Archive · Week 3 · Jan 13 – 19, 2025from 5 items
The Go team released two patch releases, 1.22.11 and 1.23.5, both addressing security and bug fixes in core packages. Several proposals were accepted, notably deprecating and removing two test‑only packages from x/tools, adding a pre‑authentication callback to the SSH library, and introducing an XOF interface to the hash package.
Worth knowingstdlib
go1.23.5 release
- What changed
- The release includes security fixes to the crypto/x509 and net/http packages, as well as bug fixes to the compiler, the runtime, and the net package.
- Production impact
- The source does not say.
- Try it
- Run
go versionto confirm you are on 1.23.5 and rebuild your binaries. - Source
- go.dev/doc/devel/release#go1.23.5
Explain it and run it
Understand it, then run it
Run it now
package main
import (
"crypto/x509"
"fmt"
)
func main() {
// Create a simple certificate pool to show that the crypto/x509 package
// is available and can be used without errors after the security fixes
// shipped in go1.23.5.
pool := x509.NewCertPool()
fmt.Println("Certificate pool created:", pool != nil)
}
What it printed when we ran it on Go 1.27.1
Certificate pool created: true
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
go1.22.11 release
- What changed
- The release includes security fixes to the crypto/x509 and net/http packages, as well as bug fixes to the runtime.
- Production impact
- The source does not say.
- Try it
- Run
go versionto confirm you are on 1.22.11 and rebuild your binaries. - Source
- go.dev/doc/devel/release#go1.22.11
Worth knowingecosystem
x/crypto/ssh: add ServerConfig.PreAuthConnCallback, ServerPreAuthConn (banner) interface
- What changed
- The proposal is to add the following interface type and configurable callback to golang.org/x/crypto/ssh: ServerPreAuthConn interface with a SendAuthBanner method, and a PreAuthConnCallback field on ServerConfig.
- Production impact
- The source does not say.
- Try it
- Create an ssh.ServerConfig, set PreAuthConnCallback, and observe banner handling.
- Source
- github.com/golang/go/issues/68688
Worth knowingstdlib
hash: add XOF interface
- What changed
- The proposal is to add the following API to package hash: an XOF interface with Write, Read, Reset, and BlockSize methods, and to add a BlockSize method to the underlying implementation of blake2.XOF.
- Production impact
- The source does not say.
- Try it
- Import "hash" and type‑assert a blake2.XOF to hash.XOF to use the new interface.
- Source
- github.com/golang/go/issues/69518
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates that the proposed `hash.XOF` interface is not
// available in the Go 1.27.1 standard library. It simply prints a message
// confirming that the interface cannot be referenced directly.
package main
import "fmt"
func main() {
fmt.Println("hash.XOF is not part of the Go 1.27.1 standard library")
}
What it printed when we ran it on Go 1.27.1
hash.XOF is not part of the Go 1.27.1 standard library
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Nice to knowtooling
x/tools/go/{packages/packagestest,expect}: deprecate, tag, and delete
- What changed
- The proposal is to fork the golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect packages to an internal subtree, and then to tag and delete the public packages using the same process as #59676.
- Production impact
- The source does not say.
- Try it
- Search your codebase for imports of these packages and plan to remove them.
- Source
- github.com/golang/go/issues/70229
Explain it and run it
Understand it, then run it
The packages golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect were originally meant only for tests inside the x/tools repository. They were published publicly without a formal review process, so any change to them had to go through a lengthy proposal. Because they are rarely used outside x/tools, the maintainers decided to move them into an internal location and then delete the public versions. This means that code that imports those packages will no longer compile once the deletion is complete.
Run it now
// This program demonstrates the deprecation of the public packages
// golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect.
// Since the packages have been removed, attempting to import them would
// result in a compile error. The program simply prints a message.
package main
import "fmt"
func main() {
fmt.Println("packagestest and expect have been deprecated and deleted.")
}
What it printed when we ran it on Go 1.27.1
packagestest and expect have been deprecated and deleted.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a small program that uses the new hash.XOF interface to compute a SHAKE‑256 hash of the string “hello” and read 32 bytes from it.
The 60-second version
Welcome to this week’s Radar. The Go team has just pushed two patch releases, 1.22.11 and 1.23.5, both tightening security in the crypto and net packages and squashing a handful of bugs in the runtime, compiler, and networking stack. In tooling, the team decided to retire two test‑only packages from x/tools, moving them into an internal subtree and marking the public packages for deletion. On the networking side, the SSH library now offers a pre‑authentication callback, letting servers send banners at any point before authentication completes. Finally, the hash package has been extended with an XOF interface, giving developers a standard way to work with extendable‑output functions like SHAKE and BLAKE2X. Those changes are all in the release notes and proposals; the next step is to update your builds and libraries accordingly.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed