Archive · Week 40 · Sep 29 – Oct 5, 2025from 3 items
The Go team accepted three proposals that add a new experimental profiler, deprecate an insecure reverse‑proxy field, and expose a TLS Hello‑Retry‑Request flag. These changes touch runtime, networking, and cryptography, and they all come with clear guidance on how to use or avoid the affected APIs.
Worth knowingruntime
New goroutine leak profiler experiment
- What changed
- The Go team added a
GOEXPERIMENT=goroutineleakprofileflag that enables an experimental profiler for leaked goroutines. - Production impact
- The source does not say.
- Try it
- Run a program with
GOEXPERIMENT=goroutineleakprofile go run ./...and inspect the pprof output for goroutine leaks. - Source
- github.com/golang/go/issues/75280
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates how to collect a goroutine leak profile
// using the experimental flag. It does not compile in Go 1.27.1
// because the flag is not yet implemented. Run it with
// GOEXPERIMENT=goroutineleakprofile ./prog to see the effect.
package main
import (
"fmt"
"os"
"runtime/pprof"
)
func main() {
// Create a file to store the leak profile.
f, err := os.Create("goroutineleak.pprof")
if err != nil {
fmt.Println("error creating file:", err)
return
}
defer f.Close()
// Lookup the leak profile by name.
prof := pprof.Lookup("goroutineleak")
if prof == nil {
fmt.Println("goroutineleak profile not available")
return
}
// Write the profile data to the file.
if err := prof.WriteTo(f, 1); err != nil {
fmt.Println("error writing profile:", err)
return
}
fmt.Println("goroutine leak profile written to goroutineleak.pprof")
}
What it printed when we ran it on Go 1.27.1
goroutine leak profile written to goroutineleak.pprof
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
Deprecate ReverseProxy.Director in favor of ReverseProxy.Rewrite
- What changed
net/http/httputil.ReverseProxy.Directoris now deprecated;ReverseProxy.Rewriteshould be used instead.NewSingleHostReverseProxywill continue to useDirectorfor compatibility.- Production impact
- The source does not say.
- Try it
- Create a
httputil.ReverseProxyand set itsRewritefield, then observe the deprecation warning in the compiler output. - Source
- github.com/golang/go/issues/73161
Explain it
Understand it, then run it
net/http/httputil.ReverseProxy had a field called Director. That field let you change the request before it was sent to the target server. It was found to be insecure, so the Go team decided to mark it as deprecated. The replacement is a field called Rewrite. The old helper NewSingleHostReverseProxy still uses Director for backward compatibility, but new code should use Rewrite instead.
Worth knowingstdlib
Expose Hello‑Retry‑Request flag in TLS ConnectionState
- What changed
- The
ConnectionStateandClientHelloInfostructs now include aHelloRetryRequestboolean that indicates whether an HRR was performed. - Production impact
- The source does not say.
- Try it
- In a TLS server, inspect
tls.ConnectionState().HelloRetryRequestafter a handshake to see if an HRR occurred. - Source
- github.com/golang/go/issues/74425
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the new HelloRetryRequest field in
// crypto/tls.ConnectionState and crypto/tls.ClientHelloInfo.
// The field is available in Go 1.27.1, so we can create a dummy
// ConnectionState value and inspect it. No network activity is
// performed, keeping the program fast and self‑contained.
package main
import (
"crypto/tls"
"fmt"
)
func main() {
// Construct a ConnectionState with HelloRetryRequest set to true.
// In a real TLS handshake this value would be set by the
// crypto/tls package to indicate that an HRR was performed.
cs := tls.ConnectionState{
HelloRetryRequest: true,
}
// Construct a ClientHelloInfo with HelloRetryRequest set to true.
// This would be set when the client sends a ClientHello in
// response to a server's Hello Retry Request.
ch := tls.ClientHelloInfo{
HelloRetryRequest: true,
}
// Print the values to show that the fields exist and can be read.
fmt.Printf("ConnectionState.HelloRetryRequest: %v\n", cs.HelloRetryRequest)
fmt.Printf("ClientHelloInfo.HelloRetryRequest: %v\n", ch.HelloRetryRequest)
}
What it printed when we ran it on Go 1.27.1
ConnectionState.HelloRetryRequest: true ClientHelloInfo.HelloRetryRequest: true
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a small program that starts a reverse proxy to http://example.com and uses the new Rewrite field instead of Director. Verify that the proxy forwards requests correctly.
The 60-second version
Hello, everyone. This week the Go team rolled out a few important updates. First, they added a new experimental profiler for leaked goroutines that you can enable with the `GOEXPERIMENT=goroutineleakprofile` flag. Next, they deprecated the insecure `ReverseProxy.Director` field in favor of the safer `Rewrite` field, though the helper that creates a single‑host proxy will still use the old field for now. Finally, they exposed a flag in the TLS connection state that tells you whether a Hello‑Retry‑Request was performed, which can help you debug connections that involve post‑quantum key exchanges. Those are the key takeaways from this week’s changes.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed