{"record":{"id":"274079e8d7c7e252","repo":"hashicorp/terraform","slug":"failed-to-verify-checksum-of-s-s-package-cached","errorCode":null,"errorMessage":"failed to verify checksum of %s %s package cached in in %s: %s","messagePattern":"failed to verify checksum of (.+?) (.+?) package cached in in (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/meta_providers.go","lineNumber":413,"sourceCode":"\t\t\t// loops below, for dev overrides etc.\n\t\t\tcontinue\n\t\t}\n\n\t\tversion := lock.Version()\n\t\tcached := cacheDir.ProviderVersion(provider, version)\n\t\tif cached == nil {\n\t\t\treportError(fmt.Errorf(\n\t\t\t\t\"there is no package for %s %s cached in %s\",\n\t\t\t\tprovider, version, cacheDir.BasePath(),\n\t\t\t))\n\t\t\tcontinue\n\t\t}\n\t\t// The cached package must match one of the checksums recorded in\n\t\t// the lock file, if any.\n\t\tif allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {\n\t\t\tmatched, err := cached.MatchesAnyHash(allowedHashes)\n\t\t\tif err != nil {\n\t\t\t\treportError(fmt.Errorf(\n\t\t\t\t\t\"failed to verify checksum of %s %s package cached in in %s: %s\",\n\t\t\t\t\tprovider, version, cacheDir.BasePath(), err,\n\t\t\t\t))\n\t\t\t\tcontinue\n\t\t\t}\n\t\t\tif !matched {\n\t\t\t\treportError(fmt.Errorf(\n\t\t\t\t\t\"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file\",\n\t\t\t\t\tprovider, version, cacheDir.BasePath(),\n\t\t\t\t))\n\t\t\t\tcontinue\n\t\t\t}\n\t\t}\n\t\tfactories[provider] = providerFactory(cached)\n\t}\n\tfor provider, localDir := range devOverrideProviders {\n\t\tfactories[provider] = devOverrideProviderFactory(provider, localDir)\n\t}","sourceCodeStart":395,"sourceCodeEnd":431,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/meta_providers.go#L395-L431","documentation":"After locating a cached provider package, providerFactoriesFromLocks verifies it against lock.PreferredHashes via cached.MatchesAnyHash. If MatchesAnyHash itself returns an error (as opposed to a clean false), the verification could not complete — typically an I/O error reading the package files or computing hashes — and this error is recorded. Note the message contains a typo ('cached in in') in the source.","triggerScenarios":"cached.MatchesAnyHash(allowedHashes) returns a non-nil err while lock.PreferredHashes() is non-empty. Causes include file permission errors reading the unpacked package, missing files inside the package directory, or a hashing algorithm the runtime cannot compute.","commonSituations":"Permissions changed on .terraform/providers after a sudo/role switch; antivirus or container overlay filesystem locking package files; partially-extracted archive left by an interrupted init; filesystem corruption on the cache volume.","solutions":["Inspect the trailing %s (the inner err) for the exact I/O or hash failure, then fix that root cause (permissions, disk space).","Remove the affected provider directory under .terraform/providers/<provider>/<version>/ and re-run terraform init to re-extract cleanly.","Ensure the user running Terraform owns and can read the entire cache tree (chown -R if needed).","If TF_PLUGIN_CACHE_DIR is on a network/overlay share, move it to a local fast volume."],"exampleFix":"# before: hash verification I/O error\n# after: clear and re-fetch\nrm -rf .terraform/providers/registry.terraform.io/hashicorp/aws/5.0.1\nterraform init","handlingStrategy":"retry","validationCode":"// Pre-check readability of the package dir before Terraform verifies hashes.\ninfo, err := os.Stat(pkgDir)\nif err != nil || !info.IsDir() {\n    return fmt.Errorf(\"provider package unreadable at %s: %w\", pkgDir, err)\n}","typeGuard":null,"tryCatchPattern":"// Transient I/O hash errors are often resolved by re-fetching once.\nif errors.Is(err, syscall.EIO) || strings.Contains(err.Error(), \"hash\") {\n    _ = os.RemoveAll(pkgDir)\n    return runTerraform(\"init\") // single retry after clearing\n}","preventionTips":["Keep the cache on a reliable local filesystem, not a flaky network mount.","Avoid running Terraform as different users against the same cache (permissions drift).","Periodically verify cache integrity in CI."],"tags":["terraform","provider","checksum","cache","io","lock-file"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}