Archive · Week 20 · May 12 – 18, 2025from 4 items
The Go team accepted four proposals that touch the compiler, standard library, and crypto packages. No new releases or bug advisories were published this week.
Breakingstdlib
crypto/tls: disable SHA-1 signature algorithms in TLS 1.2
- What changed
- Support for the SHA‑1 signature algorithms
rsa_pkcs1_sha1andecdsa_sha1is removed from TLS 1.2. AGODEBUG=tlssha1=1flag can restore the old behavior. - Production impact
- Any service that relies on TLS 1.2 with SHA‑1 signatures will fail to negotiate a connection unless the flag is set.
- Try it
- Run a TLS client with
GODEBUG=tlssha1=1and observe that SHA‑1 signatures are accepted again. - Source
- github.com/golang/go/issues/72883
Explain it
Understand it, then run it
TLS 1.2 still allowed certificates signed with the old SHA‑1 hash. The change removes that support. Now a TLS 1.2 connection will refuse to use a certificate that was signed with SHA‑1. If a server still uses such a certificate, clients will fail to connect unless the special GODEBUG=tlssha1=1 flag is set to re‑enable the old behaviour.
Worth knowingstdlib
go/ast: add PreorderStack, a wrapper around ast.Inspect that maintains a stack
- What changed
- A new helper
PreorderStacktraverses an AST and supplies a correctly maintained stack of ancestor nodes to the callback. - Production impact
- The source does not say.
- Try it
- Use
ast.PreorderStackto walk a parsed file and print each node’s depth. - Source
- github.com/golang/go/issues/73319
Nice to knowstdlib
crypto/ecdsa: add NewPublicKey and PublicKey.Bytes
- What changed
- The
ecdsapackage now supports parsing and encoding uncompressed public keys viaParseUncompressedPublicKeyandPublicKey.Bytes. - Production impact
- The source does not say.
- Try it
- Parse a known uncompressed key with
ParseUncompressedPublicKeyand then round‑trip it withPublicKey.Bytes. - Source
- github.com/golang/go/issues/63963
Exercise
Task Use the new ast.PreorderStack helper to walk a Go source file and print each node’s type together with the depth of its ancestor stack. Replace the manual stack logic in the starter with a call to ast.PreorderStack.
package main
import (
"fmt"
"go/ast"
"go/parser"
"go/token"
)
func main() {
src := `package main
func foo() {
bar()
}`
fset := token.NewFileSet()
file, _ := parser.ParseFile(fset, "example.go", src, 0)
// Manual stack traversal (incorrect if a node returns false).
var stack []ast.Node
ast.Inspect(file, func(n ast.Node) bool {
if n != nil {
stack = append(stack, n) // push
} else {
stack = stack[:len(stack)-1] // pop
}
if n != nil {
fmt.Printf("Node: %T, depth: %d\n", n, len(stack))
}
return true
})
}
Show a solution
package main
import (
"fmt"
"go/ast"
"go/parser"
"go/token"
)
func main() {
src := `package main
func foo() {
bar()
}`
fset := token.NewFileSet()
file, _ := parser.ParseFile(fset, "example.go", src, 0)
// Correct stack traversal using PreorderStack.
ast.PreorderStack(file, nil, func(n ast.Node, stack []ast.Node) bool {
if n != nil {
fmt.Printf("Node: %T, depth: %d\n", n, len(stack))
}
return true
})
}
What it printed when we ran it on Go 1.27.1
Node: *ast.File, depth: 0 Node: *ast.Ident, depth: 1 Node: *ast.FuncDecl, depth: 1 Node: *ast.Ident, depth: 2 Node: *ast.FuncType, depth: 2 Node: *ast.FieldList, depth: 3 Node: *ast.BlockStmt, depth: 2 Node: *ast.ExprStmt, depth: 3 Node: *ast.CallExpr, depth: 4 Node: *ast.Ident, depth: 5
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
Hello, I’m here to give you a quick rundown of what the Go team delivered this week. First, the token package now has a new method that lets you add files to a FileSet in any order, which can simplify long‑running tools that process many Go source files. Next, the AST package added a helper that walks a syntax tree while keeping a correct stack of ancestor nodes; this fixes a subtle bug that could misalign the stack when you skip subtrees. In the crypto world, the TLS package has removed support for SHA‑1 signature algorithms in TLS 1.2, following the latest RFC, and you can still opt back in with a debug flag if you need to. Finally, the ecdsa package now supports parsing and emitting uncompressed public keys, giving you a more complete set of key handling utilities. Those are the highlights for this week.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed