This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 40 · Sep 29 – Oct 5, 2025

Expose Hello‑Retry‑Request flag in TLS ConnectionState

Worth knowingstdlib

What changed
The ConnectionState and ClientHelloInfo structs now include a HelloRetryRequest boolean that indicates whether an HRR was performed.
Production impact
The source does not say.
Try it
In a TLS server, inspect tls.ConnectionState().HelloRetryRequest after a handshake to see if an HRR occurred.
Source
github.com/golang/go/issues/74425

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new HelloRetryRequest field in
// crypto/tls.ConnectionState and crypto/tls.ClientHelloInfo.
// The field is available in Go 1.27.1, so we can create a dummy
// ConnectionState value and inspect it. No network activity is
// performed, keeping the program fast and self‑contained.

package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Construct a ConnectionState with HelloRetryRequest set to true.
	// In a real TLS handshake this value would be set by the
	// crypto/tls package to indicate that an HRR was performed.
	cs := tls.ConnectionState{
		HelloRetryRequest: true,
	}

	// Construct a ClientHelloInfo with HelloRetryRequest set to true.
	// This would be set when the client sends a ClientHello in
	// response to a server's Hello Retry Request.
	ch := tls.ClientHelloInfo{
		HelloRetryRequest: true,
	}

	// Print the values to show that the fields exist and can be read.
	fmt.Printf("ConnectionState.HelloRetryRequest: %v\n", cs.HelloRetryRequest)
	fmt.Printf("ClientHelloInfo.HelloRetryRequest: %v\n", ch.HelloRetryRequest)
}

What it printed when we ran it on Go 1.27.1

ConnectionState.HelloRetryRequest: true
ClientHelloInfo.HelloRetryRequest: true

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed