BoundaryML/baml · error
Invalid checksum file format
Error message
Invalid checksum file format
What it means
After downloading the checksum file, verify_sha256_checksum parses it expecting the format "hash filename" or just "hash". If splitting on whitespace yields no tokens (empty body), it errors with "Invalid checksum file format".
Solutions
- Inspect the checksum URL response body; regenerate and re-upload a valid '<sha256> <filename>' file for the asset.
- Confirm the checksum URL points at the checksum file, not a directory listing or empty object.
- Re-run the release pipeline to republish the checksum asset.
Example fix
// before (released file) (empty) // after 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08 web-panel-dist.tar.gz
Defensive patterns
Strategy: validation
Validate before calling
body=$(curl -fsS "$CHECKSUM_URL"); echo "$body" | awk 'NF>=1 {print $1; exit}' | grep -Eq '^[0-9a-f]{64}$' && echo valid || echo invalid-checksum-file Try / catch
if let Err(e) = get_playground_dist().await {
if e.to_string().contains("Invalid checksum file format") {
// alert: release metadata is broken, do not retry blindly
}
} Prevention
- CI-validate checksum files match /^[0-9a-f]{64}(\s+.*)?$/ before publishing.
- Never upload empty checksum artifacts.
- Point checksum URLs at the file itself, not a listing.
When it happens
Trigger: The checksum URL returns an empty body (or only whitespace), so checksum_text.split_whitespace().next() is None.
Common situations: Misconfigured release pipeline uploading a zero-byte .sha256 file; a URL that serves an HTML error page of whitespace-free... more commonly an empty 200 response from a misrouted endpoint; truncated upload.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- blob digest mismatch for
- blob size mismatch for
- Checksum mismatch: expected
- ExposedError (formatted via format_last_error_with_details)
- Failed to download checksum file
AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12).
Data as JSON: /api/errors/461523e4e362b893.
Report an issue: GitHub.
Appendix: source
Thrown at engine/playground-server/src/server.rs:274
.header("User-Agent", "baml-playground-server")
.send()
.await
.map_err(|e| anyhow::anyhow!("Failed to download checksum file: {e}"))?;
if !checksum_resp.status().is_success() {
return Err(anyhow::anyhow!(
"Checksum download failed with status: {}",
checksum_resp.status()
));
}
let checksum_text = checksum_resp.text().await?;
// Parse the expected checksum (format: "hash filename" or just "hash")
let expected_checksum = checksum_text
.split_whitespace()
.next()
.ok_or_else(|| anyhow::anyhow!("Invalid checksum file format"))?
.to_lowercase();
// Calculate actual checksum
let mut hasher = Sha256::new();
hasher.update(file_bytes);
let actual_checksum = format!("{:x}", hasher.finalize());
// Verify checksums match
if actual_checksum != expected_checksum {
return Err(anyhow::anyhow!(
"SHA256 checksum verification failed. Expected: {}, Actual: {}",
expected_checksum,
actual_checksum
));
}
tracing::info!("SHA256 checksum verification passed");
Ok(())View on GitHub (pinned to bd85ce9dee)