This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 25 · Jun 15 – 21, 2026from 2 items

This week the Go team accepted two proposals that refine how the runtime and tooling interact with the operating system and version control. The changes focus on sandboxing child processes on Linux and on tightening the semantics of the `vcs.modified` flag reported by the `go` command.

Worth knowingruntime

syscall: support process sandboxing using Landlock on Linux

What changed
The syscall.SysProcAttr struct on Linux now includes fields to enable Landlock restrictions (UseLandlock, LandlockFD, LandlockFlags) and a NoNewPrivs flag that calls prctl(PR_SET_NO_NEW_PRIVS) before exec.
Production impact
The source does not say.
Try it
Compile a small program that sets SysProcAttr{UseLandlock:true, NoNewPrivs:true} on a child process and observe that it fails to acquire new privileges.
Source
github.com/golang/go/issues/68595
Explain it and run it

Understand it, then run it

The syscall.SysProcAttr struct on Linux now has three new fields that let you put a child process into a Landlock sandbox. UseLandlock tells the runtime to call landlock_restrict_self before the child execs. LandlockFD is the file descriptor of a Landlock ruleset that you create elsewhere. LandlockFlags are flags passed to the restriction call. There is also a NoNewPrivs field that makes the child run with prctl(PR_SET_NO_NEW_PRIVS) so it cannot gain new privileges.

Run it now

Todaygo
// This program demonstrates how to run a subprocess on Linux without the
// Landlock fields that are not yet available in Go 1.27.1. It simply
// executes the `echo` command and prints its output. The fields
// `UseLandlock`, `LandlockFD`, `LandlockFlags`, and `NoNewPrivs` are
// omitted because they are not part of the current syscall.SysProcAttr
// definition.
package main

import (
	"fmt"
	"os/exec"
)

func main() {
	// Create a command that prints "Hello, world!".
	cmd := exec.Command("echo", "Hello, world!")

	// Run the command and capture its combined standard output and error.
	out, err := cmd.CombinedOutput()
	if err != nil {
		fmt.Printf("command failed: %v\n", err)
		return
	}

	// Print the output of the command.
	fmt.Printf("Command output: %s", out)
}

What it printed when we ran it on Go 1.27.1

Command output: Hello, world!

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingtooling

cmd/go: only set vcs.modified=true if changes are relevant to build

What changed
The go command now sets vcs.modified=true only when the modifications affect files used by the current build or by the same build in a clean repository.
Production impact
The source does not say.
Try it
Run go build in a repository, add an unrelated file, then run go install and check the binary’s build info for the vcs.modified flag.
Source
github.com/golang/go/issues/77897
Explain it

Understand it, then run it

The go command used to mark a repository as “modified” whenever any file changed, even if that file had nothing to do with the code you were building. When you built a program, the binary’s build info would show vcs.modified=true and the module path would get a +dirty suffix, even if the change was just an unrelated log file or a temporary profile. The change now limits that flag. It is set only when the modified files are ones that the current build actually uses, or when a file that the build uses in a clean repository has been removed. This means the +dirty suffix now better reflects whether the binary differs from the source you built.

Exercise

Create a Go program that launches a child process with Landlock restrictions enabled and verifies that the child cannot open a file that is not allowed by the Landlock ruleset.

The 60-second version

Hello, I’m here to share a couple of updates from the Go team this week. First, they’ve extended the `syscall.SysProcAttr` structure on Linux to let you place child processes into a Landlock sandbox. This means you can now specify a Landlock ruleset file descriptor and flags, and the runtime will call `landlock_restrict_self` before the child execs. It also adds a `NoNewPrivs` flag that invokes `prctl(PR_SET_NO_NEW_PRIVS)` to prevent the child from gaining new privileges. Second, the `go` command has been refined to set the `vcs.modified` flag only when the changes actually affect files that are part of the current build. This should make the “+dirty” suffix on binaries more meaningful, especially when you have stray files in your repository that don’t influence the build. Those are the key takeaways from this week’s proposals.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed