BoundaryML/baml · error
invalid checksum format
Error message
invalid checksum format '%s' for %s in %s
What it means
A line in the checksum file matched the target filename, but the extracted checksum string failed the isHex validation (non-empty, even-length, hex characters). The file contents are malformed, so downloadChecksum refuses to return an untrustworthy value.
Solutions
- Inspect the checksum file at checksumURL and confirm its format matches '<hex> <filename>'
- Regenerate/publish the checksum file with sha256sum output format
- If a mirror serves an HTML error page, fix the mirror or use the canonical URL
- Update library code if upstream changed the checksum file format
Example fix
// before: mismatched checksum file format myfile.bin:e3b0c442... // parsed field fails isHex // after: publish standard format e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 myfile.bin
Defensive patterns
Strategy: validation
Validate before calling
func validChecksumLine(line string) bool {
f := strings.Fields(line)
return len(f) >= 2 && len(f[0])%2 == 0 && isHexString(f[0])
} Type guard
func isHexChecksum(s string) bool {
if len(s) == 0 || len(s)%2 != 0 { return false }
_, err := hex.DecodeString(s)
return err == nil
} Try / catch
if _, err := downloadChecksum(url, name); err != nil && strings.Contains(err.Error(), "invalid checksum format") {
logger.Warn("malformed checksum file; skipping verification", "url", url)
} Prevention
- Publish checksum files in standard sha256sum output format ('<hex> <file>')
- Never hand-edit checksum files; generate with sha256sum
- Verify mirrors serve raw text, not HTML error pages
- Keep checksum generation in the release pipeline, consistent across versions
When it happens
Trigger: The checksum file contains a line whose second field for targetFilename is not a valid hex hash — e.g. 'sha256' prefixed column, a text placeholder, or a truncated/garbage hash.
Common situations: Checksum file generated by a tool with a different format (e.g. '<hash> <file>' vs '<file>:<hash>' parsed incorrectly), a partially written checksum file, or an HTML error page saved as .sha256.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- blob digest mismatch for
- blob size mismatch for
- checksum for ' ' not found within file
- invalid SHA-256 checksum
- invalid sha256 blob digest; expected only hex characters
AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12).
Data as JSON: /api/errors/0d7fd4470e05017d.
Report an issue: GitHub.
Appendix: source
Thrown at engine/language_client_go/baml_go/lib_common.go:611
if err != nil {
return "", fmt.Errorf("error reading checksum body %s: %w", checksumURL, err)
}
lines := strings.Split(string(bodyBytes), "\n")
for _, line := range lines {
parts := strings.Fields(line)
if len(parts) >= 2 {
checksum, filenameInLine := parts[0], strings.TrimPrefix(parts[1], "*")
if filenameInLine == targetFilename {
if len(checksum) == 64 && isHex(checksum) {
logger.Debug("Found matching checksum in file", "filename", targetFilename, "checksum", checksum)
return checksum, nil
}
logger.Warn("Invalid checksum format found in checksum file",
"url", checksumURL,
"filename", targetFilename,
"found_checksum", checksum)
return "", fmt.Errorf("invalid checksum format '%s' for %s in %s", checksum, targetFilename, checksumURL)
}
}
}
logger.Warn("Checksum for target file not found within checksum file",
"url", checksumURL,
"target_filename", targetFilename)
return "", fmt.Errorf("checksum for '%s' not found within file %s", targetFilename, checksumURL)
}
func isHex(s string) bool {
if len(s) == 0 {
return false
}
for _, r := range s {
if !((r >= '0' && r <= '9') || (r >= 'a' && r <= 'f') || (r >= 'A' && r <= 'F')) {
return false
}View on GitHub (pinned to bd85ce9dee)