{"record":{"id":"001ddf98a4c32ad1","repo":"Hmbown/CodeWhale","slug":"checksum-mismatch-for-assetname-from-expected-expected-got","errorCode":null,"errorMessage":"Checksum mismatch for ${assetName}${from}: expected ${expected}, got ${actual}","messagePattern":"Checksum mismatch for (.+?)(.+?): expected (.+?), got (.+?)","errorType":"exception","errorClass":"NonRetryableError","httpStatus":null,"severity":"critical","filePath":"npm/codewhale/scripts/install.js","lineNumber":1186,"sourceCode":"\nasync function sha256File(filePath) {\n  const content = await readFile(filePath);\n  return crypto.createHash(\"sha256\").update(content).digest(\"hex\");\n}\n\nasync function verifyChecksum(filePath, assetName, checksums, sourceLabel) {\n  const expected = checksums.get(assetName);\n  if (!expected) {\n    const from = sourceLabel ? ` from ${sourceLabel}` : \"\";\n    throw new NonRetryableError(`Checksum manifest is missing ${assetName}${from}`);\n  }\n  const actual = await sha256File(filePath);\n  if (actual !== expected) {\n    // Bytes are corrupted; another fetch is unlikely to help without a fix\n    // upstream. Mark non-retryable. Never mix a locked source's bytes with\n    // another source's manifest.\n    const from = sourceLabel ? ` from ${sourceLabel}` : \"\";\n    throw new NonRetryableError(\n      `Checksum mismatch for ${assetName}${from}: expected ${expected}, got ${actual}`,\n    );\n  }\n}\n\nasync function checksumMatches(filePath, assetName, checksums) {\n  const expected = checksums.get(assetName);\n  if (!expected) {\n    throw new NonRetryableError(`Checksum manifest is missing ${assetName}`);\n  }\n  const actual = await sha256File(filePath);\n  return actual === expected;\n}\n\nfunction formatSourceReceipt(source, version) {\n  return [\n    `source=${source.id}`,\n    `label=${source.label}`,","sourceCodeStart":1168,"sourceCodeEnd":1204,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/npm/codewhale/scripts/install.js#L1168-L1204","documentation":"After hashing the downloaded file, `verifyChecksum` compares the actual SHA-256 with the digest from the manifest. A mismatch means the bytes on disk differ from the published artifact — the download was corrupted, truncated, or tampered with — so the installer throws a NonRetryableError and explicitly refuses to retry, since re-fetching from the same broken source will not fix it.","triggerScenarios":"sha256File(filePath) != checksums.get(assetName) after a completed download from the release/mirror source identified by sourceLabel.","commonSituations":"Flaky network or proxy truncating large tarballs; a mirror serving stale or re-uploaded (bit-different) artifacts; CDN cache poisoning; disk corruption; interrupted write not caught by size checks.","solutions":["Delete the cached/partial download and retry from a different network (the error is non-retryable by design, so change the source, not just re-run).","Switch to the official GitHub Release source (unset CODEWHALE_RELEASE_BASE_URL / CODEWHALE_USE_CNB_MIRROR).","Compare the file's sha256 manually (`sha256sum <file>`) against the manifest and re-download the asset.","If you operate the mirror, restore the exact published artifact bytes that match SHA256SUMS.","Check proxy/AV software that may rewrite downloaded binaries."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await install();\n} catch (err) {\n  if (err.message.startsWith('Checksum mismatch for')) {\n    // non-retryable by design: change source/network, purge cache, then retry once\n    await purgeCache();\n    await install({ source: 'official' });\n  } else throw err;\n}","preventionTips":["Download over stable networks; avoid flaky proxies for large artifacts.","Always verify checksums — never bypass the installer's verification.","Prefer official release sources over third-party mirrors that may re-upload artifacts.","Exclude installer downloads from AV/proxy rewriting."],"tags":["npm","installer","checksum","integrity","download","security"],"backgroundTag":"checksum-mismatch","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}