{"record":{"id":"5fe39f44e9b839b7","repo":"hashicorp/terraform","slug":"this-version-of-terraform-does-not-support-any-of","errorCode":null,"errorMessage":"this version of Terraform does not support any of the checksum formats given for this provider","messagePattern":"this version of Terraform does not support any of the checksum formats given for this provider","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":247,"sourceCode":"// This uses the hash algorithms implemented by functions PackageHash and\n// MatchesHash. The PreferredHashes function will select which of the given\n// hashes are considered by Terraform to be the strongest verification, and\n// authentication succeeds as long as one of those matches.\nfunc NewPackageHashAuthentication(platform Platform, validHashes []Hash) PackageAuthentication {\n\trequiredHashes := PreferredHashes(validHashes)\n\treturn packageHashAuthentication{\n\t\tRequiredHashes: requiredHashes,\n\t\tAllHashes:      validHashes,\n\t\tPlatform:       platform,\n\t}\n}\n\nfunc (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tif len(a.RequiredHashes) == 0 {\n\t\t// Indicates that none of the hashes given to\n\t\t// NewPackageHashAuthentication were considered to be usable by this\n\t\t// version of Terraform.\n\t\treturn nil, fmt.Errorf(\"this version of Terraform does not support any of the checksum formats given for this provider\")\n\t}\n\n\tmatches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to verify provider package checksums: %s\", err)\n\t}\n\n\tif matches {\n\t\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n\t}\n\tif len(a.RequiredHashes) == 1 {\n\t\treturn nil, fmt.Errorf(\"provider package doesn't match the expected checksum %q\", a.RequiredHashes[0].String())\n\t}\n\t// It's non-ideal that this doesn't actually list the expected checksums,\n\t// but in the many-checksum case the message would get pretty unweildy.\n\t// In practice today we typically use this authenticator only with a\n\t// single hash returned from a network mirror, so the better message\n\t// above will prevail in that case. Maybe we'll improve on this somehow","sourceCodeStart":229,"sourceCodeEnd":265,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L229-L265","documentation":"Thrown by packageHashAuthentication.AuthenticatePackage when RequiredHashes is empty, meaning PreferredHashes filtered the supplied validHashes down to zero hashes this build recognizes. The constructor NewPackageHashAuthentication(platform, validHashes) keeps hashes the current Terraform/OpenTofu supports; if none of the lock-file/registry hashes match a known scheme (e.g. only 'h1:' hashes are present but this code path expected 'zh:', or vice-versa, or the hashes are malformed), authentication cannot proceed.","triggerScenarios":"Calling NewPackageHashAuthentication with a hash set whose every entry uses a scheme PreferredHashes drops, then AuthenticatePackage. Common when a lock file from a newer tool version (with a newer hash scheme) is read by an older binary, or when hashes are non-standard/corrupt strings that fail scheme parsing.","commonSituations":"Version skew between team members — one developer upgrades and writes 'zh:' (zip) hashes into .terraform.lock.hcl while another runs an older binary that only understands 'h1:'; a hand-edited lock file with malformed hashes; a custom mirror serving hashes in an unrecognized format.","solutions":["Upgrade the running Terraform/OpenTofu binary to a version that supports the hash scheme present in the lock file.","Delete the hashes block for the affected provider in .terraform.lock.hcl and re-run init to regenerate hashes in a supported scheme.","Ensure the source/mirror provides hashes in a recognized scheme (h1: base64 SHA-256 of unpacked dir, or zh: base64 SHA-256 of the zip).","Align all team members on the same tool version so the lock file uses a single scheme."],"exampleFix":"// before: lock file only has a scheme this binary does not prefer\n//   version = \"5.0.0\"\n//   hashes = [\n//     \"zh:deadbeef...\"\n//   ]\n\n// after: regenerate after `terraform init -upgrade` on a current binary\n//   hashes = [\n//     \"h1:abcdef...=\",\n//     \"zh:deadbeef...\"\n//   ]","handlingStrategy":"validation","validationCode":"// Before constructing NewPackageHashAuthentication, confirm at least one\n// hash survives PreferredHashes for this build.\nimport \"github.com/hashicorp/terraform/internal/getproviders\"\n\nfunc hasRecognizedHash(validHashes []getproviders.Hash) error {\n    if len(getproviders.PreferredHashes(validHashes)) == 0 {\n        return fmt.Errorf(\"no hash in a scheme this build supports; upgrade or regenerate the lock file\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Wrap auth so callers can surface a clearer message and choose to\n// regenerate the lock file rather than abort.\nresult, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"does not support any of the checksum formats\") {\n    log.Printf(\"lock file uses an unsupported hash scheme; run `terraform init -upgrade` to regenerate\")\n}\nreturn result, err","preventionTips":["Keep team tool versions aligned to avoid lock-file scheme drift.","Regenerate the lock file after upgrading the tool.","Ensure mirrors serve at least one of h1: or zh: scheme hashes."],"tags":["authentication","checksum","lock-file","version-skew","hash"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}