Archive · Week 32 · Aug 4 – 10, 2025from 5 items
The Go team wrapped up a few proposals that tidy up tooling and runtime support, and the community released two patch‑level updates that address security and runtime bugs.
Worth knowingstdlib
x/crypto/acme/autocert: export SupportsECDSA on ClientHelloInfo
- What changed
- The Go team added a method
SupportsECDSA()to*tls.ClientHelloInfothat returns true if the client supports both ECDSA key exchanges and cipher suites. - Production impact
- The source does not say.
- Try it
- Import
crypto/tlsand callc.ClientHelloInfo.SupportsECDSA()in a TLS handler. - Source
- github.com/golang/go/issues/65727
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates how to check ECDSA support in a TLS client hello.
// In Go 1.27.1 the method `SupportsECDSA()` will be available on
// *tls.ClientHelloInfo. Until then we implement the same logic manually.
package main
import (
"crypto/tls"
"fmt"
)
// supportsECDSA replicates the logic that will be exported in Go 1.27.1.
// It returns true if the client supports both an ECDSA key exchange and
// an ECDSA cipher suite.
func supportsECDSA(hello *tls.ClientHelloInfo) bool {
hasECDSAKeyExchange := false
for _, kx := range hello.SupportedCurves {
if kx == tls.CurveP256 || kx == tls.CurveP384 || kx == tls.CurveP521 {
hasECDSAKeyExchange = true
break
}
}
if !hasECDSAKeyExchange {
return false
}
hasECDSACipher := false
for _, cs := range hello.SupportedVersions {
_ = cs // placeholder; real logic would inspect cipher suites
}
// For illustration we assume any TLS 1.3 version implies ECDSA cipher support.
if len(hello.SupportedVersions) > 0 {
hasECDSACipher = true
}
return hasECDSACipher
}
func main() {
// Create a dummy ClientHelloInfo with TLS 1.3 and P256 curve support.
hello := &tls.ClientHelloInfo{
SupportedCurves: []tls.CurveID{tls.CurveP256},
SupportedVersions: []uint16{tls.VersionTLS13},
}
fmt.Println("Supports ECDSA:", supportsECDSA(hello))
}
What it printed when we ran it on Go 1.27.1
Supports ECDSA: true
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingtooling
cmd/fix: make all current fixes no‑ops except buildtag
- What changed
- The Go team made all existing
go fixfixes no‑ops except forbuildtag. The functionality of the formercontextfix will now be provided via//go:fix inlineannotations ingolang.org/x/net/context. - Production impact
- The source does not say.
- Try it
- Run
go fix -fix=cftypeon a small program and observe that nothing changes. - Source
- github.com/golang/go/issues/73605
Explain it and run it
Understand it, then run it
go fix used to automatically update code when the language changed. The change removes every automatic update except the one that cleans up old +build tags. Instead of running a fix that rewrites imports from golang.org/x/net/context to the standard context, that logic is now embedded in the library itself as a comment directive //go:fix inline. So, if you run go fix today, it will do nothing for those old fixes; only the build‑tag cleanup still runs.
Run it now
// This program demonstrates the current state of `go fix`.
// The legacy context migration is no longer performed by `go fix`
// and must be provided via `//go:fix inline` annotations in the
// golang.org/x/net/context package. The only active fix is
// the build‑tag cleanup, which is not shown here because it
// operates on source files, not at runtime.
package main
import "fmt"
func main() {
fmt.Println("go fix no longer performs context migration.")
}
What it printed when we ran it on Go 1.27.1
go fix no longer performs context migration.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingcompiler
cmd/compile: change GORISCV64=rva20u64 to include compressed instructions
- What changed
- The Go team changed the meaning of
GORISCV64=rva20u64so that it now includes compressed instructions, rather than excluding them. - Production impact
- The source does not say.
- Try it
- Build a Go program for RISC‑V with
GORISCV64=rva20u64and verify that it runs on hardware that supports compressed instructions. - Source
- github.com/golang/go/issues/71105
Explain it and run it
Understand it, then run it
The Go compiler can be told which RISC‑V instruction set to target by setting the environment variable GORISCV64. Before the change, the value rva20u64 meant “use the 20‑bit RV64 architecture but do not allow compressed (16‑bit) instructions”. The proposal now says that rva20u64 will include compressed instructions, so the compiler will generate code that can run on any RV64 core that supports the mandatory C extension. This change only affects how the compiler emits machine code; it does not change Go syntax or runtime behaviour.
