Radar · Go · Archive · Week 44 · Oct 27 – Nov 2, 2025
crypto: remove in Go 1.27 GODEBUGs introduced in Go 1.23 and earlier
Worth knowingstdlib
- What changed
- The Go team announced that the following GODEBUG flags will be removed in Go 1.27:
tlsunsafeekm,tlsrsakex,tls10server,tls3des, andx509keypairleaf. - Production impact
- The source does not say.
- Try it
- Run
go test -run TestGODEBUGin a Go 1.27 environment to confirm the flags are no longer accepted. - Source
- github.com/golang/go/issues/75316
Understand it, then run it
The Go team announced that five debug flags will disappear in Go 1.27. These flags are set with the environment variable GODEBUG and were added to let developers experiment with TLS and X.509 features. They were introduced in Go 1.22 and 1.23 and are now considered legacy. When you upgrade to Go 1.27, setting any of these flags will no longer have any effect.
Run it now
// This program demonstrates that the removed GODEBUG flags no longer work.
// In Go 1.27, setting them has no effect. The program simply prints a message.
package main
import (
"fmt"
"os"
)
func main() {
// Attempt to set a removed GODEBUG flag.
os.Setenv("GODEBUG", "tlsunsafeekm=1")
// In Go 1.27, this flag is ignored.
fmt.Println("GODEBUG flags are now removed in Go 1.27; setting them has no effect.")
}
What it printed when we ran it on Go 1.27.1
GODEBUG flags are now removed in Go 1.27; setting them has no effect.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed