How many engineers does it take to deprecate a struct?

Jonathan Hall:

It's fine that you feel worse. It's fine. There's our Can't keep talking about

Shay Nehmad:

fine on this show.

Jonathan Hall:

Okay. This is Cup of Go for 10/09/2026. Keep up to date with the important happenings in the Go community in about twenty minutes per week. I'm Jonathan Hall.

Shay Nehmad:

And I'm Shay Nehmad.

Jonathan Hall:

Feels like I haven't seen you forever, Shay.

Shay Nehmad:

Yeah. We took a fall break. What did you do I with your

Jonathan Hall:

babysat my kids pretty much full time. They've had three weeks off. This is week two of three, so next week I'll be doing the same. And I've been doing job interviews and going to the playground. Yeah.

Jonathan Hall:

Spending time with

Shay Nehmad:

your kids. That sounds good. I I also did the same. I went camping. Nice.

Shay Nehmad:

Anybody's here in the Bay Area, I can highly recommend the Henry Cowell's Redwood State Park. Super beautiful, huge redwoods, we just chilled with friends, played music, went walking in nature, it was really great. Very cool. To compensate for us spending time with our families and having fun, we have two episodes this week. One I recorded just the other night with Bill Kennedy, which may be out by the time you're listening to this, which is a quick live episode.

Shay Nehmad:

And this one, which is just like a normal cup of Go episode. We're just recording news about Go.

Jonathan Hall:

That's right.

Shay Nehmad:

How do we even do... I don't remember how we do this now. How do we start the

Jonathan Hall:

I remember. I I think we start by looking at release notes. Hang on, let me see if there's any release notes. Oh, here's one go. 1 point 27 point 2 has been released.

Shay Nehmad:

Aye, aye, you're letting me go first. You're

Jonathan Hall:

putting my eyes on Yeah, well, we could I will talk about proposals too. I don't know if No, that's things

Shay Nehmad:

I will start. That's fine. Can start? I will start.

Jonathan Hall:

All All right.

Shay Nehmad:

This is one of these releases that I really like. We have just released Go versions 1.27.2 and 1.26.9. These releases include fifteen secondurity fixes.

Jonathan Hall:

Holy cow.

Shay Nehmad:

Yeah, I saw that and I DM'd Jonathan on Slack and I was like, well, I know what our show is gonna be about. But we've decided not to dive into all of them. Sometimes we have like very security focused episodes. I just picked two, but sort of randomly, one of them is from Ryu tek, which we've mentioned, on the show in the past, with the beautiful rainbow themed colored website, just very cutesy, a 22 year old security researcher. Like, we we recognize you just by name already, so you're very good work.

Shay Nehmad:

So the security, vulnerability is in HTTP two servers. HTTP two, in case you're you're unfamiliar, so there's HTTP, which is like protocol used to talk to the web, and two is like the newer one, which is faster. Right?

Jonathan Hall:

Yeah. More efficient.

Shay Nehmad:

Why is it faster? Wow.

Jonathan Hall:

I believe the main advantage of HTTPtwo is it keeps... There's like connection pooling in ways that HTTPone can't, and they can like prefetch things. I don't know, I'm really not a guru in this area.

Shay Nehmad:

So the thing is that there are a lot of things. Right? What you're saying is right. It's... It has connection pooling and it multiplexes on the same connection, like data and blah blah blah.

Shay Nehmad:

But it does a lot of stuff, including something called h pack, which is not... Which is maybe less, obvious than you mentioned stream multiplexing and stream dependencies and server push and all this stuff. You have, like, the TCP and then you have the TLS and then finally you have HTTP over it. And usually compression was in the lower layers and now HTTP two has this thing called h pack... Well, now it's not that new.

Shay Nehmad:

Has a compression for the headers specifically called h pack. There's a way to like, you know, commonly used headers have some header fields that just have a predefined, like, dictionary of what matches to what, and you can do it dynamically as well. And you just, you know, make the headers very highly compressed, which helps a lot in making the things smaller, both in requests and responses. Right? But it's a bit complicated.

Shay Nehmad:

You like, you can't just obviously compress it. And why? Go read the HVAC, like, spec, because it's an audio show and this will not carry well. Turns out that you could cause a server to crash because there are multiple headers here, you could encode HVAC concurrently, which would, like, make it faster, from from the server part. But if you, like, sort of edited that same section, when you're trying to encode both the headers frame and the settings frame, you could...

Shay Nehmad:

It would crash the server because there are two things trying to write basically... You know, it's two goroutines without synchronization. Mhmm. So you as a client, a malicious client, like a bad guy, knowing this, you could send the same request again and again and again and again Mhmm. Which would cause the server to, like, write the same response again and again and again and again.

Shay Nehmad:

But if you change on every request the header table size, it would it would mess up the... Because you're handling a settings frame that contains a settings header table size, like that the client should read. Doing that at the same time would cause a crash. Fix is relatively simple, just don't do it at the same time. Buffer the header table size thing and just wait until you apply it, because you're trying to apply it while you're writing it.

Shay Nehmad:

So one... So it's one go routine trying to write the headers table, and one go routine, like, updating the size of what you're trying to write maybe mid flight and it was unsynchronized. And now it's synchronized. It just waits a second. Alright.

Shay Nehmad:

I thought this was cool. Like, it's a, it's a feature I don't... Like, I assume it happens. Oh, of course, it's compressed. It's efficient, but I don't actually know the details of how it works.

Shay Nehmad:

And two, it also has a synchronization bug, so I feel less stupid for having them myself.

Jonathan Hall:

So I'm curious why this took so long to detect if it's if it's basically a race. Why didn't, for example, the go race detector detect this and people noticed it, you know, ages ago?

Shay Nehmad:

So that's a great question. The Go Race detector, which we talked about like a few episodes ago, detects when you're writing... Two goroutines are reading or writing to the same place. Right? And they might deadlock or something like that.

Shay Nehmad:

This case is a bit more convoluted than that. I actually pulled up the CL from the GoReview Google source site. I think people call it Garrett, right? Yep. Yep.

Shay Nehmad:

I don't know why though. It doesn't say it in the domain name.

Jonathan Hall:

Garrett is the name of the tool that just happens to be hosted at that URL.

Shay Nehmad:

Oh, okay. Whatever. Anyway, so you can see that in the past in the red, and if you're listening, you can't see, but don't worry. I'll tell you. When a client was processing, when the server was processing the settings frame of a client, if you got the settings header table size, you would just apply it to the encoder immediately.

Shay Nehmad:

So it's not like two goroutines editing the same value. It's one goroutine trying to write the headers and another one telling it, oh, here's the max size. Right? If I made it really big and then made it really small, maybe it crashed because it's like, oh, I'm over like my max size, so I don't know what to do now. And if you look at the CL itself, you can see that now there's a little thing called pending encoder table size where it will wait for a second before...

Shay Nehmad:

It will wait until like it's okay to write before it updates the HVAC encoder max dynamic table size to the minimum and then to the maximum. So it's doing something similar to what it used to do, just at a different time, which is not something the race detector would detect. The race detector is like looking at the same pieces of data in memory and like trying to find that. You know, maybe if you made it complicated enough to follow what does this variable impact all over, you could detect it with, like, tools. But this just seems like one of these cases that's gonna be really hard to generalize because, you know, it's not the same address in memory and it happens somewhere else in the code.

Shay Nehmad:

It'll be very difficult to like figure this out, I think.

Jonathan Hall:

And

Shay Nehmad:

also testing, like you got to test concurrently to request with these very malicious values. The race detector is not built to detect these cases. And I also think there aren't any, like, tools that that I can think of

Jonathan Hall:

that will be...

Shay Nehmad:

Yeah. Luckily, we do have security researchers like Riotex.

Jonathan Hall:

That's great.

Shay Nehmad:

The other one's way simpler. Okay. You'll you'll be able to figure out real quick. And also, it's a bug in, Windows, your favorite operating system to dongle. I

Jonathan Hall:

love Windows. I

Shay Nehmad:

love these.

Jonathan Hall:

Let me go let me go open one right now and let the sarcasm out the window. Okay.

