Go 1.26's runtime/secret (GOEXPERIMENT=runtimesecret) tags allocations inside secret.Do(f) for erasure — the right layer to stop secrets leaking into crash core dumps. Key takeaway: it marks, doesn't wipe — you must call runtime.GC() right after or you still leak, and it's a no-op off linux/amd64+arm64.
I built a reproducible harness (canary → SIGSEGV → scan the core): control leaks, secret doesn't. Repo + Dockerfile: https://github.com/cheikh2shift/go-snippets/tree/main/secret-demo Writeup: https://towardsdev.com/runtime-secret-go-1-26s-answer-to-secrets-leaking-in-core-dumps-d884615e971f -- You received this message because you are subscribed to the Google Groups "golang-nuts" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/golang-nuts/44dcd648-f8d0-43ae-9e7b-9db48a68fd2en%40googlegroups.com.
