{"record":{"id":"5e61c5bb4a7b223d","repo":"jdx/mise","slug":"could-not-resolve-the-configured-checksum-for-on","errorCode":null,"errorMessage":"could not resolve the configured checksum for {} on {}","messagePattern":"could not resolve the configured checksum for (.+?) on (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/backend/http.rs","lineNumber":1173,"sourceCode":"        // entry that is miscounted as a successful platform (see #7113).\n        let Some(url) = self.lock_url_for_target(&opts, tv, target) else {\n            return Err(crate::errors::Error::UnsupportedTarget(format!(\n                \"no URL configured for {} on {}; skipping\",\n                self.ba.full(),\n                target.to_key()\n            ))\n            .into());\n        };\n\n        let checksum = self.resolve_lock_checksum(&opts, tv, target, &url).await;\n\n        // A checksum source was configured but produced nothing for this target\n        // (manifest miss, SHASUMS naming mismatch, unreachable file, ...). The\n        // url-only entry is still written, but surface it so it isn't a silent\n        // drop of checksum verification.\n        if checksum.is_none() && opts.checksum_url_for_target(target).is_some() {\n            if Settings::get().generate_lockfiles() {\n                eyre::bail!(\n                    \"could not resolve the configured checksum for {} on {}\",\n                    self.ba.full(),\n                    target.to_key()\n                );\n            }\n            warn!(\n                \"could not resolve a checksum for {} on {}; locking the URL without checksum verification\",\n                self.ba.full(),\n                target.to_key()\n            );\n        }\n\n        Ok(PlatformInfo {\n            url: Some(url),\n            checksum,\n            ..Default::default()\n        })\n    }","sourceCodeStart":1155,"sourceCodeEnd":1191,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/backend/http.rs#L1155-L1191","documentation":"An HTTP-backend checksum source was configured (checksum URL/manifest) but produced no checksum for this specific platform target. When lockfile generation is enabled, mise treats this as a hard error rather than silently writing an unverified url-only lockfile entry, because the resulting lockfile could not pin integrity for that artifact.","triggerScenarios":"Installing an HTTP-backend tool where opts.checksum_url_for_target(target) returns Some but resolution yields checksum == None (manifest lacks the target's filename, SHASUMS naming mismatch, checksum file unreachable), with generate_lockfiles enabled.","commonSituations":"Upstream publishes SHASUMS files that don't include this platform's asset name; checksum_file pattern doesn't match the asset; checksum host is down or URL changed.","solutions":["Fix the checksum_file/checksum_url pattern so it matches the target asset's name in the manifest","Verify the checksum URL is reachable and lists an entry for this platform's artifact","Disable generate_lockfiles (or set lockfile=false) if you accept an unverified url-only entry — note the warning this emits"],"exampleFix":"// before (mise.toml)\nchecksum_file = \"SHA256SUMS\"   # asset missing from this file\n// after\nchecksum_file = \"SHA256SUMS-linux-x64\"  # or pattern matching the target asset","handlingStrategy":"validation","validationCode":"// bash: confirm the checksum manifest actually lists the target asset before install\ncurl -fsSL \"$CHECKSUM_URL\" | grep -q \"${ASSET_NAME}$\" || { echo 'checksum manifest missing asset'; exit 1; }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify the checksum_file/checksum_url pattern matches every platform's asset name","Test installs on all target platforms, not just the one used to author the config","Monitor checksum-host availability; prefer checksum files bundled in the release"],"tags":["checksum","http-backend","lockfile","config"],"backgroundTag":"unresolved-checksum-source","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}