Shay Nehmad:

If you're watching on video, I have like these big beautiful windows behind me. The beautiful San Jose wall of the parking lot. All right. So this one's really simple. Do you know the root thing?

Shay Nehmad:

We talked about it a few times on the show. Like, root. O o s dot

Jonathan Hall:

root, you mean. Right? Yes. Yes. I know that.

Jonathan Hall:

I've been using it lately, actually. What does it do? It lets you, like, sort of open a virtual file system of sorts that you can't escape from or or the the the calls that are made from it can't escape from it. So you can say, like, I trust everything in my home directory, but not the rest of the system. So open up a route there and then you can do things there and it won't follow Simlinks or other potentially nefarious paths outside of that route.

Shay Nehmad:

Okay. So if I'm telling you there's a yeah, if I'm telling you this security issue is about OS. Root, what do you think it's going to what it's going to be about?

Jonathan Hall:

Well, Simion links would be the first thing I'd think about, but you said Windows, and I know Windows kind of has a version of that, but it's not really Simion links, so I don't know.

Shay Nehmad:

So so all I'm saying is it doesn't it doesn't do it.

Jonathan Hall:

So it's supposed

Shay Nehmad:

to do it, and here's one other case where it doesn't do it. Thanks to Danielle Bolgiani, I guess the one from Elastic, although, I don't know if it's actually this one, because there's no link to them. If you put a junction...

Jonathan Hall:

I don't know what that is.

Shay Nehmad:

That... I didn't know either.

Jonathan Hall:

So what is a junction...

Shay Nehmad:

Is a junction in Microsoft path? But wait, if you put a junction there, if the target is a junction and the junction is pointing at an empty location, it will create a directory at the target even if it's located outside the root. So let's say you want, your desktop, right? So c colon forward slash users colon forward slash Jonathan, desktop, right? I think I may have said colon too many times, but whatever, like your desktop on windows.

Shay Nehmad:

You're trying to create a root there. So you're calling o s dot root mkdir. Right?

Jonathan Hall:

Mhmm.

Shay Nehmad:

A root dot mkdir. And what's there is a junction that's pointing towards, you know, super, a super folder that doesn't exist. But if it will exist, it will be really good for you. Like user, you know, slash server slash users and then whenever there's a folder there, it creates a new user or something like that.

Jonathan Hall:

Uh-huh.

Shay Nehmad:

You could create a junction that points at that nonexistent directory, and then when root. Mkdir is called, it will create a directory there, even though it's not under your desktop, even though it's outside the root. And the only remaining question is, what the f is a junction?

Jonathan Hall:

It looks like it's Windows version of a of a Simlink, so I wasn't as far off as I thought.

Shay Nehmad:

No, it's... It is, but it's not a shortcut. That when when people tell me the Windows version of a Simlink, I'm thinking, oh, a shortcut. Right?

Jonathan Hall:

Right. Yeah. Yeah.

Shay Nehmad:

It's not that. It's something different. When you create it, you need to pass, like, MK Link slash j. It's only for folders. It's only for your local machine, and it's only absolute paths, and it's something to do with NTFS.

Shay Nehmad:

But it's just like a edge case sort of something I'd never heard of or maybe I heard of it like, you know, somewhere in my history, but I I didn't remember it for sure. And it it didn't work for OSroot and now it does. The the... It didn't let you escape. That's important.

Shay Nehmad:

It only allows you to create. You know what I mean? You can't, like, use this bug to actually access content that you shouldn't be able to access.

Jonathan Hall:

Right. I can do that.

Shay Nehmad:

But you can create folders that aren't, that you shouldn't be able to create, which is not usually not a way that leads to incredible security vulnerabilities. But you know what? It's something you shouldn't be able to do, so probably shouldn't be able to do. What is our recommendation following these security patches?

Jonathan Hall:

Don't use Windows. That's what you mean. Right? Oh, wait. No.

Jonathan Hall:

Up... Upgrade go. Update... That's what it was. Now I remember.

Shay Nehmad:

Now I remember.

Jonathan Hall:

Yes. Are 13 other there are

Shay Nehmad:

13 other fixes we haven't talked about. And these are minor point releases, so just upgrade. If you have HTTP servers or if you're using, by the way, Crypto TLS or if you're trying to write FIPS, like all these things have changed HTML templates, net HTTP, client discordization, like a lot of things that you are probably using. So our recommendation is to upgrade.

Jonathan Hall:

While you're at it...

Shay Nehmad:

If you're not on 26 or 27 yet, then not all these things are getting backported at this point. You should always be on the one before most major usually, if you're not on the latest.

Jonathan Hall:

Yeah. Also, some of these had fixes that landed in the XNet package. So don't just upgrade your Go version, also update to XNet, the XNet version, if you're using that, and you probably are. Almost every project uses that. So

Shay Nehmad:

There there's a lot of other interesting security fixes there, so we'll drop the link to, you know, all of them if you wanna read through them. I just picked two that I thought would make enough sense in an audio format. What else do we do on this show?

Jonathan Hall:

Sometimes I think we talk about proposals. So let's let's try some of that.

Shay Nehmad:

Educate me.

Jonathan Hall:

So we have a couple of proposals we'll talk about. One is a little bit more substantial, although it will affect a small number of people, smaller than general Go population that is. That is an... A proposal has been accepted as an experiment. So this isn't full fledged yet, but the next version of Go presumably will include the ability to use Sego without C.

Jonathan Hall:

What?

Shay Nehmad:

What does that even mean?

Jonathan Hall:

So you probably... If you've if you've done anything with C before, and I've done... I wrote C back in university days. I haven't written serious C programs in anger in a very long time. But you know that you compile your C into like an object file and you can potentially distribute the object file without the C files.

Jonathan Hall:

Right? When you do that, you don't need a C compiler to use that object file. You need a linker and these other tools, but you don't need a C compiler. So this is the idea here is if you're writing Sego that works with these object files, you know, maybe it's a closed source C library or something or you just don't have the source available on your on your target machine or whatever. Maybe you still want to build Sego tools or programs, but you don't want to go to the extra effort of installing a C compiler that you're not actually going to be using because you just have these object files.

Jonathan Hall:

So the idea is to make that possible. I'm not going go into all the details. I'm not a seed developer or a Sego developer, but it's a quite lengthy proposal. And what has been accepted here is the experimental version of that proposal. So if once the experiment lands and people start using it, then it will likely become perhaps in this form or perhaps in a modified form will become an official part of Go for general purpose usage.

Jonathan Hall:

But that seems like a good thing. So like I said, I'm not...

Shay Nehmad:

What you're saying is this should lower friction for Go developers who want to use code that was originally written in C but don't want the C compiler on their machines.

Jonathan Hall:

That's right. Or in their Docker build. Maybe they have it on their dev machine, but they don't need it in their Docker environment or, you know, somewhere along their build process. Don't need to open And

Shay Nehmad:

also we like say the C compiler is if it's the Go compiler, like it's really easy. You just go call Go

Jonathan Hall:

build and

Shay Nehmad:

it works for all platforms. But C, like compiling C is a nightmare. You gotta put all the files in the right place and that's why they have Makefiles, right? Like, because you gotta do all this work ahead of time. That's interesting.

Shay Nehmad:

But why doesn't it work like right now? That's my main question. If you're just loading object files, why do you need the compiler to begin with?

Jonathan Hall:

There's a there's a few things, and the biggest thing is the type... My understanding again, I'm not a Sego developer, but my understanding from reading through this, the biggest thing is the bindings between Go and C. They require information that that depends on the C compiler. So this isn't just a matter of like changing the tooling. This is actually you have to change the way you write your C Go code to make this work.

Shay Nehmad:

Oh, so this is actually going to change just to not just to avoid, like, installing the compiler because you're not actually compiling. It's not a huge friction. You know what I mean?

Jonathan Hall:

I don't know how big a friction it is, but apparently because I've not done this, but I can imagine, like you just said, C is not necessarily easy. So maybe it is a big enough friction to be worth the effort of doing this. It must be because people are doing it. So, yeah, we'll put a link, of course, to the to the original proposal and the the experimental one for anybody who does see Go and wants to understand how this works. It's long proposal.

