if haspointers(t.Type) {
                                escassign(e, &e.theSink, src)
                        }
+               } else { // indirect and OCALLFUNC = could be captured variables, too. (#14409)
+                       ll = e.nodeEscState(n).Escretval
+                       for ; ll != nil; ll = ll.Next {
+                               escassignDereference(e, ll.N, fn)
+                       }
                }
                return
        }
 
 
 var asmstdcallAddr unsafe.Pointer
 
+func windowsFindfunc(name []byte, lib uintptr) stdFunction {
+       f := stdcall2(_GetProcAddress, lib, uintptr(unsafe.Pointer(&name[0])))
+       return stdFunction(unsafe.Pointer(f))
+}
+
 func loadOptionalSyscalls() {
-       var buf [50]byte // large enough for longest string
-       strtoptr := func(s string) uintptr {
-               buf[copy(buf[:], s)] = 0 // nil-terminated for OS
-               return uintptr(noescape(unsafe.Pointer(&buf[0])))
-       }
-       l := stdcall1(_LoadLibraryA, strtoptr("kernel32.dll"))
-       findfunc := func(name string) stdFunction {
-               f := stdcall2(_GetProcAddress, l, strtoptr(name))
-               return stdFunction(unsafe.Pointer(f))
-       }
-       if l != 0 {
-               _AddDllDirectory = findfunc("AddDllDirectory")
-               _AddVectoredContinueHandler = findfunc("AddVectoredContinueHandler")
-               _GetQueuedCompletionStatusEx = findfunc("GetQueuedCompletionStatusEx")
-               _LoadLibraryExW = findfunc("LoadLibraryExW")
+       var (
+               kernel32dll                 = []byte("kernel32.dll\000")
+               addVectoredContinueHandler  = []byte("AddVectoredContinueHandler\000")
+               getQueuedCompletionStatusEx = []byte("GetQueuedCompletionStatusEx\000")
+               addDllDirectory             = []byte("AddDllDirectory\000")
+               loadLibraryExW              = []byte("LoadLibraryExW\000")
+       )
+
+       k32 := stdcall1(_LoadLibraryA, uintptr(unsafe.Pointer(&kernel32dll[0])))
+       if k32 == 0 {
+               throw("kernel32.dll not found")
        }
+       _AddDllDirectory = windowsFindfunc(addDllDirectory, k32)
+       _AddVectoredContinueHandler = windowsFindfunc(addVectoredContinueHandler, k32)
+       _GetQueuedCompletionStatusEx = windowsFindfunc(getQueuedCompletionStatusEx, k32)
+       _LoadLibraryExW = windowsFindfunc(loadLibraryExW, k32)
 }
 
 //go:nosplit
 
                // BAD: p should not escape here
        }(&p) // ERROR "&p escapes to heap" "\(func literal\)\(&p\) escapes to heap"
 }
+
+func ClosureLeak1(s string) string { // ERROR "ClosureLeak1 s does not escape"
+       t := s + "YYYY"         // ERROR "escapes to heap"
+       return ClosureLeak1a(t) // ERROR "ClosureLeak1 ... argument does not escape"
+}
+
+// See #14409 -- returning part of captured var leaks it.
+func ClosureLeak1a(a ...string) string { // ERROR "leaking param: a to result ~r1 level=1"
+       return func() string { // ERROR "ClosureLeak1a func literal does not escape"
+               return a[0]
+       }()
+}
+
+func ClosureLeak2(s string) string { // ERROR "ClosureLeak2 s does not escape"
+       t := s + "YYYY"       // ERROR "escapes to heap"
+       c := ClosureLeak2a(t) // ERROR "ClosureLeak2 ... argument does not escape"
+       return c
+}
+func ClosureLeak2a(a ...string) string { // ERROR "leaking param: a to result ~r1 level=1"
+       return ClosureLeak2b(func() string { // ERROR "ClosureLeak2a func literal does not escape"
+               return a[0]
+       })
+}
+func ClosureLeak2b(f func() string) string { // ERROR "leaking param: f to result ~r1 level=1"
+       return f()
+}