git credential helper 突然失效是因凭据存储层故障:windows凭据管理器中token过期、macos钥匙串权限变更、linux的~/.git-credentials文件被清空或权限非600;go复用git认证,故go mod download会卡在401或authentication failed。

git credential helper 为什么突然不生效
根本不是 Go 的问题,而是 Git 凭证系统在后台静默失效了——比如 Windows 凭据管理器里 token 过期、macOS 钥匙串权限变更、Linux 上 git config --global credential.helper store 对应的 ~/.git-credentials 文件被清空或权限错误。Go 完全复用 Git 的认证流程,go mod download 调用的是 git clone,一旦凭证拿不到,就卡在 authentication failed 或直接 fallback 到 401。
- Windows:打开「控制面板 → 用户账户 → 凭据管理器 → 普通凭据」,找
git:https://git.example.com条目,删掉重输 PAT(Personal Access Token),确保勾选「记住我的凭据」 - macOS:打开「钥匙串访问」,搜索域名(如
git.example.com),双击对应条目 → 「访问控制」→ 勾选/usr/bin/git和/opt/homebrew/bin/git(若用 Homebrew 安装) - Linux:检查
~/.git-credentials是否存在且内容格式为https://token:x-oauth-basic@git.example.com;权限必须是600,否则 Git 拒绝读取:chmod 600 ~/.git-credentials
HTTPS 方式下 PAT 必须带正确 scope
GitLab/GitHub 的 PAT 不是随便生成就能用的。如果拉取私有模块时提示 repository not found 或 permission denied,大概率是 token 缺少必要权限,而不是 URL 写错。
- GitHub:PAT 至少勾选
read:packages、read:org、read:repository(私有库还需read:private_repo) - GitLab:需开启
read_registry(用于包 registry)和read_repository;若模块路径含子组(如gitlab.example.com/group/subgroup/lib),还要确认 token 所属用户对整个路径有访问权限 - 避免把 token 硬编码进
go.mod或 URL:不要写成https://abc123:x-oauth-basic@git.example.com/internal/lib,而应交给 credential helper 管理
SSH 方式失败时先验证 git 层是否通
Go 不自己处理 SSH 认证,它只是调用 git clone git@git.example.com:org/repo.git。所以 go mod tidy 报错说 unknown revision,99% 是你本地 git 命令本身就连不上。
- 运行
ssh -T git@git.example.com—— 必须输出类似Welcome to GitLab, @username!,否则 SSH 密钥没加载或服务端没配公钥 - 确认
~/.ssh/config中对应 Host 的配置没有拼写错误,且IdentityFile指向正确的私钥路径(例如~/.ssh/id_ed25519) - 检查
go.mod里的 module 路径是否与 SSH URL 匹配:若仓库地址是git@git.example.com:org/repo.git,则module行必须是module git.example.com/org/repo(注意域名统一,不含git@或.git后缀)
GOPRIVATE 设置后仍 401?说明 Go 根本没走 Git
设了 GOPRIVATE=git.example.com 却还报 401,说明 Go 没绕过代理,仍在尝试走 https://proxy.golang.org 或校验 sumdb。这通常是因为 GOPRIVATE 值不匹配模块路径前缀,或者 GOPROXY 没配 direct。
- 运行
go env GOPRIVATE,输出必须是精确匹配的前缀,比如git.example.com/*(不能漏/*),多个用逗号分隔无空格:git.example.com/*,my.internal/* -
GOPROXY必须包含direct,否则私有模块仍会被代理拦截:go env -w GOPROXY=https://goproxy.cn,direct - 执行
go list -m all 2>&1 | grep -i "verifying\|sum",如果仍有verifying … sum.golang.org输出,说明GOPRIVATE没生效,回去核对模块路径和环境变量
~/.git-credentials 权限不对、SSH agent 没启动、甚至公司防火墙拦截了 Git 的 HTTPS 端口。每次失败,先跑一句 git ls-remote https://git.example.com/group/repo.git,通了再跑 go mod download。golang免费学习笔记(深入):立即使用
在学习笔记中,你将探索golang的核心概念和高级技巧!











