{"record":{"id":"36281c8b414772a3","repo":"hashicorp/terraform","slug":"failed-to-open-file-at-v-checksum-mismatch-s","errorCode":null,"errorMessage":"failed to open file at %v: checksum mismatch, %s != %s","messagePattern":"failed to open file at (.+?): checksum mismatch, (.+?) != (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/client.go","lineNumber":219,"sourceCode":"\tchecksum = rsp.Header.Get(\"X-Cos-Meta-Md5\")\n\tlog.Printf(\"[DEBUG] getObject %s: checksum: %s\", cosFile, checksum)\n\tif len(checksum) != 32 {\n\t\terr = fmt.Errorf(\"failed to open file at %v: checksum %s invalid\", cosFile, checksum)\n\t\treturn\n\t}\n\n\texists = true\n\tdata, err = ioutil.ReadAll(rsp.Body)\n\tlog.Printf(\"[DEBUG] getObject %s: data length: %d\", cosFile, len(data))\n\tif err != nil {\n\t\terr = fmt.Errorf(\"failed to open file at %v: %v\", cosFile, err)\n\t\treturn\n\t}\n\n\tcheck := fmt.Sprintf(\"%x\", md5.Sum(data))\n\tlog.Printf(\"[DEBUG] getObject %s: check: %s\", cosFile, check)\n\tif check != checksum {\n\t\terr = fmt.Errorf(\"failed to open file at %v: checksum mismatch, %s != %s\", cosFile, check, checksum)\n\t\treturn\n\t}\n\n\treturn\n}\n\n// putObject put object to remote\nfunc (c *remoteClient) putObject(cosFile string, data []byte) error {\n\topt := &cos.ObjectPutOptions{\n\t\tObjectPutHeaderOptions: &cos.ObjectPutHeaderOptions{\n\t\t\tXCosMetaXXX: &http.Header{\n\t\t\t\t\"X-Cos-Meta-Md5\": []string{fmt.Sprintf(\"%x\", md5.Sum(data))},\n\t\t\t},\n\t\t},\n\t\tACLHeaderOptions: &cos.ACLHeaderOptions{\n\t\t\tXCosACL: c.acl,\n\t\t},\n\t}","sourceCodeStart":201,"sourceCodeEnd":237,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/client.go#L201-L237","documentation":"Emitted by getObject() after a full body read when the MD5 computed from the downloaded bytes does not equal the `X-Cos-Meta-Md5` checksum stored on the object. This is an end-to-end integrity check failure — the data on the wire or at rest does not match what was originally written.","triggerScenarios":"check := hex(md5.Sum(data)) differs from the stored checksum header. Causes: silent corruption over the network (bit flips), a partially-overwritten object, an object that was rewritten with different content but the old metadata header, or a man-in-the-middle altering bytes.","commonSituations":"State object was overwritten out-of-band with new content but the X-Cos-Meta-Md5 header was not updated to match; network appliance mangling payload; rare storage-layer corruption; a botched migration that copied bytes but not metadata.","solutions":["Re-download the object and recompute its MD5 out of band to confirm whether the stored bytes or the header is wrong.","If the bytes are correct but the header is stale, re-upload the state through Terraform (`terraform state push`) so header and body agree.","If the bytes are corrupted, restore from backup or a known-good state file, then push it back through the backend.","Investigate the transport path (proxy, TLS terminator) if corruption recurs."],"exampleFix":"// before: object body and X-Cos-Meta-Md5 disagree after an out-of-band edit\n// after: rewrite the object through the backend so checksum is recomputed\n//   terraform state push terraform.tfstate","handlingStrategy":"validation","validationCode":"// Independently verify object integrity before trusting the state\nfunc verifyObjectIntegrity(ctx context.Context, client *cos.Client, key string) error {\n    rsp, err := client.Object.Get(ctx, key, nil)\n    if err != nil || rsp == nil { return err }\n    defer rsp.Body.Close()\n    stored := rsp.Header.Get(\"X-Cos-Meta-Md5\")\n    data, err := ioutil.ReadAll(rsp.Body)\n    if err != nil { return err }\n    got := fmt.Sprintf(\"%x\", md5.Sum(data))\n    if got != stored {\n        return fmt.Errorf(\"integrity mismatch for %s: body md5 %s != header %s; restore from backup and re-push\", key, got, stored)\n    }\n    return nil\n}","typeGuard":"func integrityOK(storedHeader string, data []byte) bool {\n    return storedHeader == fmt.Sprintf(\"%x\", md5.Sum(data))\n}","tryCatchPattern":"// Treat checksum mismatch as fatal, not retryable — escalating to restore\nif strings.Contains(err.Error(), \"checksum mismatch\") {\n    return fmt.Errorf(\"state object corrupted; restore from backup and terraform state push: %w\", err)\n}","preventionTips":["Always write state through the backend so header and body agree.","When migrating state, push it via `terraform state push` rather than byte-copying objects.","Keep periodic backups of state so corruption is recoverable.","Investigate any proxy or TLS terminator if mismatches recur."],"tags":["terraform","cos","tencent-cloud","data-integrity","md5","corruption","remote-state","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}