Jonathan Hall:

Like the original post itself is several is like a blog post. Scrolling pages. Yeah, it's like a blog post. So I'm not going

Shay Nehmad:

to go

Jonathan Hall:

to the details here.

Shay Nehmad:

So this proposal that you're talking about is just add a thing that will allow me to write code behind this experiment flag.

Jonathan Hall:

Yeah. Oh, got it.

Shay Nehmad:

I didn't know you needed a proposal just to add an experiment, but I guess that makes sense because you're adding a thing to the Go experiment environment variable. Yep. Also good just to have, like, for communication. So what's the other one? This doesn't impact me as well.

Shay Nehmad:

I don't write those.

Jonathan Hall:

Yeah. This won't impact you or hopefully anybody at all. The proposal has been accepted. It is to deprecate the net. Dnsconfig error type, which is a struct type that this proposal is old.

Jonathan Hall:

It's been sitting here since 2023, and it mentions that the funniest thing about this, there are, let's see, one, two, three, four comments on this entire issue. The first one says deprecate DNS configure error has been unused since CL 9380, and it is documented as not used. Is there any reason not to deprecate it properly yet? The very next comment is based on the discussion above, this proposal is likely to be accepted. True.

Jonathan Hall:

And then the follow-up one was it was accepted, and the final one was this change closes this issue. But the interesting thing about this isn't how short and terse this issue is or that it's two or three years old. But if you look at what c l ninety three eighty is, that landed in 2015. So this thing has been literally unused for over a decade, still sitting there, which I think helps explain why the discussion was so short about whether or not we should deprecate this thing. So, of course, it's not going to literally be removed.

Jonathan Hall:

It looks like no change to the compiled programs because we can't remove it for compatibility reasons. But unless you have code that was written before 2015, this will have no effect on you.

Shay Nehmad:

Wait, what do you mean we will not... Maybe I misunderstood.

Jonathan Hall:

Can we not just delete it? So literally the only change that actually happened here, this whole proposal was about, was a one line documentation change to replace in parentheses no longer used, kept for compatibility to deprecated colon no longer used, kept for compatibility. Of course, the reason this matters is because tools understand this new format and your IDE will show a strike through or other tools will say this is deprecated, you shouldn't use it anymore, things like that.

Shay Nehmad:

So this is this is the... I actually didn't know this.

Jonathan Hall:

This is like

Shay Nehmad:

the official way to deprecate Go code. You just add Yes. Deprecated colon, and then the tools That's right. Know

Jonathan Hall:

That's

Shay Nehmad:

right. Oh, interesting. I I like... But here's a question. Why can't we just delete this type?

Shay Nehmad:

Because programs will not compile anymore if you try to compile them with, one twenty eight where this type doesn't exist.

Jonathan Hall:

That's right. So if if you have code written in Go 1.5 or whatever was before 2015 You want to stay compiling. It needs to still compile. That's right.

Shay Nehmad:

That's okay. I prefer keeping that. Here's another question, though. If this is deprecated, why won't you deprecate the functions that this struct type has? I'm just...

Shay Nehmad:

Because I opened the CL, I can see here that DNS config error has unwrapped and error and time out. Shouldn't you deprecate these, functions to this, like, you know, receiver... Whatever. All the, functions that have, DNS config error as a receiver? It's kinda weird that you you don't.

Jonathan Hall:

I don't know that you would... Like, you could deprecate a specific function only. Although in this case, all of these functions are there to implement an interface.

Shay Nehmad:

I know. That's what I'm saying. You need to deprecate everything related to to it. It's not like you can call the error unwrap of DNS config error now because it's deprecated. Our recommendation is that you don't call it.

Shay Nehmad:

Although nothing will throw it. This is just a theoretical discussion. Right? I'm just trying to understand Sure.

Jonathan Hall:

I understand.

Shay Nehmad:

Yeah. Is this considered properly deprecating if you haven't added the deprecated comment above the methods as well? I think it

Jonathan Hall:

is properly deprecated because every... All the tooling will recognize that the the base object is deprecated. I think the only the only time you would wanna deprecate a specific method is if just that method is being deprecated.

Shay Nehmad:

How can I? That's interest... Another interesting question is how can I test if the deprecated thing works? If the... Like, if adding the comment will work if, like, I did it correctly?

