Podman运行Go容器时OpenSSL版本获取失败问题求助
问题:Podman exec进入容器时出现OpenSSL版本获取失败错误
我在Podman 4.9.4中运行一个基于go1.22.5-3的Docker.io容器,执行podman exec -it命令进入容器时,出现“openssl: can't retrieve OpenSSL version”错误。经排查,该错误来自golang-fips/openssl仓库v2版本的init.go文件(相关代码如下)。
容器所在的RHEL 8系统已安装OpenSSL,请问是什么原因导致dlopen无法获取已安装OpenSSL的主版本、次版本和补丁版本?
// opensslInit loads and initialize OpenSSL. // If successful, it returns the major and minor OpenSSL version // as reported by the OpenSSL API. // // See Init() for details about file. func opensslInit(file string) (major, minor, patch uint, err error) { // Load the OpenSSL shared library using dlopen. handle, err := dlopen(file) if err != nil { return 0, 0, 0, err } // Retrieve the loaded OpenSSL version and check if it is supported. // Notice that major and minor could not match with the version parameter // in case the name of the shared library file differs from the OpenSSL // version it contains. imajor := int(C.go_openssl_version_major(handle)) iminor := int(C.go_openssl_version_minor(handle)) ipatch := int(C.go_openssl_version_patch(handle)) if imajor < 0 || iminor < 0 || ipatch < 0 { return 0, 0, 0, errors.New("openssl: can't retrieve OpenSSL version") }
执行的命令:
sudo podman --log-level=debug run --name <name> -d <container> sudo podman --log-level=debug exec -i <name> ls
调试输出包含:
panic: opensslcrypto: can't initialize OpenSSL : openssl: can't retrieve OpenSSL version goroutine 1 ... [running]: panic({...}) /usr/lib/golang/src/runtime/panic.go:779 crypto/internal/backend.init.0() /usr/lib/golang/src/crypto/internal/backend/openssl.go:65 runtime.doInit1(...) /usr/lib/golang/src/runtime/proc.go:7176 runtime.doInit(...) /usr/lib/golang/src/runtime/proc.go:7143 runtime.main() /usr/lib/golang/src/runtime/proc.go:253 runtime.goexit({}) /usr/lib/golang/src/runtime/asm_amd64.s:1695 ... time="..." level=error msg="exec failed: unable to start container process: read init-p: connection reset by peer
可能的原因分析
- 容器内缺少OpenSSL库文件:宿主RHEL8系统的OpenSSL不会自动共享到容器中,容器是独立隔离环境。如果镜像本身未安装OpenSSL,或者安装后库文件路径配置错误,
dlopen无法找到目标共享库,进而无法获取版本信息。 - OpenSSL版本不兼容:golang-fips/openssl v2对OpenSSL版本有明确要求(如需1.1.1或3.x系列),若容器内的OpenSSL版本过低、过高或为不兼容的定制分支(如旧版FIPS特供版),会导致
go_openssl_version_major等函数返回负数,触发错误判断逻辑。 - 库文件路径配置异常:
dlopen调用时指定的库路径在容器内不存在,或者容器的动态链接库搜索路径(LD_LIBRARY_PATH)未包含OpenSSL库所在目录,即便库文件存在也无法被正确加载。 - 权限或SELinux限制:RHEL8默认启用SELinux,若容器运行时未配置合适的SELinux策略,可能会阻止进程访问OpenSSL库文件,导致
dlopen调用失败,最终无法获取版本。 - Go编译时FIPS配置问题:go1.22.5-3可能启用了FIPS模式,此时依赖golang-fips/openssl处理加密操作。若编译阶段未正确指向容器内的OpenSSL库,或FIPS模式下的库加载逻辑存在缺陷,会引发版本获取失败。
内容的提问来源于stack exchange,提问作者Brian
相关产品推荐
相关产品推荐

