{"record":{"id":"6a633d49206762bf","repo":"hashicorp/terraform","slug":"checksum-list-has-no-sha-256-hash-for-q","errorCode":null,"errorMessage":"checksum list has no SHA-256 hash for %q","messagePattern":"checksum list has no SHA-256 hash for %q","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":361,"sourceCode":"\t\tFilename:      filename,\n\t\tWantSHA256Sum: wantSHA256Sum,\n\t}\n}\n\nfunc (m matchingChecksumAuthentication) AuthenticatePackage(location PackageLocation) (*PackageAuthenticationResult, error) {\n\t// Find the checksum in the list with matching filename. The document is\n\t// in the form \"0123456789abcdef filename.zip\".\n\tfilename := []byte(m.Filename)\n\tvar checksum []byte\n\tfor _, line := range bytes.Split(m.Document, []byte(\"\\n\")) {\n\t\tparts := bytes.Fields(line)\n\t\tif len(parts) > 1 && bytes.Equal(parts[1], filename) {\n\t\t\tchecksum = parts[0]\n\t\t\tbreak\n\t\t}\n\t}\n\tif checksum == nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has no SHA-256 hash for %q\", m.Filename)\n\t}\n\n\t// Decode the ASCII checksum into a byte array for comparison.\n\tvar gotSHA256Sum [sha256.Size]byte\n\tif _, err := hex.Decode(gotSHA256Sum[:], checksum); err != nil {\n\t\treturn nil, fmt.Errorf(\"checksum list has invalid SHA256 hash %q: %s\", string(checksum), err)\n\t}\n\n\t// If the checksums don't match, authentication fails.\n\tif !bytes.Equal(gotSHA256Sum[:], m.WantSHA256Sum[:]) {\n\t\treturn nil, fmt.Errorf(\"checksum list has unexpected SHA-256 hash %x (expected %x)\", gotSHA256Sum, m.WantSHA256Sum[:])\n\t}\n\n\t// Success! But this doesn't result in any real authentication, only a\n\t// lack of authentication errors, so we return a nil result.\n\treturn nil, nil\n}\n","sourceCodeStart":343,"sourceCodeEnd":379,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L343-L379","documentation":"Thrown by matchingChecksumAuthentication.AuthenticatePackage when the SHA256SUMS document (m.Document) contains no line whose second field equals m.Filename. The document is parsed as '<hexhash> <filename>' lines split on newlines and whitespace (bytes.Fields); if no line's filename field matches, checksum stays nil and the error fires at package_authentication.go:360-361.","triggerScenarios":"NewMatchingChecksumAuthentication(document, filename, wantSHA256Sum) where filename is not present in the sums document — e.g. the document is for a different provider version, a different platform archive name, or the filename string does not exactly match (case, path prefix, .zip vs other extension).","commonSituations":"Platform mismatch — the sums file lists terraform-provider-aws_5.0.0_linux_amd64.zip but you asked for darwin_arm64; version mismatch — sums file from 5.0.0 queried with the 5.1.0 filename; a custom registry returning a sums document without the requested artifact; filename formatting drift (extra path component, different naming convention).","solutions":["Ensure m.Filename exactly matches an entry in the SHA256SUMS document (same version, platform, and naming including extension).","Verify the sums document corresponds to the same provider version being installed; re-fetch the sums document for that version.","If building a custom registry/mirror, include a line for every platform archive you serve in the sums document.","Log/print m.Document lines to confirm which filenames are actually present and adjust the requested filename."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Before constructing NewMatchingChecksumAuthentication, confirm the\n// requested filename appears in the sums document.\nfunc filenameInSums(document []byte, filename string) error {\n    want := []byte(filename)\n    for _, line := range bytes.Split(document, []byte(\"\\n\")) {\n        parts := bytes.Fields(line)\n        if len(parts) > 1 && bytes.Equal(parts[1], want) {\n            return nil\n        }\n    }\n    return fmt.Errorf(\"filename %q not present in SHA256SUMS document\", filename)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Ensure the sums document covers the exact platform archive being installed.","Keep the requested filename's version aligned with the sums document's version.","Custom mirrors must list every served platform archive in the sums document."],"tags":["authentication","checksum","sha256sums","registry","platform"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}