diff --git a/MICROSOFT_REVISION b/MICROSOFT_REVISION new file mode 100644 index 0000000000..56a6051ca2 --- /dev/null +++ b/MICROSOFT_REVISION @@ -0,0 +1 @@ +1 \ No newline at end of file diff --git a/VERSION b/VERSION new file mode 100644 index 0000000000..61d3ab1462 --- /dev/null +++ b/VERSION @@ -0,0 +1 @@ +go1.27.0 \ No newline at end of file diff --git a/go b/go index 59418f087c..8af21751f0 160000 --- a/go +++ b/go @@ -1 +1 @@ -Subproject commit 59418f087ceb48826c09acff7eaa12cfe2d479f6 +Subproject commit 8af21751f066eced273ca3ce49506b366847c623 diff --git a/patches/0001-Vendor-external-dependencies.patch b/patches/0001-Vendor-external-dependencies.patch index 340facf064..c89c7fcff7 100644 --- a/patches/0001-Vendor-external-dependencies.patch +++ b/patches/0001-Vendor-external-dependencies.patch @@ -827,7 +827,7 @@ Use a 'go' that was recently built by the current branch to ensure stable result create mode 100644 src/vendor/github.com/microsoft/go/cryptobackend/tls13/tls13_windows.go diff --git a/src/cmd/go.mod b/src/cmd/go.mod -index 9aa7c87ac0e0cf..5e85568ef92c29 100644 +index c3e7be5ccd4fd7..a3e96b32d6a962 100644 --- a/src/cmd/go.mod +++ b/src/cmd/go.mod @@ -4,6 +4,8 @@ go 1.27 @@ -838,9 +838,9 @@ index 9aa7c87ac0e0cf..5e85568ef92c29 100644 + github.com/microsoft/go-infra/telemetry/config v0.0.0-20260526160655-aa04f117b3ce golang.org/x/arch v0.27.1-0.20260521044007-9c1a596a2c97 golang.org/x/build v0.0.0-20260522210304-d55d0041b921 - golang.org/x/mod v0.36.1-0.20260520130633-087f6515dd3b + golang.org/x/mod v0.36.1-0.20260813213634-8569e2639ca1 diff --git a/src/cmd/go.sum b/src/cmd/go.sum -index 9c6aa59dc288d6..17467e5a70382f 100644 +index 504ca7c63c0213..356b4b45a3d8c2 100644 --- a/src/cmd/go.sum +++ b/src/cmd/go.sum @@ -4,6 +4,10 @@ github.com/google/pprof v0.0.0-20260507013755-92041b743c96 h1:YDDnaZ9afWajDboPMt @@ -2666,7 +2666,7 @@ index 00000000000000..016de9bdd95956 + return filtered +} diff --git a/src/cmd/vendor/modules.txt b/src/cmd/vendor/modules.txt -index 6e513d8a5f175e..3fa585ff67412b 100644 +index 9dd15064276d3b..8aac6bff803737 100644 --- a/src/cmd/vendor/modules.txt +++ b/src/cmd/vendor/modules.txt @@ -16,6 +16,17 @@ github.com/google/pprof/third_party/svgpan @@ -2734,7 +2734,7 @@ index 00000000000000..d4671e1584dfa8 +// This file is here just to declare cryptobackend dependencies. +// This allows tracking their versions in a single patch file. diff --git a/src/go.mod b/src/go.mod -index bb6abc93792f39..33f32c2e5ba232 100644 +index 111f99e60629e1..1bb34e0220022e 100644 --- a/src/go.mod +++ b/src/go.mod @@ -3,11 +3,17 @@ module std @@ -2742,7 +2742,7 @@ index bb6abc93792f39..33f32c2e5ba232 100644 require ( - golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766 -- golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d +- golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90 + github.com/microsoft/go-crypto-darwin v0.0.3-0.20260619075948-e554deeefa9f // indirect + github.com/microsoft/go-crypto-openssl v0.5.1-0.20260728092821-b4aef158c3ae // indirect + github.com/microsoft/go-crypto-winnative v0.0.0-20260605073512-713d2add0825 // indirect @@ -2755,12 +2755,12 @@ index bb6abc93792f39..33f32c2e5ba232 100644 - golang.org/x/text v0.37.0 // indirect + github.com/microsoft/go/cryptobackend v0.0.0 + golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766 -+ golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d ++ golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90 ) + +replace github.com/microsoft/go/cryptobackend => ../../cryptobackend diff --git a/src/go.sum b/src/go.sum -index ab34844da17757..2187be9137b03e 100644 +index 20681d37cbe14c..35a399d7bcb2b4 100644 --- a/src/go.sum +++ b/src/go.sum @@ -1,3 +1,9 @@ @@ -2772,7 +2772,7 @@ index ab34844da17757..2187be9137b03e 100644 +github.com/microsoft/go-crypto-winnative v0.0.0-20260605073512-713d2add0825/go.mod h1:a1Z07CJIuWa8WT/pzFIGNTTKS96s8o1B1TPOziAHUxw= golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766 h1:ABD+jVg0H4Hwu2sGcUtKeb3T8mlS+jS3uWrkTAPcXjs= golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc= - golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d h1:G6GZDsxGyGK2SxMEqnPJfBWRKGCNpWheup5btZYkYpw= + golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90 h1:v8JYc8J0G5tszb4H3rnr1UU9fjQFKQLtPr8U6HjvVqI= diff --git a/src/go/build/deps_test.go b/src/go/build/deps_test.go index 4959a421892996..67627cdb93ff22 100644 --- a/src/go/build/deps_test.go @@ -45251,7 +45251,7 @@ index 00000000000000..b7ffeea07c6b8d + panic("cryptobackend: not available") +} diff --git a/src/vendor/modules.txt b/src/vendor/modules.txt -index 54fcbab6a221c0..7818f183b12cf3 100644 +index b34527fdb12010..9f653626f97532 100644 --- a/src/vendor/modules.txt +++ b/src/vendor/modules.txt @@ -1,3 +1,57 @@ diff --git a/patches/0002-Add-crypto-backends.patch b/patches/0002-Add-crypto-backends.patch index f801afb638..26ba50d177 100644 --- a/patches/0002-Add-crypto-backends.patch +++ b/patches/0002-Add-crypto-backends.patch @@ -2280,7 +2280,7 @@ index 275c60b4de49eb..a5b6ae9dc90505 100644 return nil, err } diff --git a/src/crypto/ecdsa/ecdsa.go b/src/crypto/ecdsa/ecdsa.go -index 40a89017570171..24b8ae80344ee8 100644 +index 3bd4a5e7b4adaa..48ec7d658c1bbd 100644 --- a/src/crypto/ecdsa/ecdsa.go +++ b/src/crypto/ecdsa/ecdsa.go @@ -20,8 +20,6 @@ import ( @@ -2303,7 +2303,7 @@ index 40a89017570171..24b8ae80344ee8 100644 "golang.org/x/crypto/cryptobyte" "golang.org/x/crypto/cryptobyte/asn1" ) -@@ -339,8 +341,8 @@ func (priv *PrivateKey) Sign(random io.Reader, digest []byte, opts crypto.Signer +@@ -343,8 +345,8 @@ func (priv *PrivateKey) Sign(random io.Reader, digest []byte, opts crypto.Signer // ignored unless GODEBUG=cryptocustomrand=1 is set. This setting will be removed // in a future Go release. Instead, use [testing/cryptotest.SetGlobalRandom]. func GenerateKey(c elliptic.Curve, r io.Reader) (*PrivateKey, error) { @@ -2314,7 +2314,7 @@ index 40a89017570171..24b8ae80344ee8 100644 if err != nil { return nil, err } -@@ -389,12 +391,12 @@ func SignASN1(r io.Reader, priv *PrivateKey, hash []byte) ([]byte, error) { +@@ -393,12 +395,12 @@ func SignASN1(r io.Reader, priv *PrivateKey, hash []byte) ([]byte, error) { return nil, errors.New("ecdsa: hash cannot be empty") } @@ -2329,7 +2329,7 @@ index 40a89017570171..24b8ae80344ee8 100644 } boring.UnreachableExceptTests() -@@ -510,12 +512,13 @@ func VerifyASN1(pub *PublicKey, hash, sig []byte) bool { +@@ -511,12 +513,13 @@ func VerifyASN1(pub *PublicKey, hash, sig []byte) bool { return false } @@ -2898,7 +2898,7 @@ index a4c9fc977bc136..116106bd0a4cfb 100644 // MustMinimumFIPS140ModuleVersion skips the test if compiled against a lower diff --git a/src/crypto/internal/cryptotest/hash.go b/src/crypto/internal/cryptotest/hash.go -index 37fd96a2d9d0b9..6d4b190831d57d 100644 +index 