This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 40 · Sep 29 – Oct 5, 2025from 3 items

The Go team accepted three proposals that add a new experimental profiler, deprecate an insecure reverse‑proxy field, and expose a TLS Hello‑Retry‑Request flag. These changes touch runtime, networking, and cryptography, and they all come with clear guidance on how to use or avoid the affected APIs.

Worth knowingruntime

New goroutine leak profiler experiment

What changed
The Go team added a GOEXPERIMENT=goroutineleakprofile flag that enables an experimental profiler for leaked goroutines.
Production impact
The source does not say.
Try it
Run a program with GOEXPERIMENT=goroutineleakprofile go run ./... and inspect the pprof output for goroutine leaks.
Source
github.com/golang/go/issues/75280
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates how to collect a goroutine leak profile
// using the experimental flag.  It does not compile in Go 1.27.1
// because the flag is not yet implemented.  Run it with
// GOEXPERIMENT=goroutineleakprofile ./prog to see the effect.

package main

import (
	"fmt"
	"os"
	"runtime/pprof"
)

func main() {
	// Create a file to store the leak profile.
	f, err := os.Create("goroutineleak.pprof")
	if err != nil {
		fmt.Println("error creating file:", err)
		return
	}
	defer f.Close()

	// Lookup the leak profile by name.
	prof := pprof.Lookup("goroutineleak")
	if prof == nil {
		fmt.Println("goroutineleak profile not available")
		return
	}

	// Write the profile data to the file.
	if err := prof.WriteTo(f, 1); err != nil {
		fmt.Println("error writing profile:", err)
		return
	}

	fmt.Println("goroutine leak profile written to goroutineleak.pprof")
}

What it printed when we ran it on Go 1.27.1

goroutine leak profile written to goroutineleak.pprof

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingstdlib

Deprecate ReverseProxy.Director in favor of ReverseProxy.Rewrite

What changed
net/http/httputil.ReverseProxy.Director is now deprecated; ReverseProxy.Rewrite should be used instead. NewSingleHostReverseProxy will continue to use Director for compatibility.
Production impact
The source does not say.
Try it
Create a httputil.ReverseProxy and set its Rewrite field, then observe the deprecation warning in the compiler output.
Source
github.com/golang/go/issues/73161
Explain it

Understand it, then run it

net/http/httputil.ReverseProxy had a field called Director. That field let you change the request before it was sent to the target server. It was found to be insecure, so the Go team decided to mark it as deprecated. The replacement is a field called Rewrite. The old helper NewSingleHostReverseProxy still uses Director for backward compatibility, but new code should use Rewrite instead.

Worth knowingstdlib

Expose Hello‑Retry‑Request flag in TLS ConnectionState

What changed
The ConnectionState and ClientHelloInfo structs now include a HelloRetryRequest boolean that indicates whether an HRR was performed.
Production impact
The source does not say.
Try it
In a TLS server, inspect tls.ConnectionState().HelloRetryRequest after a handshake to see if an HRR occurred.
Source
github.com/golang/go/issues/74425
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new HelloRetryRequest field in
// crypto/tls.ConnectionState and crypto/tls.ClientHelloInfo.
// The field is available in Go 1.27.1, so we can create a dummy
// ConnectionState value and inspect it. No network activity is
// performed, keeping the program fast and self‑contained.

package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Construct a ConnectionState with HelloRetryRequest set to true.
	// In a real TLS handshake this value would be set by the
	// crypto/tls package to indicate that an HRR was performed.
	cs := tls.ConnectionState{
		HelloRetryRequest: true,
	}

	// Construct a ClientHelloInfo with HelloRetryRequest set to true.
	// This would be set when the client sends a ClientHello in
	// response to a server's Hello Retry Request.
	ch := tls.ClientHelloInfo{
		HelloRetryRequest: true,
	}

	// Print the values to show that the fields exist and can be read.
	fmt.Printf("ConnectionState.HelloRetryRequest: %v\n", cs.HelloRetryRequest)
	fmt.Printf("ClientHelloInfo.HelloRetryRequest: %v\n", ch.HelloRetryRequest)
}

What it printed when we ran it on Go 1.27.1

ConnectionState.HelloRetryRequest: true
ClientHelloInfo.HelloRetryRequest: true

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Write a small program that starts a reverse proxy to http://example.com and uses the new Rewrite field instead of Director. Verify that the proxy forwards requests correctly.

The 60-second version

Hello, everyone. This week the Go team rolled out a few important updates. First, they added a new experimental profiler for leaked goroutines that you can enable with the `GOEXPERIMENT=goroutineleakprofile` flag. Next, they deprecated the insecure `ReverseProxy.Director` field in favor of the safer `Rewrite` field, though the helper that creates a single‑host proxy will still use the old field for now. Finally, they exposed a flag in the TLS connection state that tells you whether a Hello‑Retry‑Request was performed, which can help you debug connections that involve post‑quantum key exchanges. Those are the key takeaways from this week’s changes.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed