GOMAXPROCS(0)
fmt.Printf("GOMAXPROCS: %d\n", max)
}
What it printed when we ran it on Go 1.27.1
GOMAXPROCS: 2
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Exercise – Detect unsafe JSON tags
Write a small program that inspects the struct tags of a type and reports any field that has a JSON tag that is a single dash ("-") or contains the word omitempty. The program should print the field name and the offending tag.
package main
import (
"fmt"
"reflect"
)
type Person struct {
Name string `json:"name"`
Age int `json:"-"`
Secret string `json:"secret,omitempty"`
Email string `json:"email"`
Password string
}
func main() {
// TODO: Inspect the Person type and print any unsafe JSON tags
}
Show a solution
package main
import (
"fmt"
"reflect"
"strings"
)
type Person struct {
Name string `json:"name"`
Age int `json:"-"`
Secret string `json:"secret,omitempty"`
Email string `json:"email"`
Password string
}
func main() {
t := reflect.TypeOf(Person{})
for i := 0; i < t.NumField(); i++ {
f := t.Field(i)
tag := f.Tag.Get("json")
if tag == "" {
continue
}
// Split on comma to ignore options after the name
parts := strings.Split(tag, ",")
name := parts[0]
if name == "-" || strings.Contains(tag, "omitempty") {
fmt.Printf("Field %s has unsafe JSON tag: %q\n", f.Name, tag)
}
}
}
What it printed when we ran it on Go 1.27.1
Field Age has unsafe JSON tag: "-" Field Secret has unsafe JSON tag: "secret,omitempty"
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
This week the Go team added several new tools and libraries to help developers write safer and more reliable code. They tightened the static analysis of JSON struct tags, making it easier to catch accidental omissions or misconfigurations. A new package now lets you programmatically access the NSS trust store’s root certificates, giving you more control over TLS verification. The SSH package is expanding to support the SSHSIG signature format, and the Windows syscall package now accepts a richer set of file‑opening flags, improving interoperability with native APIs. Finally, Go 1.25 was released, bringing container‑aware scheduling, a new synctest package for testing concurrent code, experimental garbage collection, and a preview of a new JSON encoder. These changes are all available in the current release, and developers can start experimenting with them today.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed