You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Podman运行Go容器时OpenSSL版本获取失败问题求助

问题:Podman exec进入容器时出现OpenSSL版本获取失败错误

我在Podman 4.9.4中运行一个基于go1.22.5-3的Docker.io容器,执行podman exec -it命令进入容器时,出现“openssl: can't retrieve OpenSSL version”错误。经排查,该错误来自golang-fips/openssl仓库v2版本的init.go文件(相关代码如下)。

容器所在的RHEL 8系统已安装OpenSSL,请问是什么原因导致dlopen无法获取已安装OpenSSL的主版本、次版本和补丁版本?

// opensslInit loads and initialize OpenSSL.
// If successful, it returns the major and minor OpenSSL version
// as reported by the OpenSSL API.
//
// See Init() for details about file.
func opensslInit(file string) (major, minor, patch uint, err error) {
    // Load the OpenSSL shared library using dlopen.
    handle, err := dlopen(file)
    if err != nil {
        return 0, 0, 0, err
    }

    // Retrieve the loaded OpenSSL version and check if it is supported.
    // Notice that major and minor could not match with the version parameter
    // in case the name of the shared library file differs from the OpenSSL
    // version it contains.
    imajor := int(C.go_openssl_version_major(handle))
    iminor := int(C.go_openssl_version_minor(handle))
    ipatch := int(C.go_openssl_version_patch(handle))
    if imajor < 0 || iminor < 0 || ipatch < 0 {
        return 0, 0, 0, errors.New("openssl: can't retrieve OpenSSL version")
    }

执行的命令:

sudo podman --log-level=debug run --name <name> -d <container>
sudo podman --log-level=debug exec -i <name> ls

调试输出包含:

panic: opensslcrypto: can't initialize OpenSSL : openssl: can't retrieve OpenSSL version

goroutine 1 ... [running]:
panic({...})
   /usr/lib/golang/src/runtime/panic.go:779
crypto/internal/backend.init.0()
   /usr/lib/golang/src/crypto/internal/backend/openssl.go:65
runtime.doInit1(...)
   /usr/lib/golang/src/runtime/proc.go:7176
runtime.doInit(...)
   /usr/lib/golang/src/runtime/proc.go:7143
runtime.main()
   /usr/lib/golang/src/runtime/proc.go:253
runtime.goexit({})
   /usr/lib/golang/src/runtime/asm_amd64.s:1695

...

time="..." level=error msg="exec failed:  unable to start container process: read init-p: connection reset by peer

可能的原因分析

  • 容器内缺少OpenSSL库文件:宿主RHEL8系统的OpenSSL不会自动共享到容器中,容器是独立隔离环境。如果镜像本身未安装OpenSSL,或者安装后库文件路径配置错误,dlopen无法找到目标共享库,进而无法获取版本信息。
  • OpenSSL版本不兼容:golang-fips/openssl v2对OpenSSL版本有明确要求(如需1.1.1或3.x系列),若容器内的OpenSSL版本过低、过高或为不兼容的定制分支(如旧版FIPS特供版),会导致go_openssl_version_major等函数返回负数,触发错误判断逻辑。
  • 库文件路径配置异常:dlopen调用时指定的库路径在容器内不存在,或者容器的动态链接库搜索路径(LD_LIBRARY_PATH)未包含OpenSSL库所在目录,即便库文件存在也无法被正确加载。
  • 权限或SELinux限制:RHEL8默认启用SELinux,若容器运行时未配置合适的SELinux策略,可能会阻止进程访问OpenSSL库文件,导致dlopen调用失败,最终无法获取版本。
  • Go编译时FIPS配置问题:go1.22.5-3可能启用了FIPS模式,此时依赖golang-fips/openssl处理加密操作。若编译阶段未正确指向容器内的OpenSSL库,或FIPS模式下的库加载逻辑存在缺陷,会引发版本获取失败。

内容的提问来源于stack exchange,提问作者Brian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 18:23:15