Hmbown/CodeWhale · error · NonRetryableError

checksum manifest is missing

Error message

${label} checksum manifest is missing ${missing.join(", ")}

What it means

Before downloading, the installer validates that the label's (e.g. the chosen release source's) checksum manifest contains entries for every required asset, collecting all missing names and throwing one aggregated NonRetryableError listing them. This fails fast instead of discovering missing digests mid-verification.

Solutions

  1. Use the official GitHub Release source (unset CODEWHALE_RELEASE_BASE_URL / CODEWHALE_USE_CNB_MIRROR) whose manifest is complete.
  2. If you run the mirror, regenerate SHA256SUMS to include every required asset listed in the error.
  3. Only require assets for the current platform by running the installer on a supported target, or upgrade the installer/mirror to matching versions.
  4. Pick a different complete mirror via CODEWHALE_RELEASE_BASE_URL.

Example fix

// before (partial mirror manifest)
codewhale-linux-x64.tar.gz  <hash>
// after (manifest covers all required assets)
codewhale-linux-x64.tar.gz  <hash>
codewhale-linux-arm64.tar.gz  <hash>
codewhale-darwin-x64.tar.gz  <hash>
codewhale-darwin-arm64.tar.gz  <hash>
codewhale-win32-x64.zip  <hash>
Defensive patterns

Strategy: validation

Validate before calling

const missing = requiredAssets.filter(a => !checksums.has(a));
if (missing.length) throw new Error(`Manifest incomplete, missing: ${missing.join(', ')}`);

Try / catch

try {
  await install();
} catch (err) {
  if (err.message.includes('checksum manifest is missing')) {
    // switch to the official source or complete the mirror's manifest
  } else throw err;
}

Prevention

When it happens

Trigger: A selected source's fetched manifest lacks one or more assets in the `requiredAssets` list — typically a partial or stale SHA256SUMS on a custom mirror, or a new asset added by the installer that an older mirror's manifest predates.

Common situations: Third-party CODEWHALE_RELEASE_BASE_URL mirrors that only republish a subset of assets; installer upgraded to require a new platform artifact the mirror has never hosted; locked/pinned manifest older than the current release's asset set.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/b6c8f57840113112. Report an issue: GitHub.

Appendix: source

Thrown at npm/codewhale/scripts/install.js:1224

    `version=${version}`,
    "",
  ].join("\n");
}

async function writeSourceReceipt(targetPath, source, version) {
  await writeFile(`${targetPath}.source`, formatSourceReceipt(source, version), "utf8");
}

function assertManifestHasAssets(checksums, requiredAssets, label) {
  const missing = [];
  for (let i = 0; i < requiredAssets.length; i += 1) {
    const asset = requiredAssets[i];
    if (!checksums.has(asset)) {
      missing.push(asset);
    }
  }
  if (missing.length > 0) {
    throw new NonRetryableError(
      `${label} checksum manifest is missing ${missing.join(", ")}`,
    );
  }
}

async function fetchChecksumManifest(url, options) {
  const fetchText = options.fetchText || downloadText;
  const text = await fetchText(url, {
    context: options.context,
    signal: options.signal,
    totalTimeoutMs:
      options.totalTimeoutMs === undefined || options.totalTimeoutMs === null
        ? MANIFEST_TIMEOUT_MS
        : options.totalTimeoutMs,
    stallMs:
      options.stallMs === undefined || options.stallMs === null
        ? MANIFEST_STALL_MS
        : options.stallMs,

View on GitHub (pinned to 433685b202)