RepoJournal

$ cat golang/week/2026-09-21.log

Go

Go

the week in review · Sep 21 – Sep 27, 2026

Go strips malformed HTTP/2 headers, moves HTTP/3 into std

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

The header deletion closes a response-smuggling path; HTTP/3 now lives in an internal std package, cutting repeated vendoring.

134 commits 7 briefings covered

all golang reviews →

net/http/internal/http2: delete malformed framing-related headers golang/go

by Nicholas S. Husin

Historically lax parsing of framing-related headers let the HTTP/2 implementation forward responses it should have rejected. Malformed headers are now dropped rather than passed along, so servers or proxies that relied on the old leniency need to check their framing.

net/http/internal/http3: move HTTP/3 from x/net to std golang/go

by Nicholas S. Husin

The HTTP/3 implementation moves out of x/net into an internal package in std, so development no longer requires repeated vendoring. Practically, HTTP/3 support now tracks the main tree instead of a module you have to pin.

all: use os.Root for handling user input golang/playground

by Neal Patel

The /compile endpoint accepted an arbitrary txtar, and a malicious one could force writes into the playground host's trusted files. User input now goes through os.Root, which is the same containment pattern you should be applying to untrusted paths in your own services.

simd/archsimd: don't read past the end of the slice in Load*Part golang/go

by Steve Muir

Dropping LoadMasked* changed the Part loads to read a whole vector and mask afterward, which reads past the end of slices shorter than the vector. If you are on the simd/archsimd API, this is the load semantics fix to pick up.

types2, go/types: prevent nil types in published packages golang/go

by Peter Weinberger

Syntax errors, broken cycles, and unresolved types could leave Object.Type(), Alias.fromRHS, Named.fromRHS, or TypeParam.bound nil, and tools traversing the published package graph would panic. Fixed in both go/types and types2, which matters for anything walking type graphs outside the compiler, gopls and linters included.

gopls/internal/cache: clear unloadableFiles on workspace reinit golang/tools

by Hana Kim

A file that failed to load stayed in snapshot.unloadableFiles until something changed the file itself, so repairing go.mod alone did not clear the mark and MetadataForFile kept skipping it. gopls now clears the set on workspace reinit, which fixes stale inlining and analysis after a module fix.

Revert "cmd/cgo: emit any instead of interface{} in generated files" golang/go

by Robert Griesemer

Generating any instead of interface{} in cgo output broke builds, so the change is reverted and interface{} is back in generated files until issue 81648 is resolved. Regenerate or re-vendor if you had already absorbed the rewrite.

compress/flate: speed up writeTokens golang/go

by Alex Gaynor

writeTokens now flushes whole bytes from the bit accumulator after every iteration instead of testing whether 48 bits had accumulated, removing a poorly predicted data-dependent branch. Alongside: go/types gained a Scope.Objects iterator with cached Scope.Names, overflowing constants are invalidated instead of left valid for a later unsafe.Pointer assertion, salsa20 and AES decryption picked up...

$ ls golang/week/ # the briefings behind this review

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all golang reviews →