{"record":{"id":"580a8393dd238b75","repo":"hashicorp/terraform","slug":"cannot-check-archive-hash-for-non-archive-location","errorCode":null,"errorMessage":"cannot check archive hash for non-archive location %s","messagePattern":"cannot check archive hash for non-archive location (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":306,"sourceCode":"// This authentication is suitable only for PackageHTTPURL and\n// PackageLocalArchive source locations, because the unpacked layout\n// (represented by PackageLocalDir) does not retain access to the original\n// source archive. Therefore this authenticator will return an error if its\n// given localLocation is not PackageLocalArchive.\n//\n// NewPackageHashAuthentication is preferable to use when possible because\n// it uses the newer hashing scheme (implemented by function PackageHash) that\n// can work with both packed and unpacked provider packages.\nfunc NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {\n\treturn archiveHashAuthentication{platform, wantSHA256Sum}\n}\n\nfunc (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tarchiveLocation, ok := localLocation.(PackageLocalArchive)\n\tif !ok {\n\t\t// A source should not use this authentication type for non-archive\n\t\t// locations.\n\t\treturn nil, fmt.Errorf(\"cannot check archive hash for non-archive location %s\", localLocation)\n\t}\n\n\tgotHash, err := PackageHashLegacyZipSHA(archiveLocation)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to compute checksum for %s: %s\", archiveLocation, err)\n\t}\n\twantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)\n\tif gotHash != wantHash {\n\t\treturn nil, fmt.Errorf(\"archive has incorrect checksum %s (expected %s)\", gotHash, wantHash)\n\t}\n\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n}\n\nfunc (a archiveHashAuthentication) AcceptableHashes() []Hash {\n\treturn []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}\n}\n\ntype matchingChecksumAuthentication struct {","sourceCodeStart":288,"sourceCodeEnd":324,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L288-L324","documentation":"Thrown by archiveHashAuthentication.AuthenticatePackage when the supplied localLocation is not a PackageLocalArchive. This authenticator (NewArchiveChecksumAuthentication) only works on a packaged archive file because it computes the legacy zip SHA-256 over the archive bytes; an unpacked directory (PackageLocalDir) or any other location type is rejected at package_authentication.go:302-306. The doc on the constructor explicitly states this authenticator is unsuitable for unpacked layouts.","triggerScenarios":"Constructing NewArchiveChecksumAuthentication and calling AuthenticatePackage on a PackageLocalDir (unpacked provider), a PackageHTTPURL, or any location that does not type-assert to PackageLocalArchive. Happens when a source stages providers unpacked but the auth chain still includes the archive authenticator.","commonSituations":"Switching a source from archive-based to unpacked-dir staging without updating the authenticator; building a custom source/mirror that unpacks for inspection then tries archive auth; mixing NewArchiveChecksumAuthentication with NewPackageHashAuthentication and applying it to a dir.","solutions":["Use NewPackageHashAuthentication instead — it works on both packed archives and unpacked directories via the newer PackageHash scheme.","Ensure the source stages the provider as a PackageLocalArchive (keeps the original .zip) before applying archive auth.","Drop archiveHashAuthentication from the auth chain when the location is an unpacked dir."],"exampleFix":"// before\nauth := NewArchiveChecksumAuthentication(platform, wantSHA256Sum)\n// applied to an unpacked PackageLocalDir -> error\n\n// after\nauth := NewPackageHashAuthentication(platform, validHashes)\n// works for PackageLocalArchive and PackageLocalDir","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"// Guard the location type before applying archive auth.\nfunc isArchiveLocation(loc getproviders.PackageLocation) bool {\n    _, ok := loc.(getproviders.PackageLocalArchive)\n    return ok\n}\n\n// usage:\n// if !isArchiveLocation(loc) {\n//     auth = getproviders.NewPackageHashAuthentication(platform, hashes)\n// }","tryCatchPattern":null,"preventionTips":["Prefer NewPackageHashAuthentication — it works on archives and unpacked dirs.","Only attach NewArchiveChecksumAuthentication when the source keeps the original archive.","Type-assert the location before choosing an authenticator."],"tags":["authentication","archive","checksum","type-guard","package-location"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}