This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 45 · Nov 3 – 9, 2025from 6 items

The Go team delivered a handful of proposals that extend the crypto libraries and added a few bug‑fix releases. The changes focus on making certificate handling future‑proof, improving TPM support in TLS, and simplifying the use of SHA‑3 and ML‑KEM in tests. Two new point releases, 1.24.10 and 1.25.4, ship a handful of package fixes.

Worth knowingstdlib

crypto/x509: add ExtKeyUsage.OID

What changed
The proposal adds a new method ExtKeyUsage.OID() OID and a helper OIDFromASN1OID(asn1OID asn1.ObjectIdentifier) (OID, error) to the crypto/x509 package.
Production impact
The source does not say.
Try it
Inspect a certificate’s ExtKeyUsage values and call OID() to see the underlying OID.
Source
github.com/golang/go/issues/75325
Explain it and run it

Understand it, then run it

The crypto/x509 package has a type called ExtKeyUsage that represents the extended key usage (EKU) values found in a certificate. Before the change, the only way to see what EKUs a certificate had was to look at the slice of ExtKeyUsage values and the slice of unknown OIDs. The ExtKeyUsage values were just integers, so a program could not ask “what is the ASN.1 OID for this EKU?” The change adds a method ExtKeyUsage.OID() that returns the ASN.1 object identifier for a known EKU. It also adds a helper OIDFromASN1OID to create an OID from a raw ASN.1 OID. With these additions a program can now compare EKUs by their OIDs, even if the EKU is not yet supported by the Go library.

Run it now

Todaygo
// This program demonstrates that the new ExtKeyUsage.OID method is not
// available in Go 1.27.1. It simply prints a message explaining the
// current limitation.

package main

import "fmt"

func main() {
	// In Go 1.27.1 the crypto/x509 package does not expose an OID() method
	// on the ExtKeyUsage type, so we cannot retrieve the ASN.1 object
	// identifier of an extended key usage directly.
	fmt.Println("ExtKeyUsage.OID is not available in Go 1.27.1")
}

What it printed when we ran it on Go 1.27.1

ExtKeyUsage.OID is not available in Go 1.27.1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingstdlib

crypto/tls: support crypto.MessageSigner

What changed
The proposal adds support for crypto.MessageSigner in TLS handshakes, allowing implementations that need to hash raw data before signing (e.g., TPM‑backed restricted keys).
Production impact
The source does not say.
Try it
Build a TLS server that uses a crypto.MessageSigner key and observe the handshake logs.
Source
github.com/golang/go/issues/75656
Explain it

Understand it, then run it

The Go standard library now lets TLS use a type called crypto.MessageSigner. Before, TLS only used crypto.Signer, which expects the data to be hashed before it is signed. MessageSigner lets the signer hash the data itself, which is needed for some hardware keys, like TPM‑backed restricted keys. With this change a TLS server can hand the raw data to the signer and let the signer do the hashing and signing in one step.

Nice to knowstdlib

crypto/mlkem: support derandomized encapsulation in tests

What changed
The proposal adds a crypto/mlkem/mlkemtest package with MLKEMEncapsulate768 and MLKEMEncapsulate1024 functions that accept a deterministic randomness slice for known‑answer tests.
Production impact
The source does not say.
Try it
Use mlkemtest.MLKEMEncapsulate768 in a unit test to reproduce a known vector.
Source
github.com/golang/go/issues/73627
Explain it and run it

Understand it, then run it

The Go standard library now has a helper for testing the ML‑KEM cryptographic primitive. When you run ML‑KEM encapsulation in production code, the algorithm picks random bytes from a secure source. For unit tests you often want the same, predictable output so you can compare against known test vectors. The new crypto/mlkem/mlkemtest package gives two functions, MLKEMEncapsulate768 and MLKEMEncapsulate1024, that let you supply the 32‑byte randomness yourself.

Run it now

Todaygo
// This program demonstrates that the mlkemtest package is not available in Go 1.27.1.
// It simply prints a message indicating the absence of the new API.
package main

import "fmt"

func main() {
	fmt.Println("The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.")
}

What it printed when we ran it on Go 1.27.1

The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowtooling

go1.24.10 released

What changed
The release includes fixes to the encoding/pem and net/url packages.
Production impact
The source does not say.
Try it
Run go test ./... to verify that URL parsing behaves as expected.
Source
go.dev/doc/devel/release#go1.24.10
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the fixed behaviour of url.Parse in Go 1.24.10.
// It parses a URL with an uncommon scheme and prints the components.
package main

import (
	"fmt"
	"net/url"
)

func main() {
	// URL with a non‑standard scheme that previously caused a panic.
	u, err := url.Parse("custom://example.com/path?query=1")
	if err != nil {
		fmt.Println("Parse error:", err)
		return
	}
	fmt.Println("Scheme:", u.Scheme)
	fmt.Println("Host:", u.Host)
	fmt.Println("Path:", u.Path)
	fmt.Println("RawQuery:", u.RawQuery)
}

What it printed when we ran it on Go 1.27.1

Scheme: custom
Host: example.com
Path: /path
RawQuery: query=1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowtooling

go1.25.4 released

What changed
The release includes fixes to the compiler, the runtime, and the crypto/subtle, encoding/pem, net/url, and os packages.
Production impact
The source does not say.
Try it
Upgrade to 1.25.4 and run your CI pipeline to ensure no regressions.
Source
go.dev/doc/devel/release#go1.25.4
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates that the standard library still works after the
// 1.25.4 fixes. It parses a URL and prints its components.
package main

import (
	"fmt"
	"net/url"
)

func main() {
	u, err := url.Parse("https://example.com/path?query=1")
	if err != nil {
		panic(err)
	}
	fmt.Printf("Scheme: %s\nHost: %s\nPath: %s\nQuery: %s\n",
		u.Scheme, u.Host, u.Path, u.RawQuery)
}

What it printed when we ran it on Go 1.27.1

Scheme: https
Host: example.com
Path: /path
Query: query=1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Write a small program that parses a PEM‑encoded X.509 certificate, extracts its ExtKeyUsage values, and prints each usage’s OID string using the new OID() method.

The 60-second version

Good morning. This week the Go team added a few useful extensions to the crypto libraries. They introduced a new method on the `ExtKeyUsage` type that lets you retrieve the underlying ASN.1 OID, making it easier to write future‑proof certificate handling code. In TLS, support for the `crypto.MessageSigner` interface was added, allowing implementations that need to hash raw data before signing—useful for TPM‑backed keys. The SHA‑3 package now lets you use a zero value as a valid hash state, simplifying code that creates hash objects on the fly. For testing, a new `mlkemtest` package provides deterministic encapsulation functions so you can run known‑answer tests against the ML‑KEM implementation. Finally, the point releases 1.24.10 and 1.25.4 ship a handful of bug fixes in the standard library and runtime. Those are the highlights from this week.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed