Archive · Week 10 · Mar 3 – 9, 2025from 6 items
The Go team delivered a handful of proposals and two patch‑level releases. The proposals touch the tooling, XML parsing, and the crypto API, while the releases focus on security and bug fixes in the standard library and compiler.
Worth knowingtooling
x/tools: tag and delete refactor/rename, refactor/importgraph, go/buildutil, cmd/gomvpkg
- What changed
- The Go team has decided to tag and delete the packages
x/tools/refactor/rename,x/tools/refactor/importgraph,x/tools/go/buildutil, andx/tools/cmd/gomvpkg. They will continue to work as they do now, but will no longer receive updates. - Production impact
- The source does not say.
- Try it
- Run
go list -m allto see that these modules still resolve, but note that future updates will not be available. - Source
- github.com/golang/go/issues/69538
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates that the packages
// golang.org/x/tools/refactor/rename,
// golang.org/x/tools/refactor/importgraph,
// golang.org/x/tools/go/buildutil,
// and golang.org/x/tools/cmd/gomvpkg
// are still importable but will no longer receive updates.
// In this sandbox we cannot fetch external modules, so the imports would fail.
// In a real environment, the following imports would compile and the program would run.
package main
import (
"fmt"
// _ "golang.org/x/tools/refactor/rename"
// _ "golang.org/x/tools/refactor/importgraph"
// _ "golang.org/x/tools/go/buildutil"
// _ "golang.org/x/tools/cmd/gomvpkg"
)
func main() {
fmt.Println("The x/tools refactor and build utilities are still available but are now frozen.")
}
What it printed when we ran it on Go 1.27.1
The x/tools refactor and build utilities are still available but are now frozen.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
encoding/xml: add flag for stricter XML char parsing
- What changed
- The
xml.Decodertype now has aCheckfield and theStrictfield is redefined.Strictdefaults to true and is equivalent to settingCheck.EndTagandCheck.Entitiesto true. The newChecksstruct allows finer control over end‑tag and entity validation. - Production impact
- The source does not say.
- Try it
- Create an
xml.DecoderwithStrict: falseand parse an XML document that contains an unmatched end tag to observe how the parser invents tags. - Source
- github.com/golang/go/issues/69503
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the current behavior of xml.Decoder in Go 1.27.1.
// The Decoder has a Strict field but no Check field. Setting Strict to false
// allows the parser to invent missing end tags and ignore malformed entities.
package main
import (
"encoding/xml"
"fmt"
"strings"
)
func main() {
// XML with a missing end tag and an unknown entity.
data := `<root><child>Some &unknown; text</child><empty></root>`
// Create a decoder that does not enforce strict validation.
dec := xml.NewDecoder(strings.NewReader(data))
dec.Strict = false
for {
tok, err := dec.Token()
if err != nil {
break
}
switch v := tok.(type) {
case xml.StartElement:
fmt.Printf("Start: %s\n", v.Name.Local)
case xml.EndElement:
fmt.Printf("End: %s\n", v.Name.Local)
case xml.CharData:
fmt.Printf("Char: %s\n", strings.TrimSpace(string(v)))
}
}
}
What it printed when we ran it on Go 1.27.1
Start: root Start: child Char: Some &unknown; text End: child Start: empty End: empty End: root
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
crypto: single‑shot signing interface
- What changed
- A new
MessageSignerinterface was added tocrypto. It extendsSignerand introducesSignMessage. The helperSignMessagefunction attempts an interface upgrade toMessageSignerbefore falling back toSigner.Sign. - Production impact
- The source does not say.
- Try it
- Use
crypto.SignMessagewith a key that implementsMessageSigner(e.g., an ECDSA key) to sign a message in one call. - Source
- github.com/golang/go/issues/63405
Worth knowingstdlib
go1.23.7 released
- What changed
- Security fixes to the
net/httppackage and bug fixes tocgo, the compiler, and thereflect,runtime, andsyscallpackages. - Production impact
- The source does not say.
- Try it
- Upgrade to go1.23.7 and run
go test ./...to ensure no regressions in your HTTP‑based services. - Source
- go.dev/doc/devel/release#go1.23.7
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates that the net/http package is usable in Go 1.27.1.
// It performs a simple GET request and prints the result. The request
// will fail in the sandbox because network access is disabled, but the
// code compiles and runs without panicking, showing that the security
// fixes in go1.23.7 do not alter the public API or basic behaviour.
package main
import (
"fmt"
"net/http"
)
func main() {
resp, err := http.Get("http://example.com")
if err != nil {
fmt.Println("request error:", err)
return
}
defer resp.Body.Close()
fmt.Println("status code:", resp.StatusCode)
}
What it printed when we ran it on Go 1.27.1
request error: Get "http://example.com": dial tcp: lookup example.com on 192.168.178.1:53: dial udp 192.168.178.1:53: connect: network is unreachable
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
go1.24.1 released
- What changed
- Security fixes to the
net/httppackage and bug fixes tocgo, the compiler, thegocommand, and thereflect,runtime, andsyscallpackages. - Production impact
- The source does not say.
- Try it
- Upgrade to go1.24.1 and run
go vet ./...to verify that the new compiler fixes do not introduce new warnings. - Source
- go.dev/doc/devel/release#go1.24.1
Explain it
Understand it, then run it
Go 1.24.1 was released on 2025‑03‑04. It contains security fixes for the net/http package and bug fixes for cgo, the compiler, the go command, and the reflect, runtime, and syscall packages. The change does not add new language features or APIs; it simply improves the safety and reliability of existing code. If you run Go programs that use net/http, the behavior should be the same, but with fewer security issues.
Nice to knowruntime
From unique to cleanups and weak: new low‑level tools for efficiency
- What changed
- The blog announces the introduction of weak pointers and improved finalization in Go 1.24.
- Production impact
- The source does not say.
- Try it
- Read the blog to understand how weak pointers can reduce memory pressure in long‑running services.
- Source
- go.dev/blog/cleanups-and-weak
Explain it
Understand it, then run it
Go 1.24 adds two new low‑level tools that let you clean up resources more reliably and keep references to objects without stopping them from being garbage‑collected. The first is runtime.AddCleanup, which lets you attach a function to an object that runs when that object is no longer reachable. The second is weak.Pointer, a pointer type that the garbage collector ignores when deciding reachability. Together, they let you build caches that automatically drop entries when nothing else refers to them, and they avoid the pitfalls of the older runtime.SetFinalizer approach.
Exercise
Write a small program that parses an XML string with an unmatched end tag using the new xml.Decoder flags.
The 60-second version
Good morning, everyone. This week the Go team made a few important decisions. First, they decided to tag and delete several tooling packages—`x/tools/refactor/rename`, `x/tools/refactor/importgraph`, `x/tools/go/buildutil`, and `x/tools/cmd/gomvpkg`. These packages will keep working, but they won’t receive updates any longer. Second, the XML package now offers a new `Check` field on the decoder, giving developers finer control over how strictly the parser validates end tags and entities. Third, the crypto package introduced a new `MessageSigner` interface that lets you sign a message in a single call, which will be useful for libraries that need to hide the hashing step. On the release side, Go 1.23.7 and Go 1.24.1 both landed with security fixes to the HTTP package and various bug fixes across the runtime, compiler, and standard library. Those updates are worth applying to keep your services secure and stable. That’s all for this week’s Radar.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed