go
module_error
ai_generated
true
go: 验证模块失败:校验和不匹配
go: verifying module: checksum mismatch
ID: go/checksum-mismatch-proxy
80%修复率
85%置信度
0证据数
2024-01-15首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 1.17 | active | — | — | — |
根因分析
go.sum 中记录的模块版本校验和与从代理下载的模块内容计算出的校验和不一致,通常由下载缓存损坏或代理被中间人攻击导致。
English
The go.sum entry for a module version does not match the checksum computed from the downloaded module content, often due to a corrupted download cache or a MITM attack on the proxy.
解决方案
-
80% 成功率
Remove the problematic module from the module cache: go clean -modcache, then run go mod download to re-download with fresh checksums.
-
90% 成功率
Use GONOSUMCHECK=* or GONOSUMDB=* to bypass checksum verification for specific modules (temporary, not recommended for production).
无效尝试
常见但无效的做法:
-
60% 失败
go mod tidy will regenerate go.sum from the proxy, but if the proxy serves corrupted content or is malicious, the same mismatch will recur.
-
95% 失败
This flag only affects module resolution, not checksum verification; the mismatch persists.