go/src
Russ Cox a76511f3a4 syscall: fix ForkLock spurious close(0) on pipe failure
Pipe (and therefore forkLockPipe) does not make any guarantees
about the state of p after a failed Pipe(p). Avoid that assumption
and the too-clever goto, so that we don't accidentally Close a real fd
if the failed pipe leaves p[0] or p[1] set >= 0.

Fixes #50057
Fixes CVE-2021-44717

Change-Id: Iff8e19a6efbba0c73cc8b13ecfae381c87600bb4
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1291270
Reviewed-by: Ian Lance Taylor <iant@google.com>
Reviewed-on: https://go-review.googlesource.com/c/go/+/370576
Run-TryBot: Filippo Valsorda <filippo@golang.org>
Trust: Russ Cox <rsc@golang.org>
Reviewed-by: Alex Rakoczy <alex@golang.org>
2021-12-09 13:36:16 +00:00
..
archive archive/zip: don't read data descriptor early 2021-11-07 04:56:11 +00:00
bufio bufio: mention that panic at slicing means underlying reader is broken 2021-11-26 22:36:21 +00:00
builtin builtin: document "any" and "comparable" 2021-12-03 01:09:21 +00:00
bytes
cmd cmd/api: run half as many go list calls in parallel 2021-12-08 21:24:34 +00:00
compress
constraints cmd/compile/internal/types2: use "implements" rather than "satisfies" in error messages 2021-11-15 21:22:19 +00:00
container
context
crypto crypto/x509: fix comments on certDirectories 2021-12-02 22:53:18 +00:00
database/sql database/sql: prevent closes slices from assigning to free conn 2021-11-11 19:46:03 +00:00
debug debug/buildinfo: update test for CL 369977 2021-12-08 15:30:52 +00:00
embed go/build: skip rune literals when looking for go:embed 2021-11-11 20:25:49 +00:00
encoding encoding/xml: add generic encoding test 2021-11-09 21:26:25 +00:00
errors
expvar
flag
fmt
go go/types: sort to reduce computational complexity of initOrder 2021-12-08 17:24:46 +00:00
hash
html
image
index/suffixarray
internal internal/fuzz: handle unrecoverable errors during minimization 2021-12-07 21:15:51 +00:00
io io: add error check to TeeReader Example 2021-11-11 19:34:23 +00:00
log log/syslog: create unix sockets in unique directories 2021-12-06 22:35:32 +00:00
math math/bits: add examples for Add, Sub, Mul and Div 2021-11-11 21:27:05 +00:00
mime mime: keep parsing after trailing semicolon 2021-11-09 22:58:24 +00:00
net net/smtp: skip TestTLSSClient on all freebsd platforms 2021-12-08 15:34:19 +00:00
os os: test that LookupEnv reports all keys found in Environ 2021-12-03 14:28:11 +00:00
path
plugin
reflect reflect: keep pointer in aggregate-typed args live in Call 2021-11-12 14:56:58 +00:00
regexp
runtime runtime/pprof: increase systemstack calls in TestLabelSystemstack 2021-12-08 23:00:01 +00:00
sort sort: improve sort documentation 2021-11-16 23:13:41 +00:00
strconv
strings
sync sync: in TryLock try to acquire mutex even if state is not 0 2021-11-16 05:58:03 +00:00
syscall syscall: fix ForkLock spurious close(0) on pipe failure 2021-12-09 13:36:16 +00:00
testdata
testing testing: simplify fuzzResult.String to avoid unnecessarily using fmt.Sprintf 2021-11-27 23:25:39 +00:00
text
time lib/time, time/tzdata: update to 2021e 2021-11-11 05:16:39 +00:00
unicode
unsafe
vendor all: update vendored golang.org/x/sys 2021-12-06 14:32:58 +00:00
Make.dist
README.vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod all: update vendored golang.org/x/sys 2021-12-06 14:32:58 +00:00
go.sum all: update vendored golang.org/x/sys 2021-12-06 14:32:58 +00:00
make.bash build: for default bootstrap, use Go 1.17 if present, falling back to Go 1.4 2021-12-08 16:50:04 +00:00
make.bat build: for default bootstrap, use Go 1.17 if present, falling back to Go 1.4 2021-12-08 16:50:04 +00:00
make.rc build: for default bootstrap, use Go 1.17 if present, falling back to Go 1.4 2021-12-08 16:50:04 +00:00
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.