$ the-wire · showcase
Go 1.28's string(int) ban gets migration tooling; x509 macOS crash fixed
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
Tooling to migrate code ahead of Go 1.28's rejection of string(x) conversions landed in both the stringintconv analyzer and gopls, while a macOS verifier crash on invalid UTF-8 hostnames got a fix in crypto/x509.
crypto/x509: fix crash on invalid UTF-8 DNSName in macOS verifier golang/go
CFStringCreateWithBytes fails on non-UTF-8 input, and the macOS verifier passed that failure straight to CFRelease, crashing the process; SecPolicyCreateSSL now returns an error instead, and invalid UTF-8 names are rejected at the start of systemVerify with a HostnameError. The alternative of handing Security.framework a NULL hostname was rejected because it silently disables hostname checking.
go/analysis/passes/stringintconv: make first fix behavior-preserving golang/tools
Go 1.28 rejects string(x) for non-byte, non-rune integers (go.dev/issue/3939), so the analyzer's first suggested fix was rewritten to preserve existing behavior and the pass joined the go fix suite, letting modules migrate before their go directive is raised to go1.28. The previous string(rune(x)) fix was not behavior-preserving for types wider than 32 bits.
gopls/internal/golang: quick fixes for go1.28 string(int) error golang/tools
gopls now offers quick fixes directly on the Go 1.28 type error, since the stringintconv analyzer does not run on ill-typed packages: string(rune(x)) or fmt.Sprintf("%c", x) to keep existing behavior, or fmt.Sprintf("%d", x) to format the number as decimal.
log/slog: restore handler state when dropping an empty group golang/go
Dropping an empty group (say, after ReplaceAttr removed every attribute) backed the buffer up past the group name without undoing the rest of openGroup, so JSONHandler wrote following attributes with no separator and produced invalid JSON, while TextHandler prefixed keys with the dropped group's name. The handler state is now restored when the group is closed.
go/analysis/passes/modernize: stringscut - preserve non-ASCII IndexByte golang/tools
Rewriting strings.IndexByte(s, c) to Cut or Contains converted the byte with string(c), which yields the UTF-8 encoding of the code point, so a byte >= 0x80 became a two-byte string: IndexByte(s, 0xff) was rewritten to Contains(s, "\xc3\xbf") instead of "\xff". Non-ASCII IndexByte arguments are now preserved.
testing/internal/testdeps: skip repeated entries in the test log golang/go
cmd/go hashes each test log entry from its op, name and current directory, so a loop that repeats a Getenv, Open or Stat adds nothing to a test's inputs yet was processed and stored in the build cache twice; testdeps now maps the entries written since the last chdir and skips repeats. The sys and log/slog desks also closed lower-level items: fcntl data on darwin is passed as unsafe.Pointer in F...