127 wires and counting

$ follow Go

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-25
stories 23

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Playground locks down user input, Go SIMD loads stop reading past the slice

By RepoJournal · Filed · About Go · Composed from the cited sources · methodology

The Go playground closed a path where a crafted txtar file could write to the host's filesystem or read its environment, while the experimental simd package fixed a masked-load bug that could fault on real hardware and gopls shipped import handling for MoveDeclaration.

all: use os.Root for handling user input golang/playground

by Neal Patel

The playground's /compile endpoint took arbitrary txtar input, and a malicious archive could escape the execution context and force writes to the host's trusted filesystem; separately, one of the three code paths that invokes go vet on the host did not correctly lock down its environment, letting a Go process read environment data. The commit routes user input handling through os.Root to close ...

simd/archsimd: don't read past the end of the slice in Load*Part golang/go

by Steve Muir

A previous change that dropped LoadMasked* made the Part loads read the whole vector and then mask, which walks past the end of any slice shorter than the vector and faults if the slice ends just before an inaccessible page. The masked loads return as unexported intrinsics, load*ArrayMasked, and the Part loads use them again.

spec: string(x) for integers requires x to be of (underlying) type byte or rune golang/go

by Robert Griesemer

Go 1.28 will require that string(x) for an integer x has a byte or rune underlying type, matching vet behavior that has been in place for a long time; the spec prose and examples are updated. Code converting an untyped or named integer beyond that set will be rejected.

gopls/internal/golang: MoveDeclaration - add/remove imports golang/tools

by Madeline Kalil

MoveDeclaration now adds the needed imports to the destination file and removes imports the source file no longer uses, with findImportEdits taking multiple ranges so it can add or delete import specs across an extracted range. Imports in other files holding moving declarations are left alone.

runtime,cmd/compile,cmd/link: use loader-provided TLS on Windows golang/go

by qmuntal

The runtime stops calling TlsAlloc for g's TLS slot and lets the Windows loader provide it, teaching the internal linker to emit the PE TLS directory and the external linker a .tls$ contribution. The old fallback to ArbitraryUserPointer, a field the host process may already own, goes away once 64 assembly-addressable slots are exhausted.

data/reports: review GO-2026-6452 golang/vulndb

by Ian Alexander

The long tail: gopls moved to MCP Go SDK v1.8.0 for the 2026-07-28 spec revision, go/ssa stopped materializing Selection.Type for non-generic methods to cut GC churn on large programs, typesinternal gained RecvBase in place of ReceiverNamed, and GO-2026-6452 was reviewed in the vulndb.

Quick answers

What shipped in Go on September 25, 2026?
The Go playground closed a path where a crafted txtar file could write to the host's filesystem or read its environment, while the experimental simd package fixed a masked-load bug that could fault on real hardware and gopls shipped import handling for MoveDeclaration. In total, 23 commits landed.
Who contributed to Go on September 25, 2026?
13 developers shipped this update, including Neal Patel, Nicholas S. Husin, Madeline Kalil, Hana Kim, hw, Alan Donovan, Steve Muir, and davidteather, and 5 more.
What were the notable Go updates?
all: use os.Root for handling user input, simd/archsimd: don't read past the end of the slice in Load*Part, and spec: string(x) for integers requires x to be of (underlying) type byte or rune.