Radar · Go · Archive · Week 51 · Dec 15 – 21, 2025
secret,crypto/subtle: make all "bubbles" inherited across goroutines
Worth knowingstdlib
- What changed
secret.Doandcrypto/subtle.WithDataIndependentTimingbubbles are now inherited by newly started goroutines, matching the behaviour of profile labels and synctest bubbles.- Production impact
- The source does not say.
- Try it
- Wrap a function with
secret.Doand start a new goroutine inside it; observe that the bubble is present. - Source
- github.com/golang/go/issues/76477
Understand it, then run it
secret.Do and crypto/subtle.WithDataIndependentTiming are ways to run code with special guarantees about timing or secrecy. In Go, a goroutine is a lightweight thread. When you start a new goroutine inside one of these special blocks, the new goroutine did not previously inherit the same guarantees. The change makes those guarantees automatically carried over to any goroutine that is started from inside the block. This matches how other features, like profile labels, already work.
Run it now
// This program demonstrates that in Go 1.27.1 the bubble created by
// crypto/subtle.WithDataIndependentTiming is not inherited by goroutines
// started inside the bubble. The outer function runs with data‑independent
// timing, but the goroutine started inside it does not inherit that
// property. The program prints messages to show the execution order.
package main
import (
"fmt"
"crypto/subtle"
)
func main() {
// Run a function under a data‑independent timing bubble.
subtle.WithDataIndependentTiming(func() {
fmt.Println("outer: inside WithDataIndependentTiming")
// Start a new goroutine. It will not inherit the bubble.
go func() {
fmt.Println("inner: started in a new goroutine")
}()
// Wait a moment to let the goroutine finish.
// In a real program you would use sync.WaitGroup.
// Here we just sleep for a short time.
// time.Sleep(10 * time.Millisecond)
})
fmt.Println("main: finished")
}
What it printed when we ran it on Go 1.27.1
outer: inside WithDataIndependentTiming main: finished
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed