Archive · Week 50 · Dec 8 – 14, 2025from 2 items
The Go team accepted two proposals that extend the standard library. One adds HTTP/2 configuration to `net/http`, and the other expands RSA OAEP encryption to allow independent hash selection. Both changes are slated for future releases and do not break existing code.
Worth knowingstdlib
net/http: HTTP/2 configuration API
- What changed
- The proposal introduces a new
HTTP2Configstruct that can be attached tohttp.Serverandhttp.Transport. It unifies server and client HTTP/2 settings and removes the need to importgolang.org/x/net/http2for configuration. - Production impact
- The source does not say.
- Try it
- In a future release, create an
http.Serverand set itsHTTP2Configfield to customize HTTP/2 behavior. - Source
- github.com/golang/go/issues/67813
Worth knowingstdlib
crypto/rsa: allow hash.Hash for OAEP and MGF1 to be specified independently for encryption
- What changed
- The proposal adds
EncryptOAEPWithOptions, a function that accepts separate hash functions for OAEP and MGF1 in RSA-OAEP encryption. - Production impact
- The source does not say.
- Try it
- In a future release, call
rsa.EncryptOAEPWithOptionswith customOAEPOptionsto encrypt data using SHA‑256 for OAEP and SHA‑1 for MGF1. - Source
- github.com/golang/go/issues/65716
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the current limitation of rsa.EncryptOAEP in Go 1.27.1:
// it requires the same hash function for both OAEP and MGF1. The new
// EncryptOAEPWithOptions function, which would allow independent hash
// selection, is not yet available. The code below uses the standard
// EncryptOAEP with a single hash function (sha256) for both roles.
package main
import (
"crypto/rand"
"crypto/rsa"
"crypto/sha256"
"fmt"
)
func main() {
// Generate a temporary RSA key pair for demonstration.
priv, err := rsa.GenerateKey(rand.Reader, 2048)
if err != nil {
panic(err)
}
// The message to encrypt (e.g., a 256‑bit AES key).
msg := []byte("example 256‑bit AES key for demonstration")
// Encrypt using RSA-OAEP with SHA‑256 for both OAEP and MGF1.
ciphertext, err := rsa.EncryptOAEP(sha256.New(), rand.Reader, &priv.PublicKey, msg, nil)
if err != nil {
panic(err)
}
// Decrypt to verify correctness.
plain, err := rsa.DecryptOAEP(sha256.New(), rand.Reader, priv, ciphertext, nil)
if err != nil {
panic(err)
}
fmt.Printf("original: %s\n", msg)
fmt.Printf("decrypted: %s\n", plain)
}
What it printed when we ran it on Go 1.27.1
original: example 256‑bit AES key for demonstration decrypted: example 256‑bit AES key for demonstration
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a short Go program that creates an http.Server, assigns an HTTP2Config with a custom MaxHeaderTableSize, and starts listening on port 8443. Compile and run the program to observe that the server accepts HTTP/2 connections without importing golang.org/x/net/http2.
The 60-second version
Good morning. This week the Go team added two new features to the standard library. First, they introduced a unified HTTP/2 configuration API in the `net/http` package, letting you tweak server and client settings without pulling in the external `x/net/http2` module. Second, they extended RSA OAEP encryption so you can choose different hash functions for the OAEP padding and the MGF1 mask generation, which is useful for certain Android Keystore scenarios. Both changes are slated for future releases, so you can start experimenting with them on the latest development branch. That’s all for this week’s Radar.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed