{"record":{"id":"1c5c2c5d6bddad22","repo":"siyuan-note/siyuan","slug":"w-s-checksum-is-unavailable","errorCode":null,"errorMessage":"%w: [%s] checksum is unavailable","messagePattern":"%w: \\[(.+?)\\] checksum is unavailable","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"kernel/model/updater.go","lineNumber":128,"sourceCode":"\t}\n\n\tif isVersionUpToDate(release.Version) {\n\t\terr = fmt.Errorf(\"version is up to date\")\n\t\treturn\n\t}\n\n\tpkgName := currentInstallPackageName(release.Version)\n\tif \"\" == pkgName {\n\t\terr = fmt.Errorf(\"%w for the current platform\", errUpdatePackageUnavailable)\n\t\treturn\n\t}\n\tpkg := release.Packages[pkgName]\n\tif nil == pkg || 0 == len(pkg.URLs) {\n\t\terr = fmt.Errorf(\"%w: [%s]\", errUpdatePackageUnavailable, pkgName)\n\t\treturn\n\t}\n\tif \"\" == pkg.Checksum {\n\t\terr = fmt.Errorf(\"%w: [%s] checksum is unavailable\", errUpdatePackageUnavailable, pkgName)\n\t\treturn\n\t}\n\tdownloadPkgURLs = append(downloadPkgURLs, pkg.URLs...)\n\tchecksum = pkg.Checksum\n\treturn\n}\n\nfunc downloadInstallPkg(pkgURL, checksum string) (err error) {\n\tif \"\" == pkgURL || \"\" == checksum {\n\t\terr = errors.New(\"update package URL or checksum is empty\")\n\t\treturn\n\t}\n\n\tpkg := path.Base(pkgURL)\n\tsavePath := filepath.Join(util.TempDir, \"install\", pkg)\n\tif gulu.File.IsExist(savePath) {\n\t\tlocalChecksum, _ := sha256Hash(savePath)\n\t\tif localChecksum == checksum {","sourceCodeStart":110,"sourceCodeEnd":146,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/updater.go#L110-L146","documentation":"getUpdatePkg wraps errUpdatePackageUnavailable with '%w: [pkgName] checksum is unavailable' when the release entry for the package exists and has URLs, but its Checksum field is empty. The updater refuses to download without a checksum because it verifies integrity after download.","triggerScenarios":"An update check reaches the download step while the release metadata's checksum for your platform's package is missing (publish pipeline didn't attach it, or metadata format changed).","commonSituations":"A newly published release where checksum entries were not uploaded yet; a manually edited/malformed release metadata file; custom update mirrors that strip checksum fields.","solutions":["Wait and retry the update check until the release publisher attaches checksums","Download the package manually and verify its SHA-256 yourself","If you operate the release pipeline, ensure every package entry includes its checksum","Use errors.Is(err, errUpdatePackageUnavailable) to fall back to a manual-update notification"],"exampleFix":null,"handlingStrategy":"fallback","validationCode":"const pkg = release.packages[pkgName]; const hasChecksum = !!pkg && !!pkg.checksum; if (!hasChecksum) requireManualVerification()","typeGuard":"func isChecksumMissing(err error) bool { return errors.Is(err, errUpdatePackageUnavailable) }","tryCatchPattern":"if errors.Is(err, errUpdatePackageUnavailable) {\n    pushManualDownloadNotification(release) // 提示自行校验 SHA-256\n    return\n}","preventionTips":["Ensure the release pipeline attaches a checksum for every package","If operating a mirror, preserve checksum metadata","Fall back to manual download with user-side SHA-256 verification"],"tags":["go","updater","checksum"],"backgroundTag":"checksum-mismatch","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}