Jonathan Hall:

On your own goin, like, playground? I don't I don't know that the Go playground will do that. But if you use Versus Code and and its standard Go extension, I know it will probably JetBrains, most of the standard IDEs will. So just, like, open up your a piece of Go code and add deprecated colon foo or something to one of the GoDoc comments and then try to reference it somewhere. Through it.

Jonathan Hall:

Yeah. Or on Golang CI Lint with one of the deprecated

Shay Nehmad:

Yeah. Go vet will probably let you know too. Right? Or one of them.

Jonathan Hall:

I don't know if GoVet will. It might. I know that Golang CI Lint has... I think static check and Golang CI Lint will.

Shay Nehmad:

Got it. Well, I learned how to deprecate. Literally add the word deprecate.

Jonathan Hall:

That's

Shay Nehmad:

it. We've been at Blaber for enough. We have again broken our... We have broken our compatibility promise of making this show short, which is unfortunate, but, you're here to listen us, Blaber. Let's, close it out with a lightning round.

Shay Nehmad:

Lightning round. Before we jump to the lightning round, there's no ad break anymore, but thank you very much to everybody supporting the show on Patreon. If you wanna support us too, cupago. Dev is where it's all at. You can email us at news cupago.

Shay Nehmad:

Dev and find the Slack channel, everything. And please like and share and comment and whatever. Okay, lighting round. We had on the show, Quobix or

Jonathan Hall:

Oh, I know him.

Shay Nehmad:

More formally... More, colloquially Leon as, Dave Shannon.

Speaker 3:

Hello, everyone. My name is Quobix, and I'm the founder of, a company called Princess Beef Heavy Industries or PB three three f for short. It's actually... It's shorter when you say it, you know, versus typing out. Anyway.

Shay Nehmad:

It's kind of a hard to forget name. Princess Beef Heavy Industries. I noticed on LinkedIn that he is looking for employees. And just like, I think he's a really cool guy, probably building really cool stuff. And I asked him on LinkedIn if it's relevant for Go developers.

Shay Nehmad:

And he's like, full stack is Go, all Go, custom everything, all in Go. So if you're interested in that, we're gonna put the link to this LinkedIn post. We usually don't post jobs, but I felt like this was so, you know, he's on the show and it's a Go thing and he's building usually dev tooling and stuff, it just felt right. So you can find a job with Dave. Well, you can apply for a job with Dave in the thing in the LinkedIn comments.

Jonathan Hall:

All right. Finally, rounding out the episode. Back in episode 159, we talked about a proposal to allow explicit conversion from a function to a one method interface. I'm not going to go through it here. I'm just giving you quick update.

Jonathan Hall:

It has been declined. This will not be happening. The reasons are interesting. Lengthy. Lengthy.

Jonathan Hall:

Interesting. Far too long for a lightning round, and it's such an archaic little thing. I'm not going to even go into it even in a regular episode. But if you care, the link is in the show notes. You can go check it out.

Shay Nehmad:

Yeah. I'll just say it's one of the only proposals I've seen which has a timeline that looks like an incident timeline, which is like, you know, 2021, we we thought it was a likely accept, and then it caused a lot of discussions. And then, Ian talked about it. And then after generics, it was taken off hold in 2022 and then let's have a prototype. And then 2023, it's like you actually have a, you know, flight log of what happened.

Shay Nehmad:

Which is funny because I couldn't care if it... What is expected or expect... Accepted or not, like, either way.

Jonathan Hall:

Yeah. Yeah. It's not very important. Cool. Alright.

Shay Nehmad:

I think that's it. Thanks a lot for listening. It's good to be back in the in the saddle. You know what I mean? Oh, yeah.

Shay Nehmad:

That's it. Program exited. Program exited. Goodbye.

Creators and Guests

Jonathan Hall
Host
Jonathan Hall
Freelance Gopher, Continuous Delivery consultant, and host of the Boldly Go YouTube channel.
Shay Nehmad
Host
Shay Nehmad
Engineering Enablement Architect @ Orca
How many engineers does it take to deprecate a struct?
Broadcast by