Activity

Today
Thanks. Carved out module now has a release version. ``` $ go mod init test go: creating new go.mod: module test $ go get golang.org/x/crypto/openpgp@latest go: downloading golang.org/x/crypto v0.5…
Thanks.
Thanks. This should be the version that can be tagged as v0.1.0-deprecated.
The release freeze for Go 1.28 is a bit over a month away. Do a preliminary update of the release target list. So far its diff compared to that of Go 1.27 is as follows: - No changes. We'll revisit…
Thanks. I left some suggestions, mostly minor and optional. Consider filing a tracking issue for this and adding "For golang/go#nnn." In case there are some issues with this functionality, having a …
dmitshur reviewed +2 on spec: fix EBNF for composite literals3h
Thanks.
Thanks. Unfortunately, it seems very hard¹ to avoid breaking trybots for everyone in x/crypto with this CL, so it'd be good to be able to update and submit CL 848205 very soon after this one. I'll …
Thanks. Leaving an unresolved comment for actually doing this.
dmitshur commented on golang.org/x/exp/sumdb: delete4h
Yeah, I left a comment in CL 838545 about it. Adding TryBot-Bypass here since everything else passes.
(1 comment) Note that golang​.org/x/exp/ebnflint.TestSpec [reports a finding](https://ci.chromium.org/ui/p/golang/builders/ci/x_exp-gotip-linux-amd64/b8668444157200869681/test-results?q=ExactID%3A…
dmitshur reviewed +2 on golang.org/x/exp/sumdb: delete4h
Since this is x/exp and this code already graduated to another x/ repo, this deletion seems fine without needing an accepted proposal. Thanks. Indeed.
Thanks. Leaving a general thought that this makes me think of, already resolved since it's not specific to this CL. I wonder if at some point it would make sense to start defaulting to embedding te…
There are new failures today that look like: ``` === RUN TestCertificateTransparency http://ct.googleapis.com/logs/argon2020/ct/v1/get-sth <html><head><meta http-equiv="content-type" content="tex…
Yesterday
Thanks. Adding a hold for a tagged version of the carved out module being available. That is, something like the following should be made to work before proceeding with the deletion: ``` go get gol…
(1 comment) Right now there are only two CLs in this stack. This one carves out the module, but it still has a replace directive. The second CL deletes the module. But we want a step in between tha…
By now PRIVATE-track security fixes involving a vendored/bundled package have been released, and these tests can be made to run again as before. [git-generate] updatestd -goroot=$(pwd) -branch=inter…
CC @dsnet, @bradfitz, @mvdan.
dmitshur opened an issue all: end support for macOS 13 in Go 1.291d
### Proposal Details Apple continues a yearly major macOS release cadence, and the last accepted proposal to drop the very oldest macOS version was #75836, a year ago. Since neither the macOS nor Go…
(1 comment) Thanks for clarifying this.
Thanks. See inline comment. I think this change was a good way to unblock today's release from proceeding, but maybe we don't need it longer term? After fixing the submit type, presumably there shou…
(1 comment) I just noticed this TODO - perhaps the code below addresses it.
The failing gotip-linux-amd64-boringcrypto trybot failed in the runtime package with "fatal error: gp.xRegState.p != nil on async preempt". This CL is only touching net/http, so it doesn't seem relat…
Set a limit on the number of ranges in a Range header, avoiding excessive allocations/CPU when parsing a header containing a large number of small ranges. The limit is controlled by GODEBUG=httpserv…
Thanks. Asking a few questions to improve my understanding of what this refers to. What is an example of confusion? Is an example of that when a security fix cannot be automatically cherry-picked f…
Thanks.
Thanks. This part of the method documentation is being made obsolete by the implementation change below.
This Week
Moved Critical label to the upstream issue.
Moved Critical label to the upstream issue.
Thanks. Note for next time, since this isn't the main repo, this generally needs to include the 'golang/go' prefix. ```suggestion For golang/go#82017 ``` It's not a big deal this time, and the lin…
Thanks. You'd probably want to set a known issue for this experimental builder type to start out with, right? The commit message says the intent is to add a postsubmit builder, but it's currently b…
From triage meeting, this is likely not a regalloc bug but elsewhere. @cherrymui said that @randall77 had a suggested approach for this might work for this.
We discussed this in a release meeting. Approved the already-created backport CL.
We discussed this in a release meeting. Approved the already-created backport CL.
Approving the backport to Go 1.26 for CL 795240 and CL 837245.
The upstream issue was fixed by CL 841425, so approving that for backport. Please comment if that's not right.
The upstream issue was fixed by CL 841425, so approving that for backport. Please comment if that's not right.
@abner-chenc Can you please include a backport rationale for this request. Also, is this a problem for Go 1.26 only, or is 1.27 also affected?
CC @golang/security, @cpu.
CC @neild.
CC @ianlancetaylor, @neild, @nicholashusin.
CC @golang/compiler.
dmitshur closed an issue : x/pkgsite:3d
Empty issue.
dmitshur commented on : x/pkgsite:3d
Empty issue.
CC @golang/runtime.
CC @golang/aix, @golang/runtime.
CC @griesemer, @rsc, @thatnealpatel.
CC @golang/windows, @golang/runtime.
CC @golang/windows, @golang/runtime.
CC @golang/tools-team, @ALTree.
During this month's release workflow, we saw relui get restarted due to OOM. It's quite possible that enabling the race detector contributed to more memory usage, enough to exceed its current 8 GB al…
CC @golang/runtime, @golang/windows.
(2 comments) > If we can use 12 for the default builders I think that would be better. We're already using 12 for linux/arm64 (CL 622318), but still 11 for linux/amd64. Changing the version comes w…
Thanks. (nit) Given a not very self-descriptive type like `chan string`, 'ch' is not a very descriptive variable name for it. Since it's being used to log notable state changes, consider naming it s…
dmitshur commented on security: fix CVE-2026-568614d
Removing release-blocker for clarity. Since this issue was moved to the Unreleased milestone, that label has no effect. It can be re-added if this needs to block a specific release.
Removing release-blocker for clarity. Since this issue was moved to the Unreleased milestone, that label has no effect. It can be re-added if this needs to block a specific release.
Thanks. https://go.dev/doc/comment suggests "Every exported (capitalized) name should have a doc comment." I wonder if it could work out slightly better to do the mark ready step as soon as the con…
Thanks. It's kinda surprising to see that given it's [not documented](https://gerrit-review.googlesource.com/Documentation/rest-api-changes.html#set-message) in the Gerrit API REST docs, and [this](…
Thanks. What is the effect and motivation of having a sleep here and on line 961 (above)? They're in the same goroutine, so as far as I can tell they have no effect inside synctest.Test. If they hav…
Thanks. By this line, ci has been assigned to movedCI. Will its Branch field be the new branch by then? If so, perhaps something like: ```suggestion prevBranch := ci.Branch ci = &movedCI ctx.…
Last Week
Another tool to consider is cmp.Diff, since its output on failure can be easier to read.
Thanks. I'll note that it seems a bit unexpected that DeploymentMap would have this effect on Symbols, where an empty map causes p.Symbols to be used as is, whereas a non-empty map causes some filte…