3e2efa84db720c..4e631a32de56da 100644 --- a/src/crypto/internal/cryptotest/hash.go +++ b/src/crypto/internal/cryptotest/hash.go @@ -5,7 +5,6 @@ @@ -2909,10 +2909,10 @@ index 37fd96a2d9d0b9..6d4b190831d57d 100644 "crypto/internal/fips140" "hash" "internal/testhash" -@@ -20,7 +19,7 @@ type MakeHash func() hash.Hash - // TestHash performs a set of tests on hash.Hash implementations, checking the - // documented requirements of Write, Sum, Reset, Size, and BlockSize. - func TestHash(t *testing.T, mh MakeHash) { +@@ -34,7 +33,7 @@ func TestHash(t *testing.T, mh MakeHash) { + h.Sum(end[:0]) + }) + - if boring.Enabled || fips140.Version() == "v1.0.0" { + if fips140.Version() == "v1.0.0" { testhash.TestHashWithoutClone(t, testhash.MakeHash(mh)) @@ -3254,7 +3254,7 @@ index 403ff2881f4b68..9cf1efbbeed819 100644 func maybeCloner(h hash.Hash) any { diff --git a/src/crypto/mldsa/mldsa_fips140v1.26.go b/src/crypto/mldsa/mldsa_fips140v1.26.go -index 2c36fe191e9149..24308c7391ee67 100644 +index d3ee1f0daec096..c37363dd9d2662 100644 --- a/src/crypto/mldsa/mldsa_fips140v1.26.go +++ b/src/crypto/mldsa/mldsa_fips140v1.26.go @@ -9,8 +9,13 @@ package mldsa @@ -3423,8 +3423,8 @@ index 2c36fe191e9149..24308c7391ee67 100644 var errInvalidSignerOpts = errors.New("mldsa: invalid SignerOpts") // Sign returns a signature of the given message using this private key. -@@ -112,9 +227,21 @@ func (sk *PrivateKey) Sign(_ io.Reader, message []byte, opts crypto.SignerOpts) - if opts, ok := opts.(*Options); ok { +@@ -115,9 +230,21 @@ func (sk *PrivateKey) Sign(_ io.Reader, message []byte, opts crypto.SignerOpts) + if opts, ok := opts.(*Options); ok && opts != nil { context = opts.Context } + if sk.boring != nil { @@ -3446,7 +3446,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 default: return nil, errInvalidSignerOpts } -@@ -126,15 +253,21 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts) +@@ -132,15 +259,21 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts) if opts == nil { opts = &Options{} } @@ -3459,7 +3459,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 switch opts.HashFunc() { case 0: var context string - if opts, ok := opts.(*Options); ok { + if opts, ok := opts.(*Options); ok && opts != nil { context = opts.Context } - return mldsa.SignDeterministic(&sk.k, message, context) @@ -3470,7 +3470,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 default: return nil, errInvalidSignerOpts } -@@ -146,6 +279,12 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts) +@@ -152,6 +285,12 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts) // A PublicKey is safe for concurrent use. type PublicKey struct { p mldsa.PublicKey @@ -3483,7 +3483,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 } // NewPublicKey creates a new ML-DSA public key from the given encoding. -@@ -154,6 +293,14 @@ func NewPublicKey(params Parameters, encoding []byte) (*PublicKey, error) { +@@ -160,6 +299,14 @@ func NewPublicKey(params Parameters, encoding []byte) (*PublicKey, error) { } func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKey, error) { @@ -3498,7 +3498,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 var err error var pk *mldsa.PublicKey switch params { -@@ -175,6 +322,9 @@ func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKe +@@ -181,6 +328,9 @@ func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKe // Bytes returns the public key