{"record":{"id":"14953cc4a18158fc","repo":"hashicorp/terraform","slug":"checksum-list-has-unexpected-sha-256-hash-x-expe","errorCode":null,"errorMessage":"checksum list has unexpected SHA-256 hash %x (expected %x)","messagePattern":"checksum list has unexpected SHA-256 hash %x \\(expected %x\\)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":372,"sourceCode":"\t\tparts := bytes.Fields(line)\n\t\tif len(parts) > 1 && bytes.Equal(parts[1], filename) {\n\t\t\tchecksum = parts[0]\n\t\t\tbreak\n\t\t}\n\t}\n\tif checksum == nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has no SHA-256 hash for %q\", m.Filename)\n\t}\n\n\t// Decode the ASCII checksum into a byte array for comparison.\n\tvar gotSHA256Sum [sha256.Size]byte\n\tif _, err := hex.Decode(gotSHA256Sum[:], checksum); err != nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has invalid SHA256 hash %q: %s\", string(checksum), err)\n\t}\n\n\t// If the checksums don't match, authentication fails.\n\tif !bytes.Equal(gotSHA256Sum[:], m.WantSHA256Sum[:]) {\n\t\treturn nil, fmt.Errorf(\"checksum list has unexpected SHA-256 hash %x (expected %x)\", gotSHA256Sum, m.WantSHA256Sum[:])\n\t}\n\n\t// Success! But this doesn't result in any real authentication, only a\n\t// lack of authentication errors, so we return a nil result.\n\treturn nil, nil\n}\n\ntype signatureAuthentication struct {\n\tDocument  []byte\n\tSignature []byte\n\tKeys      []SigningKey\n}\n\n// NewSignatureAuthentication returns a PackageAuthentication implementation\n// that verifies the cryptographic signature for a package against any of the\n// provided keys.\n//\n// The signing key for a package will be auto detected by attempting each key","sourceCodeStart":354,"sourceCodeEnd":390,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L354-L390","documentation":"Thrown by matchingChecksumAuthentication.AuthenticatePackage when the line for m.Filename is found and decodes to a valid 32-byte SHA-256, but that hash does not equal m.WantSHA256Sum. This is a positive mismatch: the signed sums document asserts a hash that differs from what the caller expected for the package. Checked at package_authentication.go:370-372.","triggerScenarios":"NewMatchingChecksumAuthentication where wantSHA256Sum was computed/declared for different bytes than the registry's signed sums document lists. E.g. the package metadata's declared SHA-256 and the signed sums document disagree about the same filename.","commonSituations":"Provider repacked after the metadata hash was computed; mismatch between the package-metadata declared hash and the registry sums document (registry bug or stale cache); a mirror with an inconsistent sums document vs. metadata; tampering where one of the two values was altered.","solutions":["Re-fetch both the package metadata and the signed sums document from the origin registry so they are from the same release state.","Confirm wantSHA256Sum passed to NewMatchingChecksumAuthentication comes from the same source/version as the sums document.","If both originate from the same registry and still disagree, report it as a registry inconsistency — do not weaken verification.","Clear any intermediary caches (mirror, CDN, CI cache) that could serve stale metadata or sums."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"checksum list has unexpected SHA-256 hash\") {\n    // metadata hash and signed sums disagree: re-fetch both from origin\n    return result, err\n}","preventionTips":["Source the package metadata hash and the signed sums document from the same release state.","Clear mirror/CDN caches that may serve inconsistent metadata+sums.","Report persistent registry inconsistencies rather than disabling the check."],"tags":["authentication","checksum","sha256sums","tampering","registry"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}