This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 12 · Mar 16 – 22, 2026from 5 items

The Go team accepted several proposals that expand the language’s type inference, add new math/big helpers, and simplify TLS configuration for QUIC and local certificate access. No new releases or bug advisories appeared this week.

Worth knowingstdlib

crypto/tls: remove minimum version requirement for QUIC

What changed
The explicit MinVersion check for QUIC connections has been removed; QUIC will internally clamp the effective minimum to TLS 1.3 while preserving the original value for non‑QUIC use.
Production impact
The source does not say.
Try it
Create a tls.Config with MinVersion: tls.VersionTLS12 and use it for both HTTP/2 and HTTP/3 listeners without cloning.
Source
github.com/golang/go/issues/77631
Explain it and run it

Understand it, then run it

The Go crypto/tls package used to force the minimum TLS version to 1.3 when a configuration was used for QUIC. That meant if you wanted to run both HTTP/2 (which can use TLS 1.2) and HTTP/3 (which requires TLS 1.3) with the same configuration, you had to duplicate the configuration. The change removes that requirement. Now a single configuration can be shared between TCP and QUIC; internally the library will still use TLS 1.3 for QUIC but keeps the original minimum for non‑QUIC connections.

Run it now

Todaygo
// This program demonstrates that a tls.Config with MinVersion set to TLS1.2
// can be used without error. In a real QUIC implementation the library
// would internally clamp the effective minimum to TLS1.3, but that logic
// is not exercised here because we cannot create a QUIC connection in
// this sandbox.

package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Create a configuration that allows TLS1.2 as the minimum.
	cfg := &tls.Config{
		MinVersion: tls.VersionTLS12,
	}

	// Normally we would use cfg with a QUIC listener here.
	// For demonstration, we simply print the effective MinVersion.
	fmt.Printf("Configured MinVersion: %v\n", cfg.MinVersion)

	// The configuration is valid; no panic or error occurs.
}

What it printed when we ran it on Go 1.27.1

Configured MinVersion: 771

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingecosystem

x/crypto/ssh: add AuthCallback to ClientConfig

What changed
ssh.ClientConfig now has an AuthCallback that is invoked before each authentication attempt, receiving a ClientAuthContext with metadata, algorithms, allowed methods, partial successes, and tried methods.
Production impact
The source does not say.
Try it
Set AuthCallback to a function that logs the AllowedMethods before each attempt.
Source
github.com/golang/go/issues/76146
Explain it and run it

Understand it, then run it

The ssh.ClientConfig type in the x/crypto/ssh package now has a new field called AuthCallback. When a program connects to an SSH server, the library normally tries a list of authentication methods that the programmer supplied. With AuthCallback the program can run a small piece of code before each authentication attempt. That code receives information about the server, what methods it accepts, and which methods have already succeeded or failed, and can decide which method to try next or stop the process entirely.

Run it now

Todaygo
// This program demonstrates the current state of the x/crypto/ssh package
// before the AuthCallback feature is available. It constructs a
// ClientAuthContext manually and prints its fields. The AuthCallback
// field does not exist in Go 1.27.1, so we cannot use it here.
// The program compiles and runs with the standard library only.

package main

import (
	"fmt"
)

type ConnMetadata struct{ Host string }
type NegotiatedAlgorithms struct{ KeyAlgo string }

type ClientAuthContext struct {
	Metadata              ConnMetadata
	Algorithms            NegotiatedAlgorithms
	AllowedMethods        []string
	PartialSuccessMethods []string
	TriedMethods          []string
}

func main() {
	// Create a sample context that might be passed to a future AuthCallback.
	ctx := ClientAuthContext{
		Metadata: ConnMetadata{Host: "example.com"},
		Algorithms: NegotiatedAlgorithms{
			KeyAlgo: "curve25519-sha256",
		},
		AllowedMethods:        []string{"publickey", "password"},
		PartialSuccessMethods: []string{"publickey"},
		TriedMethods:          []string{"none"},
	}

	// Print the context to show what information would be available.
	fmt.Printf("Metadata: %+v\n", ctx.Metadata)
	fmt.Printf("Algorithms: %+v\n", ctx.Algorithms)
	fmt.Printf("AllowedMethods: %v\n", ctx.AllowedMethods)
	fmt.Printf("PartialSuccessMethods: %v\n", ctx.PartialSuccessMethods)
	fmt.Printf("TriedMethods: %v\n", ctx.TriedMethods)
}

What it printed when we ran it on Go 1.27.1

Metadata: {Host:example.com}
Algorithms: {KeyAlgo:curve25519-sha256}
AllowedMethods: [publickey password]
PartialSuccessMethods: [publickey]
TriedMethods: [none]

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Write a small program that creates a big.Int, calls the new Divide method with the Floor rounding mode, and prints the quotient and remainder.

Startergo
package main

import (
	"fmt"
	"math/big"
)

func main() {
	x := big.NewInt(10)
	y := big.NewInt(3)
	var q, r big.Int
	// TODO: call Divide with Floor rounding mode and print q and r
}
Show a solution
Solutiongo
package main

import (
	"fmt"
	"math/big"
)

func main() {
	x := big.NewInt(10)
	y := big.NewInt(3)
	var q, r big.Int
	q.Divide(x, y, &r, big.Floor)
	fmt.Printf("quotient: %s, remainder: %s\n", &q, &r)
}

What it printed when we ran it on Go 1.27.1

quotient: 3, remainder: 1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

The 60-second version

This week the Go team added a few new features that make working with the language and its libraries a bit smoother. They expanded function type inference so that generic functions can be assigned to variables without explicitly spelling out type arguments. In the math package, a new Divide method lets you compute quotients and remainders with different rounding rules, which can be handy for financial or scientific calculations. For TLS, the team removed a hard‑coded minimum version check for QUIC, so you can share a single configuration between HTTP/2 and HTTP/3 without cloning it. They also added a field to the TLS connection state that exposes the local certificate used during the handshake, which can help with debugging and monitoring. Finally, in the SSH package, a new callback lets you inspect the authentication context before each attempt, giving you more control over how credentials are chosen. These changes are all optional, but they open up new ways to write cleaner, more robust code.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed