BoundaryML/baml · error

Invalid checksum file format

Error message

Invalid checksum file format

What it means

After downloading the checksum file, verify_sha256_checksum parses it expecting the format "hash filename" or just "hash". If splitting on whitespace yields no tokens (empty body), it errors with "Invalid checksum file format".

Solutions

  1. Inspect the checksum URL response body; regenerate and re-upload a valid '<sha256> <filename>' file for the asset.
  2. Confirm the checksum URL points at the checksum file, not a directory listing or empty object.
  3. Re-run the release pipeline to republish the checksum asset.

Example fix

// before (released file)
(empty)
// after
9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08  web-panel-dist.tar.gz
Defensive patterns

Strategy: validation

Validate before calling

body=$(curl -fsS "$CHECKSUM_URL"); echo "$body" | awk 'NF>=1 {print $1; exit}' | grep -Eq '^[0-9a-f]{64}$' && echo valid || echo invalid-checksum-file

Try / catch

if let Err(e) = get_playground_dist().await {
    if e.to_string().contains("Invalid checksum file format") {
        // alert: release metadata is broken, do not retry blindly
    }
}

Prevention

When it happens

Trigger: The checksum URL returns an empty body (or only whitespace), so checksum_text.split_whitespace().next() is None.

Common situations: Misconfigured release pipeline uploading a zero-byte .sha256 file; a URL that serves an HTML error page of whitespace-free... more commonly an empty 200 response from a misrouted endpoint; truncated upload.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12). Data as JSON: /api/errors/461523e4e362b893. Report an issue: GitHub.

Appendix: source

Thrown at engine/playground-server/src/server.rs:274

        .header("User-Agent", "baml-playground-server")
        .send()
        .await
        .map_err(|e| anyhow::anyhow!("Failed to download checksum file: {e}"))?;

    if !checksum_resp.status().is_success() {
        return Err(anyhow::anyhow!(
            "Checksum download failed with status: {}",
            checksum_resp.status()
        ));
    }

    let checksum_text = checksum_resp.text().await?;

    // Parse the expected checksum (format: "hash filename" or just "hash")
    let expected_checksum = checksum_text
        .split_whitespace()
        .next()
        .ok_or_else(|| anyhow::anyhow!("Invalid checksum file format"))?
        .to_lowercase();

    // Calculate actual checksum
    let mut hasher = Sha256::new();
    hasher.update(file_bytes);
    let actual_checksum = format!("{:x}", hasher.finalize());

    // Verify checksums match
    if actual_checksum != expected_checksum {
        return Err(anyhow::anyhow!(
            "SHA256 checksum verification failed. Expected: {}, Actual: {}",
            expected_checksum,
            actual_checksum
        ));
    }

    tracing::info!("SHA256 checksum verification passed");
    Ok(())

View on GitHub (pinned to bd85ce9dee)