$ the-wire · showcase
Playground locks down user input, Go SIMD loads stop reading past the slice
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
The Go playground closed a path where a crafted txtar file could write to the host's filesystem or read its environment, while the experimental simd package fixed a masked-load bug that could fault on real hardware and gopls shipped import handling for MoveDeclaration.
all: use os.Root for handling user input golang/playground
The playground's /compile endpoint took arbitrary txtar input, and a malicious archive could escape the execution context and force writes to the host's trusted filesystem; separately, one of the three code paths that invokes go vet on the host did not correctly lock down its environment, letting a Go process read environment data. The commit routes user input handling through os.Root to close ...
simd/archsimd: don't read past the end of the slice in Load*Part golang/go
A previous change that dropped LoadMasked* made the Part loads read the whole vector and then mask, which walks past the end of any slice shorter than the vector and faults if the slice ends just before an inaccessible page. The masked loads return as unexported intrinsics, load*ArrayMasked, and the Part loads use them again.
spec: string(x) for integers requires x to be of (underlying) type byte or rune golang/go
Go 1.28 will require that string(x) for an integer x has a byte or rune underlying type, matching vet behavior that has been in place for a long time; the spec prose and examples are updated. Code converting an untyped or named integer beyond that set will be rejected.
gopls/internal/golang: MoveDeclaration - add/remove imports golang/tools
MoveDeclaration now adds the needed imports to the destination file and removes imports the source file no longer uses, with findImportEdits taking multiple ranges so it can add or delete import specs across an extracted range. Imports in other files holding moving declarations are left alone.
runtime,cmd/compile,cmd/link: use loader-provided TLS on Windows golang/go
The runtime stops calling TlsAlloc for g's TLS slot and lets the Windows loader provide it, teaching the internal linker to emit the PE TLS directory and the external linker a .tls$ contribution. The old fallback to ArbitraryUserPointer, a field the host process may already own, goes away once 64 assembly-addressable slots are exhausted.
data/reports: review GO-2026-6452 golang/vulndb
The long tail: gopls moved to MCP Go SDK v1.8.0 for the 2026-07-28 spec revision, go/ssa stopped materializing Selection.Type for non-generic methods to cut GC churn on large programs, typesinternal gained RecvBase in place of ReceiverNamed, and GO-2026-6452 was reviewed in the vulndb.