{"record":{"id":"1819945c439fb753","repo":"rust-lang/cargo","slug":"failed-to-verify-the-checksum-of-181994","errorCode":null,"errorMessage":"failed to verify the checksum of `{}`","messagePattern":"failed to verify the checksum of `(.+?)`","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/sources/registry/local.rs","lineNumber":196,"sourceCode":"        let path = self.root.join(&pkg.tarball_name()).into_path_unlocked();\n        let mut crate_file = paths::open(&path)?;\n\n        // If we've already got an unpacked version of this crate, then skip the\n        // checksum below as it is in theory already verified.\n        let dst = path.file_stem().unwrap();\n        if self.src_path.join(dst).into_path_unlocked().exists() {\n            return Ok(MaybeLock::Ready(crate_file));\n        }\n\n        if !self.quiet {\n            self.gctx.shell().status(\"Unpacking\", pkg)?;\n        }\n\n        // We don't actually need to download anything per-se, we just need to\n        // verify the checksum matches the .crate file itself.\n        let actual = Sha256::new().update_file(&crate_file)?.finish_hex();\n        if actual != checksum {\n            anyhow::bail!(\"failed to verify the checksum of `{}`\", pkg)\n        }\n\n        crate_file.seek(SeekFrom::Start(0))?;\n\n        Ok(MaybeLock::Ready(crate_file))\n    }\n\n    async fn finish_download(\n        &self,\n        _pkg: PackageId,\n        _checksum: &str,\n        _data: &[u8],\n    ) -> CargoResult<File> {\n        panic!(\"this source doesn't download\")\n    }\n}\n","sourceCodeStart":178,"sourceCodeEnd":213,"githubUrl":"https://github.com/rust-lang/cargo/blob/eb98b54bc9f3c74519f43d066cb3fd02ebc88df0/src/sources/registry/local.rs#L178-L213","documentation":"For a local registry, instead of downloading, Cargo reads the `.crate` file from disk and computes its SHA-256 to compare against the checksum recorded in the index. A mismatch means the on-disk tarball differs from what the index attests — corruption, manual edit, or a desync between index and crate files. Mirrors error 146 but for the local (no-network) path.","triggerScenarios":"`LocalRegistry::download()` computes `Sha256(crate_file)` and it does not equal the `checksum` from the index. Happens when the local `.crate` file was modified, partially written, truncated, or replaced out-of-band with the index left stale.","commonSituations":"Manual replacement of a `.crate` file without updating the index; rsync/copy interrupted leaving a partial file; disk corruption; the local registry was rebuilt but an old crate file was left behind; mismatched index/crate pairs after a partial sync.","solutions":["Re-sync the entire local registry (both `index/` and crate files) from a trusted source.","Remove the offending `.crate` file and re-vendor it so index and crate match.","Verify integrity with `sha256sum <crate>` and compare to the index entry.","Rebuild the local registry with a tool that computes checksums consistently (e.g. `cargo vendor`)."],"exampleFix":"# before: crate file on disk mismatches index\n$ cargo build --registry mylocal\nerror: failed to verify the checksum of `serde v1.0.0`\n\n# after: re-vendor the matching crate\n$ sha256sum /srv/cargo-registry/<dep>/serde-1.0.0.crate   # compare to index\n$ cargo vendor /srv/cargo-registry                       # rebuild consistently","handlingStrategy":"validation","validationCode":"fn verify_local_crate_sha256(crate_path: &Path, expected: &str) -> Result<(), anyhow::Error> {\n    let data = std::fs::read(crate_path)?;\n    use sha2::{Digest, Sha256}; let mut h = Sha256::new(); h.update(&data);\n    if hex::encode(h.finalize()) != expected {\n        anyhow::bail!(\"local crate checksum mismatch: {}\", crate_path.display());\n    }\n    Ok(())\n}","typeGuard":"fn local_crate_checksum_ok(path: &std::path::Path, expected: &str) -> bool {\n    std::fs::read(path).ok().map(|d| {\n        use sha2::{Digest, Sha256}; let mut h = Sha256::new(); h.update(&d);\n        hex::encode(h.finalize()) == expected\n    }).unwrap_or(false)\n}","tryCatchPattern":"if actual != checksum {\n    // re-sync crate file from the trusted source before failing hard\n    resync_local_registry(&self.root)?;\n    return self.download(pkg, checksum); // one retry\n}","preventionTips":["Sync index and crate files together (atomic vendor).","Never edit `.crate` files in a local registry by hand.","Verify checksums after rsync/copy of a local registry.","Rebuild local registries with `cargo vendor` for consistency."],"tags":["cargo","registry","local","checksum","sha256","integrity"],"backgroundTag":null,"analyzedSha":"eb98b54bc9f3c74519f43d066cb3fd02ebc88df0","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}