Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions MICROSOFT_REVISION
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
1
1 change: 1 addition & 0 deletions VERSION
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
go1.27.0
2 changes: 1 addition & 1 deletion go
Submodule go updated 135 files
20 changes: 10 additions & 10 deletions patches/0001-Vendor-external-dependencies.patch
Original file line number Diff line number Diff line change
Expand Up @@ -827,7 +827,7 @@ Use a 'go' that was recently built by the current branch to ensure stable result
create mode 100644 src/vendor/github.com/microsoft/go/cryptobackend/tls13/tls13_windows.go

diff --git a/src/cmd/go.mod b/src/cmd/go.mod
index 9aa7c87ac0e0cf..5e85568ef92c29 100644
index c3e7be5ccd4fd7..a3e96b32d6a962 100644
--- a/src/cmd/go.mod
+++ b/src/cmd/go.mod
@@ -4,6 +4,8 @@ go 1.27
Expand All @@ -838,9 +838,9 @@ index 9aa7c87ac0e0cf..5e85568ef92c29 100644
+ github.com/microsoft/go-infra/telemetry/config v0.0.0-20260526160655-aa04f117b3ce
golang.org/x/arch v0.27.1-0.20260521044007-9c1a596a2c97
golang.org/x/build v0.0.0-20260522210304-d55d0041b921
golang.org/x/mod v0.36.1-0.20260520130633-087f6515dd3b
golang.org/x/mod v0.36.1-0.20260813213634-8569e2639ca1
diff --git a/src/cmd/go.sum b/src/cmd/go.sum
index 9c6aa59dc288d6..17467e5a70382f 100644
index 504ca7c63c0213..356b4b45a3d8c2 100644
--- a/src/cmd/go.sum
+++ b/src/cmd/go.sum
@@ -4,6 +4,10 @@ github.com/google/pprof v0.0.0-20260507013755-92041b743c96 h1:YDDnaZ9afWajDboPMt
Expand Down Expand Up @@ -2666,7 +2666,7 @@ index 00000000000000..016de9bdd95956
+ return filtered
+}
diff --git a/src/cmd/vendor/modules.txt b/src/cmd/vendor/modules.txt
index 6e513d8a5f175e..3fa585ff67412b 100644
index 9dd15064276d3b..8aac6bff803737 100644
--- a/src/cmd/vendor/modules.txt
+++ b/src/cmd/vendor/modules.txt
@@ -16,6 +16,17 @@ github.com/google/pprof/third_party/svgpan
Expand Down Expand Up @@ -2734,15 +2734,15 @@ index 00000000000000..d4671e1584dfa8
+// This file is here just to declare cryptobackend dependencies.
+// This allows tracking their versions in a single patch file.
diff --git a/src/go.mod b/src/go.mod
index bb6abc93792f39..33f32c2e5ba232 100644
index 111f99e60629e1..1bb34e0220022e 100644
--- a/src/go.mod
+++ b/src/go.mod
@@ -3,11 +3,17 @@ module std
go 1.27

require (
- golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766
- golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d
- golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90
+ github.com/microsoft/go-crypto-darwin v0.0.3-0.20260619075948-e554deeefa9f // indirect
+ github.com/microsoft/go-crypto-openssl v0.5.1-0.20260728092821-b4aef158c3ae // indirect
+ github.com/microsoft/go-crypto-winnative v0.0.0-20260605073512-713d2add0825 // indirect
Expand All @@ -2755,12 +2755,12 @@ index bb6abc93792f39..33f32c2e5ba232 100644
- golang.org/x/text v0.37.0 // indirect
+ github.com/microsoft/go/cryptobackend v0.0.0
+ golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766
+ golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d
+ golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90
)
+
+replace github.com/microsoft/go/cryptobackend => ../../cryptobackend
diff --git a/src/go.sum b/src/go.sum
index ab34844da17757..2187be9137b03e 100644
index 20681d37cbe14c..35a399d7bcb2b4 100644
--- a/src/go.sum
+++ b/src/go.sum
@@ -1,3 +1,9 @@
Expand All @@ -2772,7 +2772,7 @@ index ab34844da17757..2187be9137b03e 100644
+github.com/microsoft/go-crypto-winnative v0.0.0-20260605073512-713d2add0825/go.mod h1:a1Z07CJIuWa8WT/pzFIGNTTKS96s8o1B1TPOziAHUxw=
golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766 h1:ABD+jVg0H4Hwu2sGcUtKeb3T8mlS+jS3uWrkTAPcXjs=
golang.org/x/crypto v0.52.1-0.20260526024921-9beb694f9766/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc=
golang.org/x/net v0.55.1-0.20260526154343-657eb1317b5d h1:G6GZDsxGyGK2SxMEqnPJfBWRKGCNpWheup5btZYkYpw=
golang.org/x/net v0.55.1-0.20260731170536-c1d18010be90 h1:v8JYc8J0G5tszb4H3rnr1UU9fjQFKQLtPr8U6HjvVqI=
diff --git a/src/go/build/deps_test.go b/src/go/build/deps_test.go
index 4959a421892996..67627cdb93ff22 100644
--- a/src/go/build/deps_test.go
Expand Down Expand Up @@ -45251,7 +45251,7 @@ index 00000000000000..b7ffeea07c6b8d
+ panic("cryptobackend: not available")
+}
diff --git a/src/vendor/modules.txt b/src/vendor/modules.txt
index 54fcbab6a221c0..7818f183b12cf3 100644
index b34527fdb12010..9f653626f97532 100644
--- a/src/vendor/modules.txt
+++ b/src/vendor/modules.txt
@@ -1,3 +1,57 @@
Expand Down
52 changes: 26 additions & 26 deletions patches/0002-Add-crypto-backends.patch
Original file line number Diff line number Diff line change
Expand Up @@ -2280,7 +2280,7 @@ index 275c60b4de49eb..a5b6ae9dc90505 100644
return nil, err
}
diff --git a/src/crypto/ecdsa/ecdsa.go b/src/crypto/ecdsa/ecdsa.go
index 40a89017570171..24b8ae80344ee8 100644
index 3bd4a5e7b4adaa..48ec7d658c1bbd 100644
--- a/src/crypto/ecdsa/ecdsa.go
+++ b/src/crypto/ecdsa/ecdsa.go
@@ -20,8 +20,6 @@ import (
Expand All @@ -2303,7 +2303,7 @@ index 40a89017570171..24b8ae80344ee8 100644
"golang.org/x/crypto/cryptobyte"
"golang.org/x/crypto/cryptobyte/asn1"
)
@@ -339,8 +341,8 @@ func (priv *PrivateKey) Sign(random io.Reader, digest []byte, opts crypto.Signer
@@ -343,8 +345,8 @@ func (priv *PrivateKey) Sign(random io.Reader, digest []byte, opts crypto.Signer
// ignored unless GODEBUG=cryptocustomrand=1 is set. This setting will be removed
// in a future Go release. Instead, use [testing/cryptotest.SetGlobalRandom].
func GenerateKey(c elliptic.Curve, r io.Reader) (*PrivateKey, error) {
Expand All @@ -2314,7 +2314,7 @@ index 40a89017570171..24b8ae80344ee8 100644
if err != nil {
return nil, err
}
@@ -389,12 +391,12 @@ func SignASN1(r io.Reader, priv *PrivateKey, hash []byte) ([]byte, error) {
@@ -393,12 +395,12 @@ func SignASN1(r io.Reader, priv *PrivateKey, hash []byte) ([]byte, error) {
return nil, errors.New("ecdsa: hash cannot be empty")
}

Expand All @@ -2329,7 +2329,7 @@ index 40a89017570171..24b8ae80344ee8 100644
}
boring.UnreachableExceptTests()

@@ -510,12 +512,13 @@ func VerifyASN1(pub *PublicKey, hash, sig []byte) bool {
@@ -511,12 +513,13 @@ func VerifyASN1(pub *PublicKey, hash, sig []byte) bool {
return false
}

Expand Down Expand Up @@ -2898,7 +2898,7 @@ index a4c9fc977bc136..116106bd0a4cfb 100644

// MustMinimumFIPS140ModuleVersion skips the test if compiled against a lower
diff --git a/src/crypto/internal/cryptotest/hash.go b/src/crypto/internal/cryptotest/hash.go
index 37fd96a2d9d0b9..6d4b190831d57d 100644
index 3e2efa84db720c..4e631a32de56da 100644
--- a/src/crypto/internal/cryptotest/hash.go
+++ b/src/crypto/internal/cryptotest/hash.go
@@ -5,7 +5,6 @@
Expand All @@ -2909,10 +2909,10 @@ index 37fd96a2d9d0b9..6d4b190831d57d 100644
"crypto/internal/fips140"
"hash"
"internal/testhash"
@@ -20,7 +19,7 @@ type MakeHash func() hash.Hash
// TestHash performs a set of tests on hash.Hash implementations, checking the
// documented requirements of Write, Sum, Reset, Size, and BlockSize.
func TestHash(t *testing.T, mh MakeHash) {
@@ -34,7 +33,7 @@ func TestHash(t *testing.T, mh MakeHash) {
h.Sum(end[:0])
})

- if boring.Enabled || fips140.Version() == "v1.0.0" {
+ if fips140.Version() == "v1.0.0" {
testhash.TestHashWithoutClone(t, testhash.MakeHash(mh))
Expand Down Expand Up @@ -3254,7 +3254,7 @@ index 403ff2881f4b68..9cf1efbbeed819 100644

func maybeCloner(h hash.Hash) any {
diff --git a/src/crypto/mldsa/mldsa_fips140v1.26.go b/src/crypto/mldsa/mldsa_fips140v1.26.go
index 2c36fe191e9149..24308c7391ee67 100644
index d3ee1f0daec096..c37363dd9d2662 100644
--- a/src/crypto/mldsa/mldsa_fips140v1.26.go
+++ b/src/crypto/mldsa/mldsa_fips140v1.26.go
@@ -9,8 +9,13 @@ package mldsa
Expand Down Expand Up @@ -3423,8 +3423,8 @@ index 2c36fe191e9149..24308c7391ee67 100644
var errInvalidSignerOpts = errors.New("mldsa: invalid SignerOpts")

// Sign returns a signature of the given message using this private key.
@@ -112,9 +227,21 @@ func (sk *PrivateKey) Sign(_ io.Reader, message []byte, opts crypto.SignerOpts)
if opts, ok := opts.(*Options); ok {
@@ -115,9 +230,21 @@ func (sk *PrivateKey) Sign(_ io.Reader, message []byte, opts crypto.SignerOpts)
if opts, ok := opts.(*Options); ok && opts != nil {
context = opts.Context
}
+ if sk.boring != nil {
Expand All @@ -3446,7 +3446,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
default:
return nil, errInvalidSignerOpts
}
@@ -126,15 +253,21 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts)
@@ -132,15 +259,21 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts)
if opts == nil {
opts = &Options{}
}
Expand All @@ -3459,7 +3459,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
switch opts.HashFunc() {
case 0:
var context string
if opts, ok := opts.(*Options); ok {
if opts, ok := opts.(*Options); ok && opts != nil {
context = opts.Context
}
- return mldsa.SignDeterministic(&sk.k, message, context)
Expand All @@ -3470,7 +3470,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
default:
return nil, errInvalidSignerOpts
}
@@ -146,6 +279,12 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts)
@@ -152,6 +285,12 @@ func (sk *PrivateKey) SignDeterministic(message []byte, opts crypto.SignerOpts)
// A PublicKey is safe for concurrent use.
type PublicKey struct {
p mldsa.PublicKey
Expand All @@ -3483,7 +3483,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
}

// NewPublicKey creates a new ML-DSA public key from the given encoding.
@@ -154,6 +293,14 @@ func NewPublicKey(params Parameters, encoding []byte) (*PublicKey, error) {
@@ -160,6 +299,14 @@ func NewPublicKey(params Parameters, encoding []byte) (*PublicKey, error) {
}

func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKey, error) {
Expand All @@ -3498,7 +3498,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
var err error
var pk *mldsa.PublicKey
switch params {
@@ -175,6 +322,9 @@ func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKe
@@ -181,6 +328,9 @@ func newPublicKey(pub *PublicKey, params Parameters, encoding []byte) (*PublicKe

// Bytes returns the public key encoding.
func (pk *PublicKey) Bytes() []byte {
Expand All @@ -3508,7 +3508,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
return pk.p.Bytes()
}

