{"record":{"id":"789131b4b5d07c1f","repo":"Hmbown/CodeWhale","slug":"the-update-checksum-did-not-match-your-current-app-is","errorCode":null,"errorMessage":"The update checksum did not match. Your current app is unchanged.","messagePattern":"The update checksum did not match\\. Your current app is unchanged\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"crates/tui/plugins/computer-use/app/updates.mjs","lineNumber":98,"sourceCode":"  if(position!==end) throw new Error(\"Invalid update archive length.\");\n  return count;\n}\n\nexport async function prepareUpdate(update) {\n  if(!update?.available) throw new Error(\"Check for an available update first.\");\n  if(!newerVersion(update.version,APP_VERSION)||update.url!==`${repository}/releases/download/v${update.version}/Codewhale-Computer-Use-${update.version}-macos-universal.zip`||!Number.isSafeInteger(update.size)||update.size<=0||update.size>limit) throw new Error(\"The update identity is invalid.\");\n  // Only GitHub's fixed release URL and its asset CDN can serve the bytes.\n  let url=update.url, response;\n  for(let redirects=0;redirects<4;redirects++) {\n    response=await fetch(url,{redirect:\"manual\",signal:AbortSignal.timeout(60_000)});\n    if(![301,302,303,307,308].includes(response.status)) break;\n    const next=new URL(response.headers.get(\"location\"),url);\n    if(next.protocol!==\"https:\"||![\"github.com\",\"release-assets.githubusercontent.com\",\"objects.githubusercontent.com\"].includes(next.hostname)) throw new Error(\"The update download redirected to an unexpected host.\");\n    url=next.href;\n  }\n  if(!response?.ok) throw new Error(\"The update could not be downloaded. Your current app is unchanged.\");\n  const bytes=await responseBytes(response,update.size);\n  if(bytes.length!==update.size||crypto.createHash(\"sha256\").update(bytes).digest(\"hex\")!==update.sha256) throw new Error(\"The update checksum did not match. Your current app is unchanged.\");\n  validateReleaseZip(bytes);\n  const stage=fs.mkdtempSync(path.join(os.tmpdir(),\"codewhale-cu-release-\"));\n  try {\n    const archive=path.join(stage,\"release.zip\"); fs.writeFileSync(archive,bytes,{mode:0o600});\n    const result=spawnSync(\"ditto\",[\"-x\",\"-k\",archive,stage],{encoding:\"utf8\"});\n    if(result.status!==0) throw new Error(\"The update could not be unpacked.\");\n    const bundle=path.join(stage,`${APP_NAME}.app`); verifyReleaseBundle(bundle);\n    const version=spawnSync(\"/usr/libexec/PlistBuddy\",[\"-c\",\"Print :CFBundleShortVersionString\",path.join(bundle,\"Contents\",\"Info.plist\")],{encoding:\"utf8\"});\n    if(version.status!==0||version.stdout.trim()!==update.version) throw new Error(\"The downloaded app has a different version.\");\n    return {stage,bundle};\n  } catch(error) { fs.rmSync(stage,{recursive:true,force:true}); throw error; }\n}\n\nexport async function restartWithUpdate(prepared,destination) {\n  const logDir=path.join(os.homedir(),\"Library\",\"Logs\",APP_NAME); fs.mkdirSync(logDir,{recursive:true});\n  const log=fs.openSync(path.join(logDir,\"update.log\"),\"a\",0o600);\n  const child=spawn(process.execPath,[fileURLToPath(import.meta.url),\"--apply\",prepared.bundle,destination,String(process.pid),String(process.ppid)],{detached:true,stdio:[\"ignore\",log,log]});\n  try { await new Promise((resolve,reject)=>{child.once(\"spawn\",resolve);child.once(\"error\",reject);}); child.unref(); }","sourceCodeStart":80,"sourceCodeEnd":116,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/plugins/computer-use/app/updates.mjs#L80-L116","documentation":"prepareUpdate() verifies both the downloaded byte length and the SHA-256 digest of the archive against the values from the update descriptor (update.size and update.sha256). A mismatch means the downloaded bytes differ from what the release metadata promised, so the archive is discarded and the installed app is left unchanged.","triggerScenarios":"A truncated or interrupted download (responseBytes returned fewer bytes than update.size); a proxy or middlebox modifying the payload; downloading a re-uploaded asset whose content changed after the descriptor's sha256 was computed; bit-level corruption in transit.","commonSituations":"Flaky Wi-Fi or mobile connections dropping bytes; corporate TLS proxies that re-compress or inspect content; a release asset replaced in place without updating the published checksum; disk-full conditions during buffering.","solutions":["Retry the update — a fresh download usually fixes transient truncation or corruption.","Re-run the update check to refresh update.size/sha256 in case the release asset was re-published with different bytes.","Bypass any content-modifying proxy or TLS interceptor and download over a direct connection.","Compare the asset's published SHA-256 on the GitHub release page against update.sha256 to confirm which side is stale."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { await prepareUpdate(update); } catch (e) { if (/checksum did not match/.test(e.message)) { /* refresh descriptor via check-for-update and retry once on a stable connection */ } else throw e; }","preventionTips":["Update over stable networks; avoid captive portals and content-modifying proxies.","Re-run check-for-update if a release asset was re-published.","Never bypass the checksum check; treat mismatches as transient or as a compromised release."],"tags":["checksum","sha256","download","integrity"],"backgroundTag":"checksum-mismatch","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}