encoding. func (pk *PublicKey) Bytes() []byte { @@ -3508,7 +3508,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 return pk.p.Bytes() } -@@ -187,11 +337,29 @@ func (pk *PublicKey) Equal(x crypto.PublicKey) bool { +@@ -193,11 +343,29 @@ func (pk *PublicKey) Equal(x crypto.PublicKey) bool { if !ok || other == nil { return false } @@ -3538,7 +3538,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 switch pk.p.Parameters() { case "ML-DSA-44": return MLDSA44() -@@ -213,5 +381,8 @@ func Verify(pk *PublicKey, message []byte, signature []byte, opts *Options) erro +@@ -222,5 +390,8 @@ func Verify(pk *PublicKey, message []byte, signature []byte, opts *Options) erro if opts == nil { opts = &Options{} } @@ -3548,7 +3548,7 @@ index 2c36fe191e9149..24308c7391ee67 100644 return mldsa.Verify(&pk.p, message, signature, opts.Context) } diff --git a/src/crypto/mldsa/mldsa_test.go b/src/crypto/mldsa/mldsa_test.go -index 375333a70cf686..c319bfe3d98f42 100644 +index 0a2fc4edf11183..9c27ff51b27a4f 100644 --- a/src/crypto/mldsa/mldsa_test.go +++ b/src/crypto/mldsa/mldsa_test.go @@ -18,6 +18,9 @@ import ( @@ -4892,7 +4892,7 @@ index 46e47df1d32cf2..48e9bd510cf92e 100644 d.Reset() d.Write(data) diff --git a/src/crypto/sha1/sha1_test.go b/src/crypto/sha1/sha1_test.go -index ef6e5ddcbb2d97..b1af8757599a9d 100644 +index 8b4618df556271..ae4abc9edfa7c1 100644 --- a/src/crypto/sha1/sha1_test.go +++ b/src/crypto/sha1/sha1_test.go @@ -8,10 +8,11 @@ package sha1 @@ -5830,7 +5830,7 @@ index 027bc22c33c921..eba08da985f832 100644 package fipsonly diff --git a/src/crypto/tls/handshake_client.go b/src/crypto/tls/handshake_client.go -index 54227aabfb698c..e99bd9bcc49bbf 100644 +index 74389458f5b214..1c09278330beda 100644 --- a/src/crypto/tls/handshake_client.go +++ b/src/crypto/tls/handshake_client.go @@ -11,7 +11,6 @@ import ( @@ -5850,7 +5850,7 @@ index 54227aabfb698c..e99bd9bcc49bbf 100644 ) type clientHandshakeState struct { -@@ -524,7 +525,20 @@ func (c *Conn) pickTLSVersion(serverHello *serverHelloMsg) error { +@@ -531,7 +532,20 @@ func (c *Conn) pickTLSVersion(serverHello *serverHelloMsg) error { // Does the handshake, either a full one or resumes old session. Requires hs.c, // hs.hello, hs.serverHello, and, optionally, hs.session to be set. @@ -5893,7 +5893,7 @@ index f55150697d96f6..b4a89941749d99 100644 type clientHandshakeStateTLS13 struct { diff --git a/src/crypto/tls/handshake_server.go b/src/crypto/tls/handshake_server.go -index b62feef1a0d2a3..a51f06da2a4928 100644 +index a05d6c896bf02f..7e87572488da78 100644 --- a/src/crypto/tls/handshake_server.go +++ b/src/crypto/tls/handshake_server.go @@ -64,7 +64,20 @@ func (c *Conn) serverHandshake(ctx context.Context) error { @@ -6367,7 +6367,7 @@ index 89fd74eb823162..6d266ff641d721 100644 var Error error diff --git a/src/internal/buildcfg/cfg_test.go b/src/internal/buildcfg/cfg_test.go -index 2bbd478280241e..dd58604b80b77e 100644 +index 2bbd478280241e..313e39edf7514c 100644 --- a/src/internal/buildcfg/cfg_test.go +++ b/src/internal/buildcfg/cfg_test.go @@ -6,6 +6,8 @@ package buildcfg @@ -6434,7 +6434,7 @@ index 2bbd478280241e..dd58604b80b77e 100644 "v1.0.0", "v1.0.1", diff --git a/src/internal/buildcfg/exp.go b/src/internal/buildcfg/exp.go -index bf411a8dbbfcde..daa5ceddfdfb63 100644 +index bf411a8dbbfcde..99ce118524720c 100644 --- a/src/internal/buildcfg/exp.go +++ b/src/internal/buildcfg/exp.go @@ -10,12 +10,14 @@ import (