$ the-wire · showcase
HTTP/2 framing header fix lands in x/net, compiler and PGO changes across Go
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
A CVE-tagged backport in golang/net is the day's only obligation, while golang/go and golang/tools ship a steady run of compiler, PGO, and tooling corrections.
http2: delete malformed framing-related headers golang/net
The x/net backport of CL 835145 makes http2 delete malformed framing-related headers, fixing CVE-2026-78660. Anything terminating or proxying HTTP/2 traffic through x/net's http2 package should pick up this release.
go/ssa: do not canonicalize the signatures of method wrappers golang/tools
Method wrapper signatures are no longer canonicalized, closing a case where a wrapper cached for one instantiation of a generic function could be handed to another and dereference a receiver its origin does not have. MethodValue now returns nil for generic methods before that point.
cmd/internal/pgo: accept CPU profiles from external tools like Linux perf golang/go
FromPProf accepted only Go's own runtime/pprof value types and hard-errored on anything else, which shut out Linux perf profiles converted with perf_data_converter (perf_to_profile) that name sample values after the profiled event, e.g. cycles. PGO consumers can now feed those profiles in.
compress/flate: combine codes in the writeBlockHuff literal loop golang/go
The literal loop in writeBlockHuff was bounded by a serial dependency through the pending bit count, with every code shifted by the current count before the count updated. The three codes of an iteration are now assembled into a separate word first and merged with a single shift and or, leaving the loop's flushing structure unchanged.
cmd/compile: optimize offset+base memory access lowering rules on loong64 golang/go
On loong64, MOV{W,V}P carry a 16-bit immediate field against 12 bits for MOV{W,V}, so offset+base accesses with wider offsets need fewer instructions to load the immediate. The change removes 11,436 instructions from the go binary on that architecture, including 1,280 from cgo.
gopls/internal/golang: Move Declaration - remove decls from source golang/tools
Move Declaration now returns ranges of moving declarations rather than their text, copying source ranges into the destination file and using them to delete the declarations from the source. Floating comments between adjacent moving decls, doc comments, and trailing line comments are still outstanding.
go/callgraph/rta: iterate type infos from slices, not the type map golang/tools
RTA walked every known concrete type against every known interface through typeutil.Map.Iterate, boxing a value per entry; the infos now live in a slice beside each map, which stays for lookup. The remaining long tail is routine: pkgsite attaches screentest diff images for LUCI's viewer, stringintconv's tests move to a go1.21 build tag after !go1.28 tags silently emptied them, the inliner stops...
Action items