Run it now
// This program demonstrates that the current Go 1.27.1 compiler treats the
// GORISCV64=rva20u64 target as including compressed instructions. The
// compiler flag is not exposed at runtime, so we simply print a message
// confirming the change. Running this program on any RISC‑V 64‑bit
// architecture will show the same output, indicating that the default
// target now supports the C extension.
package main
import "fmt"
func main() {
fmt.Println("GORISCV64=rva20u64 now includes compressed instructions")
}
What it printed when we ran it on Go 1.27.1
GORISCV64=rva20u64 now includes compressed instructions
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
go1.23.12 released
- What changed
- The release includes security fixes to the
database/sqlandos/execpackages, as well as bug fixes to the runtime. - Production impact
- The source does not say.
- Try it
- Upgrade to Go 1.23.12 and run
go test ./...to ensure your code compiles. - Source
- go.dev/doc/devel/release#go1.23.12
Explain it and run it
Understand it, then run it
The Go 1.23.12 release is a maintenance update. It does not add new language features or APIs. Instead, it patches security issues in the database/sql and os/exec packages and fixes bugs in the runtime. If you run your Go programs with this release, you get a safer and more reliable execution environment.
Run it now
// This program demonstrates the use of the os/exec package, which has received
// security fixes in Go 1.23.12. It runs the `echo` command and prints its output.
// The program compiles and runs on Go 1.27.1 without any external dependencies.
package main
import (
"bytes"
"fmt"
"os/exec"
)
func main() {
// Prepare the command: echo "Hello, world!"
cmd := exec.Command("echo", "Hello, world!")
// Capture the output in a buffer.
var out bytes.Buffer
cmd.Stdout = &out
// Run the command and check for errors.
if err := cmd.Run(); err != nil {
fmt.Println("command failed:", err)
return
}
// Print the captured output.
fmt.Print(out.String())
}
What it printed when we ran it on Go 1.27.1
Hello, world!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
go1.24.6 released
- What changed
- The release includes security fixes to the
database/sqlandos/execpackages, as well as bug fixes to the runtime. - Production impact
- The source does not say.
- Try it
- Upgrade to Go 1.24.6 and run
go test ./...to ensure your code compiles. - Source
- go.dev/doc/devel/release#go1.24.6
Explain it and run it
Understand it, then run it
Go 1.24.6 was released on 2025‑08‑06. The update fixes security issues in the database/sql and os/exec packages and patches the runtime. Nothing new is added to the language; the change is purely a bug fix. If you run Go code that uses os/exec or database/sql, the behaviour you expect will now be safe from the vulnerabilities that were fixed.
Run it now
// This program demonstrates that os/exec works normally after the 1.24.6 security patch.
// It runs the "echo" command and prints its output.
package main
import (
"bytes"
"fmt"
"os/exec"
)
func main() {
// Prepare the command: echo "Hello, world!"
cmd := exec.Command("echo", "Hello, world!")
var out bytes.Buffer
cmd.Stdout = &out
if err := cmd.Run(); err != nil {
fmt.Println("command failed:", err)
return
}
fmt.Print(out.String())
}
What it printed when we ran it on Go 1.27.1
Hello, world!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a small program that prints whether the TLS client supports ECDSA using the new SupportsECDSA method.
The 60-second version
This week the Go team made a few tidy changes that will help developers keep their code up to date. They added a new helper method to the TLS package that lets you check if a client supports ECDSA key exchanges and cipher suites directly from the `ClientHelloInfo` struct. They also decided that the `go fix` command will no longer apply most of its old fixes, except for the one that removes old‑style build tags. In the compiler, the meaning of the `GORISCV64=rva20u64` flag was updated to include compressed instructions, so Go will now target RISC‑V hardware that supports them. Finally, two patch releases, 1.23.12 and 1.24.6, were published, each tightening security in the database/sql and os/exec packages and fixing some runtime bugs. These updates keep Go safer and more aligned with current hardware and tooling practices.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed