Archive · Week 12 · Mar 16 – 22, 2026from 5 items
The Go team accepted several proposals that expand the language’s type inference, add new math/big helpers, and simplify TLS configuration for QUIC and local certificate access. No new releases or bug advisories appeared this week.
Worth knowingstdlib
crypto/tls: remove minimum version requirement for QUIC
- What changed
- The explicit
MinVersioncheck for QUIC connections has been removed; QUIC will internally clamp the effective minimum to TLS 1.3 while preserving the original value for non‑QUIC use. - Production impact
- The source does not say.
- Try it
- Create a
tls.ConfigwithMinVersion: tls.VersionTLS12and use it for both HTTP/2 and HTTP/3 listeners without cloning. - Source
- github.com/golang/go/issues/77631
Explain it and run it
Understand it, then run it
The Go crypto/tls package used to force the minimum TLS version to 1.3 when a configuration was used for QUIC. That meant if you wanted to run both HTTP/2 (which can use TLS 1.2) and HTTP/3 (which requires TLS 1.3) with the same configuration, you had to duplicate the configuration. The change removes that requirement. Now a single configuration can be shared between TCP and QUIC; internally the library will still use TLS 1.3 for QUIC but keeps the original minimum for non‑QUIC connections.
Run it now
// This program demonstrates that a tls.Config with MinVersion set to TLS1.2
// can be used without error. In a real QUIC implementation the library
// would internally clamp the effective minimum to TLS1.3, but that logic
// is not exercised here because we cannot create a QUIC connection in
// this sandbox.
package main
import (
"crypto/tls"
"fmt"
)
func main() {
// Create a configuration that allows TLS1.2 as the minimum.
cfg := &tls.Config{
MinVersion: tls.VersionTLS12,
}
// Normally we would use cfg with a QUIC listener here.
// For demonstration, we simply print the effective MinVersion.
fmt.Printf("Configured MinVersion: %v\n", cfg.MinVersion)
// The configuration is valid; no panic or error occurs.
}
What it printed when we ran it on Go 1.27.1
Configured MinVersion: 771
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
x/crypto/ssh: add AuthCallback to ClientConfig
- What changed
ssh.ClientConfignow has anAuthCallbackthat is invoked before each authentication attempt, receiving aClientAuthContextwith metadata, algorithms, allowed methods, partial successes, and tried methods.- Production impact
- The source does not say.
- Try it
- Set
AuthCallbackto a function that logs theAllowedMethodsbefore each attempt. - Source
- github.com/golang/go/issues/76146
Explain it and run it
Understand it, then run it
The ssh.ClientConfig type in the x/crypto/ssh package now has a new field called AuthCallback. When a program connects to an SSH server, the library normally tries a list of authentication methods that the programmer supplied. With AuthCallback the program can run a small piece of code before each authentication attempt. That code receives information about the server, what methods it accepts, and which methods have already succeeded or failed, and can decide which method to try next or stop the process entirely.
Run it now
// This program demonstrates the current state of the x/crypto/ssh package
// before the AuthCallback feature is available. It constructs a
// ClientAuthContext manually and prints its fields. The AuthCallback
// field does not exist in Go 1.27.1, so we cannot use it here.
// The program compiles and runs with the standard library only.
package main
import (
"fmt"
)
type ConnMetadata struct{ Host string }
type NegotiatedAlgorithms struct{ KeyAlgo string }
type ClientAuthContext struct {
Metadata ConnMetadata
Algorithms NegotiatedAlgorithms
AllowedMethods []string
PartialSuccessMethods []string
TriedMethods []string
}
func main() {
// Create a sample context that might be passed to a future AuthCallback.
ctx := ClientAuthContext{
Metadata: ConnMetadata{Host: "example.com"},
Algorithms: NegotiatedAlgorithms{
KeyAlgo: "curve25519-sha256",
},
AllowedMethods: []string{"publickey", "password"},
PartialSuccessMethods: []string{"publickey"},
TriedMethods: []string{"none"},
}
// Print the context to show what information would be available.
fmt.Printf("Metadata: %+v\n", ctx.Metadata)
fmt.Printf("Algorithms: %+v\n", ctx.Algorithms)
fmt.Printf("AllowedMethods: %v\n", ctx.AllowedMethods)
fmt.Printf("PartialSuccessMethods: %v\n", ctx.PartialSuccessMethods)
fmt.Printf("TriedMethods: %v\n", ctx.TriedMethods)
}
What it printed when we ran it on Go 1.27.1
Metadata: {Host:example.com}
Algorithms: {KeyAlgo:curve25519-sha256}
AllowedMethods: [publickey password]
PartialSuccessMethods: [publickey]
TriedMethods: [none]
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a small program that creates a big.Int, calls the new Divide method with the Floor rounding mode, and prints the quotient and remainder.
package main
import (
"fmt"
"math/big"
)
func main() {
x := big.NewInt(10)
y := big.NewInt(3)
var q, r big.Int
// TODO: call Divide with Floor rounding mode and print q and r
}
Show a solution
package main
import (
"fmt"
"math/big"
)
func main() {
x := big.NewInt(10)
y := big.NewInt(3)
var q, r big.Int
q.Divide(x, y, &r, big.Floor)
fmt.Printf("quotient: %s, remainder: %s\n", &q, &r)
}
What it printed when we ran it on Go 1.27.1
quotient: 3, remainder: 1
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
This week the Go team added a few new features that make working with the language and its libraries a bit smoother. They expanded function type inference so that generic functions can be assigned to variables without explicitly spelling out type arguments. In the math package, a new Divide method lets you compute quotients and remainders with different rounding rules, which can be handy for financial or scientific calculations. For TLS, the team removed a hard‑coded minimum version check for QUIC, so you can share a single configuration between HTTP/2 and HTTP/3 without cloning it. They also added a field to the TLS connection state that exposes the local certificate used during the handshake, which can help with debugging and monitoring. Finally, in the SSH package, a new callback lets you inspect the authentication context before each attempt, giving you more control over how credentials are chosen. These changes are all optional, but they open up new ways to write cleaner, more robust code.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed