$ the-wire · showcase
Go deletes malformed HTTP/2 headers to close response smuggling, and lifts HTTP/3 into std
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
The Go tree removes a response-smuggling path in its HTTP/2 reverse proxy and moves the HTTP/3 implementation from x/net into the standard library, while pkgsite tightens what counts as a breaking API change.
net/http/internal/http2: delete malformed framing-related headers golang/go
The HTTP/2 implementation was lax about malformed framing-related headers, which let a reverse-proxy response carry them through to an HTTP/1 client and enable response smuggling when that client was also not strict enough. Malformed framing headers are now deleted rather than forwarded.
net/http/internal/http3: move HTTP/3 from x/net to std golang/go
The HTTP/3 implementation moves from x/net into net/http/internal/http3 inside std, so development no longer needs repeated vendoring. Nicholas Husin writes that the CL is "mostly just one to one copy from x/net and deletion of the vendored HTTP/3 code," with imports and comments updated and the nethttp integration test not carried over.
internal/breakings: check for kind mismatches golang/pkgsite
pkgsite's breakings checker now flags kind mismatches at top level in API.Changes: changing a const to a var, even at the same type, is reported as breaking, as are most other kind changes. Tools that gate on the breakings API should expect new reports where none appeared before.
gopls/internal/analysis: use main.go files consistently golang/tools
Every gopls analyzer now ships a //go:build ignore-tagged main file so it can be run standalone, with exceptions documented and the cmd subpackages removed. It is a structural cleanup, but it changes how analyzer entry points are laid out.
gopls/internal/cache: clear unloadableFiles on workspace reinit golang/tools
Clearing the workspace now drops snapshot.unloadableFiles: a file marked unloadable previously left that set only through a metadata-affecting change to the file itself, so repairing go.mod did not clear it. MetadataForFile kept skipping the inline load, and later go.mod changes failed with "no package metadata" until the reload completed.
go/types: add Scope.Objects iterator and cache Scope.Names golang/go
Elsewhere in the tree: go/types adds a Scope.Objects iterator and caches the sorted Scope.Names slice in an atomic pointer, and crypto/x509 avoids linking fmt on empty package imports. In x/net, the internal/http3 package is deleted now that the code lives in std.