$ cat golang/month/2026-09-01.log
the month in review · September 2026
Go inliner learns to fold recover calls
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
September also brought a no-op Transport.CancelRequest, a signed-integer comparison fix in pkgsite, and a newly documented LLM-report policy.
cmd/compile: allow inlining of functions that call recover golang/go
Functions that call recover can now be inlined. The unwinder counts inline-expanded frames as separate logical frames, so gorecover previously misidentified valid recover calls; the compiler now accounts for that when deciding what to fold. Panic and recover handling in your hot paths can get ordinary inlining benefits without the old correctness hazard.
net/http: make Transport.CancelRequest into a no-op golang/go
Transport.CancelRequest is now a no-op and the per-Transport map of in-flight requests is gone. If you cancel request contexts by calling CancelRequest, switch to the request's context, which is the only mechanism the transport honors now.
_content/doc/security: decisions: add general principles golang/website
The security policy now states general principles covering how the team decides what counts as a security bug and how it is handled. Useful context the next time you weigh whether a report to golang.org/security is worth filing.
cmd/go/internal/modload: parallelize for speed golang/go
Local directory matching inside LoadPackages runs in parallel, so package loading with multiple local patterns no longer resolves matching directory trees one at a time. Large multi-module workspaces see the win directly.
net/http/httputil/reverseproxy: preserve original header on 1xx golang/go
A ReverseProxy that forwards a 1xx header from the backend now resets the ResponseWriter's headers to their original state instead of clearing them. Go's 1xx handling was new enough that this slipped; reverse proxies that emit informational responses get the fixed behavior.
quic: add Stream.StopSending, and rework stream/application errors golang/net
Stream.StopSending is new, and the error types are renamed: StreamErrorCode becomes StreamError and ApplicationError becomes ConnectionCloseError. Anyone writing against x/net/quic needs to update call sites and type assertions for the renamed error values.
gopls: support assembly References for labels and asm-only symbols golang/tools
textDocument/references in .s assembly files now covers control labels and asm-only symbols. Control labels scope to the enclosing TEXT function and <> symbols stay file-local, so renaming or tracing assembly-heavy code no longer requires guessing at symbol visibility by hand.
runtime: fix randomized heap base prefix mask misalignment golang/go
The randomized heap base prefix mask cleared the top byte at the wrong bit for its hint generator, which places the randomized prefix byte at the randHeapAddrBits position. The mask now lines up, so heap address randomization applies where it was intended on amd64, arm64, and the other affected platforms.
$ ls golang/month/ # the briefings behind this review
Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.