build: disable runtimesecret GOEXPERIMENT on WSL2

The Go 1.26 `runtimesecret` experiment (stack/register zeroing for forward
secrecy) SIGSEGVs at startup under the WSL2 kernel (confirmed go1.26.3 and
go1.26.4). Detect WSL via /proc/sys/kernel/osrelease and use GOEXPERIMENT=none
there, keeping forward secrecy on every other platform. Plain `make build` now
produces a working luxd on WSL.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Hanzo Dev
2026-06-11 12:41:48 -07:00
co-authored by Claude Opus 4.8
parent 32de1607b4
commit ec31c3ddc2
+8 -1
View File
@@ -7,8 +7,15 @@ CGO_ENABLED ?= 1
FIPS_STRICT ?= 0
# Go 1.26 experimental features:
# runtimesecret - zeroes stack/register state after secret.Do() for forward secrecy
# runtimesecret - zeroes stack/register state after secret.Do() for forward secrecy.
# It SIGSEGVs at startup under the WSL2 kernel (confirmed on go1.26.3 and go1.26.4), so enable
# it only off-WSL; forward secrecy stays on for real Linux/macOS/production builds.
WSL := $(shell grep -qiE 'microsoft|WSL' /proc/sys/kernel/osrelease 2>/dev/null && echo 1)
ifeq ($(WSL),1)
GOEXPERIMENT ?= none
else
GOEXPERIMENT ?= runtimesecret
endif
export GOEXPERIMENT
# FIPS 140-3 always enabled (required for blockchain/financial systems)