go module_error ai_generated true

go: 验证模块失败:校验和不匹配

go: verifying module: checksum mismatch

ID: go/checksum-mismatch-proxy

其他格式: JSON · Markdown 中文 · English
80%修复率
85%置信度
0证据数
2024-01-15首次发现

版本兼容性

版本状态引入弃用备注
1.17 active

根因分析

go.sum 中记录的模块版本校验和与从代理下载的模块内容计算出的校验和不一致,通常由下载缓存损坏或代理被中间人攻击导致。

English

The go.sum entry for a module version does not match the checksum computed from the downloaded module content, often due to a corrupted download cache or a MITM attack on the proxy.

generic

解决方案

  1. 80% 成功率
    Remove the problematic module from the module cache: go clean -modcache, then run go mod download to re-download with fresh checksums.
  2. 90% 成功率
    Use GONOSUMCHECK=* or GONOSUMDB=* to bypass checksum verification for specific modules (temporary, not recommended for production).

无效尝试

常见但无效的做法:

  1. 60% 失败

    go mod tidy will regenerate go.sum from the proxy, but if the proxy serves corrupted content or is malicious, the same mismatch will recur.

  2. 95% 失败

    This flag only affects module resolution, not checksum verification; the mismatch persists.