How many engineers does it take to deprecate a struct?
Oct 10, 2026 · 27m
Summary
Hosts Jonathan Hall and Shai Nechmad return after a break to discuss Go 1.27.2 and 1.26.9, highlighting 15 security fixes including an HTTP/2 HPACK race condition and a Windows junction vulnerability in os.Root. They cover an accepted experimental proposal allowing CGO builds without a C compiler and the formal deprecation of the long-unused net.DNSConfigError type. The episode also features a job opening for a Go-focused role at Princess Beef Heavy Industries and notes the decline of a proposal for explicit function-to-interface conversion.
Topics discussed
Intro, host return from break, and camping
Show format and starting with release notes
Go 1.27.2 and 1.26.9 security release overview
HTTP/2 vulnerability and protocol basics
Explaining HPACK header compression
The race condition and server crash details
Why the race detector missed this bug
Windows OS.Root security issue introduction
Junctions and escaping the root directory
What a junction is and upgrade recommendations
Advice on upgrading Go and X/net
Proposal: CGO without a C compiler
Why CGO needs compiler info and friction
Proposal: Deprecating net.DNSConfigError
How to deprecate code in Go
Testing deprecation and tooling support
Lightning round introduction
Job opportunity at Princess Beef Heavy Industries
Update on function-to-interface conversion proposal
Listen ad-free on Castria