Hmbown/CodeWhale · error · Error

contains an invalid checksum row

Error message

${label} contains an invalid checksum row: ${trimmed}

What it means

parseChecksumManifest parses a SHA256SUMS-style file where each non-empty line must match /^([a-fA-F0-9]{64})\s+\*?(.+)$/. A line that does not contain a 64-hex-digit digest followed by a filename causes this Error naming the manifest and the offending line.

Solutions

  1. Regenerate the manifest with `sha256sum *` (or an equivalent 64-hex digest) so every line matches the expected format.
  2. Open the manifest, find the line printed in the message, and fix or delete it.
  3. Remove stray non-checksum lines (headers, notes) from the file.

Example fix

// before (manifest line)
ad3f...  app.zip  (short digest)
// after
sha256sum app.zip > SHA256SUMS
Defensive patterns

Strategy: validation

Validate before calling

// validate each manifest line before handing the file to the script
const ok = text.split('\n').every(l => { const t = l.trim(); return !t || /^[a-fA-F0-9]{64}\s+\*?.+$/.test(t); });
if (!ok) throw new Error('SHA256SUMS has malformed rows');

Try / catch

try { await checksums(manifestPath); } catch (e) { if (String(e.message).includes('invalid checksum row')) { console.error('Fix or regenerate SHA256SUMS:', e.message); process.exitCode = 1; } else throw e; }

Prevention

When it happens

Trigger: A checksums file line with a truncated digest (e.g. 32 hex chars), a digest containing non-hex characters (g-z), missing whitespace between digest and filename, an empty filename, or an accidental non-checksum line (a header or prose) in the manifest.

Common situations: Hand-edited SHA256SUMS files, manifests generated by non-sha256sum tools (e.g. md5 digests), or copy-paste introducing wrapped/truncated lines.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/3276e02700dbf626. Report an issue: GitHub.

Appendix: source

Thrown at scripts/release/assemble-release-assets.js:40

  ].join("\n");
}

async function sha256(filePath) {
  const hash = crypto.createHash("sha256");
  hash.update(await fs.readFile(filePath));
  return hash.digest("hex");
}

function parseChecksumManifest(content, label) {
  const checksums = new Map();
  for (const line of content.split(/\r?\n/)) {
    const trimmed = line.trim();
    if (!trimmed) {
      continue;
    }
    const match = trimmed.match(/^([a-fA-F0-9]{64})\s+\*?(.+)$/);
    if (!match) {
      throw new Error(`${label} contains an invalid checksum row: ${trimmed}`);
    }
    const name = match[2];
    if (checksums.has(name)) {
      throw new Error(`${label} contains duplicate checksum rows for ${name}`);
    }
    checksums.set(name, match[1].toLowerCase());
  }
  return checksums;
}

function assertExactNames(actualNames, expectedNames, label) {
  const actual = new Set(actualNames);
  const expected = new Set(expectedNames);
  const missing = expectedNames.filter((name) => !actual.has(name));
  const unexpected = actualNames.filter((name) => !expected.has(name));
  if (missing.length > 0 || unexpected.length > 0 || actual.size !== actualNames.length) {
    throw new Error(
      `${label} does not match the authoritative inventory` +

View on GitHub (pinned to 433685b202)