Archive · Week 25 · Jun 15 – 21, 2026from 2 items
This week the Go team accepted two proposals that refine how the runtime and tooling interact with the operating system and version control. The changes focus on sandboxing child processes on Linux and on tightening the semantics of the `vcs.modified` flag reported by the `go` command.
Worth knowingruntime
syscall: support process sandboxing using Landlock on Linux
- What changed
- The
syscall.SysProcAttrstruct on Linux now includes fields to enable Landlock restrictions (UseLandlock,LandlockFD,LandlockFlags) and aNoNewPrivsflag that callsprctl(PR_SET_NO_NEW_PRIVS)before exec. - Production impact
- The source does not say.
- Try it
- Compile a small program that sets
SysProcAttr{UseLandlock:true, NoNewPrivs:true}on a child process and observe that it fails to acquire new privileges. - Source
- github.com/golang/go/issues/68595
Explain it and run it
Understand it, then run it
The syscall.SysProcAttr struct on Linux now has three new fields that let you put a child process into a Landlock sandbox. UseLandlock tells the runtime to call landlock_restrict_self before the child execs. LandlockFD is the file descriptor of a Landlock ruleset that you create elsewhere. LandlockFlags are flags passed to the restriction call. There is also a NoNewPrivs field that makes the child run with prctl(PR_SET_NO_NEW_PRIVS) so it cannot gain new privileges.
Run it now
// This program demonstrates how to run a subprocess on Linux without the
// Landlock fields that are not yet available in Go 1.27.1. It simply
// executes the `echo` command and prints its output. The fields
// `UseLandlock`, `LandlockFD`, `LandlockFlags`, and `NoNewPrivs` are
// omitted because they are not part of the current syscall.SysProcAttr
// definition.
package main
import (
"fmt"
"os/exec"
)
func main() {
// Create a command that prints "Hello, world!".
cmd := exec.Command("echo", "Hello, world!")
// Run the command and capture its combined standard output and error.
out, err := cmd.CombinedOutput()
if err != nil {
fmt.Printf("command failed: %v\n", err)
return
}
// Print the output of the command.
fmt.Printf("Command output: %s", out)
}
What it printed when we ran it on Go 1.27.1
Command output: Hello, world!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingtooling
cmd/go: only set vcs.modified=true if changes are relevant to build
- What changed
- The
gocommand now setsvcs.modified=trueonly when the modifications affect files used by the current build or by the same build in a clean repository. - Production impact
- The source does not say.
- Try it
- Run
go buildin a repository, add an unrelated file, then rungo installand check the binary’s build info for thevcs.modifiedflag. - Source
- github.com/golang/go/issues/77897
Explain it
Understand it, then run it
The go command used to mark a repository as “modified” whenever any file changed, even if that file had nothing to do with the code you were building. When you built a program, the binary’s build info would show vcs.modified=true and the module path would get a +dirty suffix, even if the change was just an unrelated log file or a temporary profile. The change now limits that flag. It is set only when the modified files are ones that the current build actually uses, or when a file that the build uses in a clean repository has been removed. This means the +dirty suffix now better reflects whether the binary differs from the source you built.
Exercise
Create a Go program that launches a child process with Landlock restrictions enabled and verifies that the child cannot open a file that is not allowed by the Landlock ruleset.
The 60-second version
Hello, I’m here to share a couple of updates from the Go team this week. First, they’ve extended the `syscall.SysProcAttr` structure on Linux to let you place child processes into a Landlock sandbox. This means you can now specify a Landlock ruleset file descriptor and flags, and the runtime will call `landlock_restrict_self` before the child execs. It also adds a `NoNewPrivs` flag that invokes `prctl(PR_SET_NO_NEW_PRIVS)` to prevent the child from gaining new privileges. Second, the `go` command has been refined to set the `vcs.modified` flag only when the changes actually affect files that are part of the current build. This should make the “+dirty” suffix on binaries more meaningful, especially when you have stray files in your repository that don’t influence the build. Those are the key takeaways from this week’s proposals.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed