$ the-wire · showcase
Windows thread stack corruption fix, json v1 field restored in Go 1.27 shim
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
Two Go fixes land on real defects: thread creation on Windows can overrun a goroutine stack, and encoding/json's v1 compatibility shim stopped populating UnsupportedValueError.Value when v1 moved onto v2.
runtime: create Windows threads on the system stack golang/go
newosproc stopped switching to the system stack when the runtime moved from stdcall to createThread, so a LockOSThread call reaching it on a goroutine stack could let native CreateThread overrun the stack and corrupt adjacent memory. createThread now runs on the system stack, retry loop included.
encoding/json: fix UnsupportedValueError.Value regression golang/go
With v1 implemented on top of v2 in Go 1.27, UnsupportedValueError.Value was left unpopulated, and code in the wild reads that field. The compatibility shim populates it again.
types2, go/types: fix data race in Unalias on alias instances golang/go
Alias instances created via types.Instantiate outside package checking get a nil *Checker, so Alias.actual stayed nil and Unalias memoized it without synchronization when callers touched the instance from multiple goroutines. The race is fixed in types2 and go/types.
go/analysis/passes/modernize: avoid invalid SuggestedFixes golang/tools
While editing, malformed struct literals can leave brace positions missing or out of order, and the modernize analyzer's embedlitUnnest could then emit TextEdit ranges past EOF, tripping driverutil.ValidateFixes into filing bug reports. It now validates brace positions and deletion ranges before suggesting a fix.
cmd/influx: upgrade OS packages in Dockerfile golang/build
The influxdb2 base image has not been refreshed since December 2024 and ships outdated Debian 12 packages including openssl (CVE-2025-15467); the image build now runs apt-get upgrade. Also in this batch: archsimd drops its mandatory panic for SVE vector lengths above 32, and gopls adds a release note for generic interface support plus follow-up questions that ask for type arguments.