go module_error ai_generated true

go: verifying module: checksum mismatch

ID: go/checksum-mismatch-proxy

Also available as: JSON · Markdown · 中文
80%Fix Rate
85%Confidence
0Evidence
2024-01-15First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
1.17 active

Root Cause

The go.sum entry for a module version does not match the checksum computed from the downloaded module content, often due to a corrupted download cache or a MITM attack on the proxy.

generic

中文

go.sum 中记录的模块版本校验和与从代理下载的模块内容计算出的校验和不一致,通常由下载缓存损坏或代理被中间人攻击导致。

Workarounds

  1. 80% success
    Remove the problematic module from the module cache: go clean -modcache, then run go mod download to re-download with fresh checksums.
  2. 90% success
    Use GONOSUMCHECK=* or GONOSUMDB=* to bypass checksum verification for specific modules (temporary, not recommended for production).

Dead Ends

Common approaches that don't work:

  1. 60% fail

    go mod tidy will regenerate go.sum from the proxy, but if the proxy serves corrupted content or is malicious, the same mismatch will recur.

  2. 95% fail

    This flag only affects module resolution, not checksum verification; the mismatch persists.