{"record":{"id":"2dd48caf6e827b78","repo":"siyuan-note/siyuan","slug":"checksum-manifest-is-unavailable","errorCode":null,"errorMessage":"checksum manifest is unavailable","messagePattern":"checksum manifest is unavailable","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"kernel/model/updater_release.go","lineNumber":366,"sourceCode":"\t\t\treturn \"\"\n\t\t}\n\t}\n\treturn \"\"\n}\n\nfunc findGitHubReleaseAsset(release *githubRelease, name string) *githubReleaseAsset {\n\tfor _, asset := range release.Assets {\n\t\tif nil != asset && name == asset.Name {\n\t\t\treturn asset\n\t\t}\n\t}\n\treturn nil\n}\n\nfunc getGitHubManifestChecksum(ctx context.Context, release *githubRelease, pkgName string) (string, error) {\n\tmanifestAsset := findGitHubReleaseAsset(release, \"SHA256SUMS.txt\")\n\tif nil == manifestAsset || \"uploaded\" != manifestAsset.State || \"\" == manifestAsset.BrowserDownloadURL {\n\t\treturn \"\", errors.New(\"checksum manifest is unavailable\")\n\t}\n\tmanifestDigest := normalizeSHA256(manifestAsset.Digest)\n\tmanifestCacheKey := \"\"\n\tif \"\" != manifestDigest {\n\t\tmanifestCacheKey = manifestAsset.BrowserDownloadURL + \"#\" + manifestDigest\n\t}\n\tif \"\" != manifestCacheKey {\n\t\tcached, ok := githubManifestCache.Load(manifestCacheKey)\n\t\tif ok {\n\t\t\tif checksum := parseChecksumManifest(cached.(string), pkgName); \"\" != checksum {\n\t\t\t\treturn checksum, nil\n\t\t\t}\n\t\t\treturn \"\", errors.New(\"package checksum is unavailable\")\n\t\t}\n\t}\n\n\tresponse, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)\n\tif err != nil {","sourceCodeStart":348,"sourceCodeEnd":384,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/updater_release.go#L348-L384","documentation":"getGitHubManifestChecksum locates the SHA256SUMS.txt asset on the selected GitHub release and requires it to exist, be in 'uploaded' state, and have a browser download URL. If the manifest asset is missing, still 'uploading', or lacks a URL, it cannot verify the package checksum and returns this error. The caller (getGitHubUpdateRelease) logs a warning and degrades gracefully — the release is still returned without a checksum.","triggerScenarios":"Update check on a non-stable channel when the selected release lacks a SHA256SUMS.txt asset entirely, the asset's API state is not 'uploaded' (e.g. 'started' during publish), or browser_download_url is empty.","commonSituations":"Checking for updates seconds/minutes after a new release is published while GitHub is still uploading assets; maintainer forgot to attach SHA256SUMS.txt; GitHub asset upload partially failed.","solutions":["Wait a few minutes and retry the update check until the release's assets finish uploading (state becomes 'uploaded')","Verify on the GitHub release page that SHA256SUMS.txt is attached; if missing, await a maintainer fix or download the installer manually without checksum verification","If asset.Digest (sha256 of the package) is present on the package asset, the manifest path is skipped entirely — newer releases with digests avoid this error","This is non-fatal in-kernel: the update flow continues with no checksum, but manual verification is recommended before installing"],"exampleFix":null,"handlingStrategy":"fallback","validationCode":"asset := findGitHubReleaseAsset(release, \"SHA256SUMS.txt\")\nmanifestReady := asset != nil && asset.State == \"uploaded\" && asset.BrowserDownloadURL != \"\"","typeGuard":"func manifestReady(a *githubReleaseAsset) bool {\n    return a != nil && a.State == \"uploaded\" && a.BrowserDownloadURL != \"\"\n}","tryCatchPattern":"checksum, err := getGitHubManifestChecksum(ctx, release, pkg)\nif err != nil {\n    logging.LogWarnf(\"checksum unavailable: %s\", err) // proceed without checksum, as getGitHubUpdateRelease does\n}","preventionTips":["Wait a few minutes after a release announcement before checking updates so assets finish uploading","Prefer releases whose package assets carry a digest field; they skip the manifest path entirely","Never auto-install with an empty checksum; prompt the user to verify manually","Check the release page lists SHA256SUMS.txt before automating installs"],"tags":["github-api","checksum","release-assets"],"backgroundTag":"resource-not-found","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}