{"record":{"id":"0d7fd4470e05017d","repo":"BoundaryML/baml","slug":"invalid-checksum-format-s-for-s-in-s","errorCode":null,"errorMessage":"invalid checksum format '%s' for %s in %s","messagePattern":"invalid checksum format '(.+?)' for (.+?) in (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"engine/language_client_go/baml_go/lib_common.go","lineNumber":611,"sourceCode":"\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"error reading checksum body %s: %w\", checksumURL, err)\n\t}\n\n\tlines := strings.Split(string(bodyBytes), \"\\n\")\n\tfor _, line := range lines {\n\t\tparts := strings.Fields(line)\n\t\tif len(parts) >= 2 {\n\t\t\tchecksum, filenameInLine := parts[0], strings.TrimPrefix(parts[1], \"*\")\n\t\t\tif filenameInLine == targetFilename {\n\t\t\t\tif len(checksum) == 64 && isHex(checksum) {\n\t\t\t\t\tlogger.Debug(\"Found matching checksum in file\", \"filename\", targetFilename, \"checksum\", checksum)\n\t\t\t\t\treturn checksum, nil\n\t\t\t\t}\n\t\t\t\tlogger.Warn(\"Invalid checksum format found in checksum file\",\n\t\t\t\t\t\"url\", checksumURL,\n\t\t\t\t\t\"filename\", targetFilename,\n\t\t\t\t\t\"found_checksum\", checksum)\n\t\t\t\treturn \"\", fmt.Errorf(\"invalid checksum format '%s' for %s in %s\", checksum, targetFilename, checksumURL)\n\t\t\t}\n\t\t}\n\t}\n\n\tlogger.Warn(\"Checksum for target file not found within checksum file\",\n\t\t\"url\", checksumURL,\n\t\t\"target_filename\", targetFilename)\n\treturn \"\", fmt.Errorf(\"checksum for '%s' not found within file %s\", targetFilename, checksumURL)\n}\n\nfunc isHex(s string) bool {\n\tif len(s) == 0 {\n\t\treturn false\n\t}\n\tfor _, r := range s {\n\t\tif !((r >= '0' && r <= '9') || (r >= 'a' && r <= 'f') || (r >= 'A' && r <= 'F')) {\n\t\t\treturn false\n\t\t}","sourceCodeStart":593,"sourceCodeEnd":629,"githubUrl":"https://github.com/BoundaryML/baml/blob/bd85ce9dee1463ff04d27efd20531013a4ff46c1/engine/language_client_go/baml_go/lib_common.go#L593-L629","documentation":"A line in the checksum file matched the target filename, but the extracted checksum string failed the isHex validation (non-empty, even-length, hex characters). The file contents are malformed, so downloadChecksum refuses to return an untrustworthy value.","triggerScenarios":"The checksum file contains a line whose second field for targetFilename is not a valid hex hash — e.g. 'sha256' prefixed column, a text placeholder, or a truncated/garbage hash.","commonSituations":"Checksum file generated by a tool with a different format (e.g. '<hash>  <file>' vs '<file>:<hash>' parsed incorrectly), a partially written checksum file, or an HTML error page saved as .sha256.","solutions":["Inspect the checksum file at checksumURL and confirm its format matches '<hex> <filename>'","Regenerate/publish the checksum file with sha256sum output format","If a mirror serves an HTML error page, fix the mirror or use the canonical URL","Update library code if upstream changed the checksum file format"],"exampleFix":"// before: mismatched checksum file format\nmyfile.bin:e3b0c442...   // parsed field fails isHex\n// after: publish standard format\ne3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  myfile.bin","handlingStrategy":"validation","validationCode":"func validChecksumLine(line string) bool {\n    f := strings.Fields(line)\n    return len(f) >= 2 && len(f[0])%2 == 0 && isHexString(f[0])\n}","typeGuard":"func isHexChecksum(s string) bool {\n    if len(s) == 0 || len(s)%2 != 0 { return false }\n    _, err := hex.DecodeString(s)\n    return err == nil\n}","tryCatchPattern":"if _, err := downloadChecksum(url, name); err != nil && strings.Contains(err.Error(), \"invalid checksum format\") {\n    logger.Warn(\"malformed checksum file; skipping verification\", \"url\", url)\n}","preventionTips":["Publish checksum files in standard sha256sum output format ('<hex>  <file>')","Never hand-edit checksum files; generate with sha256sum","Verify mirrors serve raw text, not HTML error pages","Keep checksum generation in the release pipeline, consistent across versions"],"tags":["checksum","format","validation","integrity"],"backgroundTag":"invalid-argument-format","analyzedSha":"bd85ce9dee1463ff04d27efd20531013a4ff46c1","analyzedAt":"2026-09-12T03:38:25.718Z","contentChangedAt":"2026-09-12T03:38:25.718Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}