{"record":{"id":"3b60ca3d6a38b535","repo":"siyuan-note/siyuan","slug":"verify-checksum-failed-download-install-package","errorCode":null,"errorMessage":"verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]","messagePattern":"verify checksum failed, download install package \\[(.+?)\\] checksum \\[(.+?)\\] not equal to downloaded \\[(.+?)\\] checksum \\[(.+?)\\]","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"kernel/model/updater.go","lineNumber":175,"sourceCode":"\tlogging.LogInfof(\"downloading install package [%s]\", pkgURL)\n\tclient := req.C().SetTLSHandshakeTimeout(7 * time.Second).SetTimeout(10 * time.Minute).DisableInsecureSkipVerify().SetUserAgent(util.UserAgent)\n\tcallback := func(info req.DownloadInfo) {\n\t\tprogress := fmt.Sprintf(\"%.2f%%\", float64(info.DownloadedSize)/float64(info.Response.ContentLength)*100.0)\n\t\t// logging.LogDebugf(\"downloading install package [%s %s]\", pkgURL, progress)\n\t\tutil.PushStatusBar(fmt.Sprintf(Conf.Language(133), progress))\n\t}\n\t_, err = client.R().SetOutputFile(savePath).SetDownloadCallbackWithInterval(callback, 1*time.Second).Get(pkgURL)\n\tif err != nil {\n\t\tlogging.LogErrorf(\"download install package [%s] failed: %s\", pkgURL, err)\n\t\tif removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {\n\t\t\tlogging.LogErrorf(\"remove incomplete install package [%s] failed: %s\", savePath, removeErr)\n\t\t}\n\t\treturn\n\t}\n\n\tlocalChecksum, _ := sha256Hash(savePath)\n\tif checksum != localChecksum {\n\t\terr = fmt.Errorf(\"verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]\", pkgURL, checksum, savePath, localChecksum)\n\t\tlogging.LogError(err.Error())\n\t\tif removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {\n\t\t\tlogging.LogErrorf(\"remove invalid install package [%s] failed: %s\", savePath, removeErr)\n\t\t}\n\t\treturn\n\t}\n\tlogging.LogInfof(\"downloaded install package [%s] to [%s]\", pkgURL, savePath)\n\tutil.PushStatusBar(Conf.Language(62))\n\treturn\n}\n\nfunc sha256Hash(filename string) (ret string, err error) {\n\tfile, err := os.Open(filename)\n\tif err != nil {\n\t\treturn\n\t}\n\tdefer file.Close()\n","sourceCodeStart":157,"sourceCodeEnd":193,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/updater.go#L157-L193","documentation":"After downloading an install package, downloadInstallPkg computes the SHA-256 of the saved file and compares it with the checksum published in the release metadata. On mismatch it returns this error, logs it, and deletes the corrupted/tampered download so a bad package is never installed.","triggerScenarios":"A completed download's file hash differs from the release checksum — interrupted/corrupted transfer, a CDN serving a stale or different asset, or the published checksum not matching the uploaded asset.","commonSituations":"Unstable network or proxy truncating large downloads; update mirror out of sync with the release; publisher re-uploading an asset without updating the checksum; disk corruption in the temp directory.","solutions":["Retry the update — the bad file was removed, and a fresh download usually fixes transient corruption","Check network/proxy stability or switch networks for large package downloads","If using a mirror, verify it serves the exact release asset bytes","If it persists, verify the publisher's checksum actually matches the uploaded asset and report the broken release"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"if err := downloadInstallPkg(pkgURL, checksum); err != nil {\n    if strings.Contains(err.Error(), \"verify checksum failed\") {\n        scheduleRetry(15 * time.Minute) // 重新下载\n        return\n    }\n    logging.LogErrorf(\"install package download failed: %s\", err)\n}","preventionTips":["Verify network/proxy stability for large downloads","Compare the downloaded file's SHA-256 with the published checksum manually when a mirror is involved","Keep temp-disk healthy; ensure releases re-publish checksums when assets change"],"tags":["go","updater","checksum","download"],"backgroundTag":"checksum-mismatch","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}