{"record":{"id":"622b18df469a2a35","repo":"hashicorp/terraform","slug":"provider-mirror-returned-invalid-provider-hash-q","errorCode":null,"errorMessage":"provider mirror returned invalid provider hash %q: %s","messagePattern":"provider mirror returned invalid provider hash %q: (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/http_mirror_source.go","lineNumber":246,"sourceCode":"\n\tret := PackageMeta{\n\t\tProvider:       provider,\n\t\tVersion:        version,\n\t\tTargetPlatform: target,\n\n\t\tLocation: PackageHTTPURL(absURL.String()),\n\t\tFilename: path.Base(absURL.Path),\n\t}\n\t// A network mirror might not provide any hashes at all, in which case\n\t// the package has no source-defined authentication whatsoever.\n\tif len(archiveMeta.Hashes) > 0 {\n\t\thashes := make([]Hash, 0, len(archiveMeta.Hashes))\n\t\tfor _, hashStr := range archiveMeta.Hashes {\n\t\t\thash, err := ParseHash(hashStr)\n\t\t\tif err != nil {\n\t\t\t\treturn PackageMeta{}, s.errQueryFailed(\n\t\t\t\t\tprovider,\n\t\t\t\t\tfmt.Errorf(\"provider mirror returned invalid provider hash %q: %s\", hashStr, err),\n\t\t\t\t)\n\t\t\t}\n\t\t\thashes = append(hashes, hash)\n\t\t}\n\t\tret.Authentication = NewPackageHashAuthentication(target, hashes)\n\t}\n\n\treturn ret, nil\n}\n\n// ForDisplay returns a string description of the source for user-facing output.\nfunc (s *HTTPMirrorSource) ForDisplay(provider addrs.Provider) string {\n\treturn \"provider mirror at \" + s.baseURL.String()\n}\n\n// ListVersionsResponseBody is the JSON structure of a response when a user queries the available versions\n// for a provider in the network mirror, i.e. a GET to path :hostname/:namespace/:type/index.json\n// See: https://developer.hashicorp.com/terraform/internals/provider-network-mirror-protocol#list-available-versions","sourceCodeStart":228,"sourceCodeEnd":264,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/http_mirror_source.go#L228-L264","documentation":"When the mirror's archive entry includes a `hashes` array, each entry is parsed with `ParseHash`. A single unparseable hash string aborts the whole `PackageMeta` construction with this error naming the bad value.","triggerScenarios":"`ParseHash(hashStr)` returns an error while iterating `archiveMeta.Hashes`; error at http_mirror_source.go:246.","commonSituations":"Mirror emits a typo'd hash (`h1:`, `zh:` prefix wrong, truncated hex); mixed-case or non-base64 payload; legacy non-prefixed SHA that `ParseHash` rejects.","solutions":["Inspect the `hashes` array in the mirror JSON and remove/fix malformed entries.","Regenerate mirror metadata so hashes use `h1:` or `zh:` form.","Omit the `hashes` field entirely if the mirror cannot guarantee validity (the code tolerates absence)."],"exampleFix":"// before\n{\"hashes\":[\"sha256=abcdef\",\"h1:valid...\"]}\n// after\n{\"hashes\":[\"h1:valid...\"]}","handlingStrategy":"validation","validationCode":"// Filter out unparseable hashes before passing them in\nhashes := make([]Hash, 0, len(archiveMeta.Hashes))\nfor _, h := range archiveMeta.Hashes {\n    if parsed, err := ParseHash(h); err == nil {\n        hashes = append(hashes, parsed)\n    } else {\n        log.Printf(\"[WARN] skipping unparseable mirror hash %q: %s\", h, err)\n    }\n}","typeGuard":"// isParsableHash narrows to strings ParseHash accepts\nfunc isParsableHash(s string) bool {\n    _, err := ParseHash(s)\n    return err == nil\n}","tryCatchPattern":"hash, err := ParseHash(hashStr)\nif err != nil {\n    log.Printf(\"[WARN] mirror hash %q invalid: %s; skipping\", hashStr, err)\n    continue\n}","preventionTips":["Generate mirror hashes with the canonical `h1:`/`zh:` tooling.","Strip malformed entries before publishing the index.","Omit `hashes` entirely if validity cannot be guaranteed.","Treat hash parse failures as warnings, not fatal."],"tags":["network","mirror","hash","registry"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}