@@ -187,11 +337,29 @@ func (pk *PublicKey) Equal(x crypto.PublicKey) bool {
@@ -193,11 +343,29 @@ func (pk *PublicKey) Equal(x crypto.PublicKey) bool {
if !ok || other == nil {
return false
}
Expand Down Expand Up @@ -3538,7 +3538,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
switch pk.p.Parameters() {
case "ML-DSA-44":
return MLDSA44()
@@ -213,5 +381,8 @@ func Verify(pk *PublicKey, message []byte, signature []byte, opts *Options) erro
@@ -222,5 +390,8 @@ func Verify(pk *PublicKey, message []byte, signature []byte, opts *Options) erro
if opts == nil {
opts = &Options{}
}
Expand All @@ -3548,7 +3548,7 @@ index 2c36fe191e9149..24308c7391ee67 100644
return mldsa.Verify(&pk.p, message, signature, opts.Context)
}
diff --git a/src/crypto/mldsa/mldsa_test.go b/src/crypto/mldsa/mldsa_test.go
index 375333a70cf686..c319bfe3d98f42 100644
index 0a2fc4edf11183..9c27ff51b27a4f 100644
--- a/src/crypto/mldsa/mldsa_test.go
+++ b/src/crypto/mldsa/mldsa_test.go
@@ -18,6 +18,9 @@ import (
Expand Down Expand Up @@ -4892,7 +4892,7 @@ index 46e47df1d32cf2..48e9bd510cf92e 100644
d.Reset()
d.Write(data)
diff --git a/src/crypto/sha1/sha1_test.go b/src/crypto/sha1/sha1_test.go
index ef6e5ddcbb2d97..b1af8757599a9d 100644
index 8b4618df556271..ae4abc9edfa7c1 100644
--- a/src/crypto/sha1/sha1_test.go
+++ b/src/crypto/sha1/sha1_test.go
@@ -8,10 +8,11 @@ package sha1
Expand Down Expand Up @@ -5830,7 +5830,7 @@ index 027bc22c33c921..eba08da985f832 100644
package fipsonly

diff --git a/src/crypto/tls/handshake_client.go b/src/crypto/tls/handshake_client.go
index 54227aabfb698c..e99bd9bcc49bbf 100644
index 74389458f5b214..1c09278330beda 100644
--- a/src/crypto/tls/handshake_client.go
+++ b/src/crypto/tls/handshake_client.go
@@ -11,7 +11,6 @@ import (
Expand All @@ -5850,7 +5850,7 @@ index 54227aabfb698c..e99bd9bcc49bbf 100644
)

type clientHandshakeState struct {
@@ -524,7 +525,20 @@ func (c *Conn) pickTLSVersion(serverHello *serverHelloMsg) error {
@@ -531,7 +532,20 @@ func (c *Conn) pickTLSVersion(serverHello *serverHelloMsg) error {

// Does the handshake, either a full one or resumes old session. Requires hs.c,
// hs.hello, hs.serverHello, and, optionally, hs.session to be set.
Expand Down Expand Up @@ -5893,7 +5893,7 @@ index f55150697d96f6..b4a89941749d99 100644

type clientHandshakeStateTLS13 struct {
diff --git a/src/crypto/tls/handshake_server.go b/src/crypto/tls/handshake_server.go
index b62feef1a0d2a3..a51f06da2a4928 100644
index a05d6c896bf02f..7e87572488da78 100644
--- a/src/crypto/tls/handshake_server.go
+++ b/src/crypto/tls/handshake_server.go
@@ -64,7 +64,20 @@ func (c *Conn) serverHandshake(ctx context.Context) error {
Expand Down Expand Up @@ -6367,7 +6367,7 @@ index 89fd74eb823162..6d266ff641d721 100644
var Error error

diff --git a/src/internal/buildcfg/cfg_test.go b/src/internal/buildcfg/cfg_test.go
index 2bbd478280241e..dd58604b80b77e 100644
index 2bbd478280241e..313e39edf7514c 100644
--- a/src/internal/buildcfg/cfg_test.go
+++ b/src/internal/buildcfg/cfg_test.go
@@ -6,6 +6,8 @@ package buildcfg
Expand Down Expand Up @@ -6434,7 +6434,7 @@ index 2bbd478280241e..dd58604b80b77e 100644
"v1.0.0",
"v1.0.1",
diff --git a/src/internal/buildcfg/exp.go b/src/internal/buildcfg/exp.go
index bf411a8dbbfcde..daa5ceddfdfb63 100644
index bf411a8dbbfcde..99ce118524720c 100644
--- a/src/internal/buildcfg/exp.go
+++ b/src/internal/buildcfg/exp.go
@@ -10,12 +10,14 @@ import (
Expand Down
Loading