{"record":{"id":"3cb0c8bd18012840","repo":"hashicorp/terraform","slug":"checksum-list-has-invalid-sha256-hash-q-s","errorCode":null,"errorMessage":"checksum list has invalid SHA256 hash %q: %s","messagePattern":"checksum list has invalid SHA256 hash %q: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":367,"sourceCode":"\t// Find the checksum in the list with matching filename. The document is\n\t// in the form \"0123456789abcdef filename.zip\".\n\tfilename := []byte(m.Filename)\n\tvar checksum []byte\n\tfor _, line := range bytes.Split(m.Document, []byte(\"\\n\")) {\n\t\tparts := bytes.Fields(line)\n\t\tif len(parts) > 1 && bytes.Equal(parts[1], filename) {\n\t\t\tchecksum = parts[0]\n\t\t\tbreak\n\t\t}\n\t}\n\tif checksum == nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has no SHA-256 hash for %q\", m.Filename)\n\t}\n\n\t// Decode the ASCII checksum into a byte array for comparison.\n\tvar gotSHA256Sum [sha256.Size]byte\n\tif _, err := hex.Decode(gotSHA256Sum[:], checksum); err != nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has invalid SHA256 hash %q: %s\", string(checksum), err)\n\t}\n\n\t// If the checksums don't match, authentication fails.\n\tif !bytes.Equal(gotSHA256Sum[:], m.WantSHA256Sum[:]) {\n\t\treturn nil, fmt.Errorf(\"checksum list has unexpected SHA-256 hash %x (expected %x)\", gotSHA256Sum, m.WantSHA256Sum[:])\n\t}\n\n\t// Success! But this doesn't result in any real authentication, only a\n\t// lack of authentication errors, so we return a nil result.\n\treturn nil, nil\n}\n\ntype signatureAuthentication struct {\n\tDocument  []byte\n\tSignature []byte\n\tKeys      []SigningKey\n}\n","sourceCodeStart":349,"sourceCodeEnd":385,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L349-L385","documentation":"Thrown by matchingChecksumAuthentication.AuthenticatePackage when a matching filename line is found but its hash field cannot be hex-decoded into a 32-byte SHA-256. The matched line's first field (checksum) is passed to hex.Decode into gotSHA256Sum; any decode error (non-hex characters, wrong length) is wrapped at package_authentication.go:365-367.","triggerScenarios":"The SHA256SUMS document has a line for m.Filename whose hash field is malformed: not 64 hex chars, contains whitespace/non-hex, or is truncated. A custom registry/mirror emitting a bad sums line, or a document that was edited/corrupted in transit.","commonSituations":"Custom mirror generating sums with a wrong algorithm prefix or uppercase that survived byte-splitting but fails hex.Decode; a sums document corrupted by a proxy/CDN; an MD5 or SHA-1 hash mistakenly placed where a SHA-256 hex string should be (too short).","solutions":["Regenerate the SHA256SUMS document so each hash is exactly 64 lowercase hex characters.","Validate the sums document format server-side: each line is '<64-hex> <filename>'.","Confirm the registry/mirror computes SHA-256 (not MD5/SHA-1/SHA-512) and emits it in hex.","If a proxy rewrites responses, fetch the sums document directly to compare against the origin."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate each hash field in the sums document is 64 lowercase hex chars.\nfunc validateSumsFormat(document []byte) error {\n    for i, line := range bytes.Split(document, []byte(\"\\n\")) {\n        parts := bytes.Fields(line)\n        if len(parts) < 2 { // skip blank/short lines\n            continue\n        }\n        if len(parts[0]) != 64 {\n            return fmt.Errorf(\"line %d: hash %q is not 64 hex chars\", i, string(parts[0]))\n        }\n        if _, err := hex.Decode(make([]byte, 32), parts[0]); err != nil {\n            return fmt.Errorf(\"line %d: invalid hex hash %q: %w\", i, string(parts[0]), err)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Generate SHA256SUMS with sha256sum (or equivalent) emitting 64 lowercase hex chars.","Validate sums documents server-side before serving.","Do not place MD5/SHA-1 hashes in a SHA-256 sums document."],"tags":["authentication","checksum","sha256sums","registry","malformed"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}