{"record":{"id":"8293088b6ac4a185","repo":"ruvnet/ruflo","slug":"sha256sums-has-no-entry-for-input-assetfilename","errorCode":null,"errorMessage":"SHA256SUMS has no entry for ${input.assetFilename}","messagePattern":"SHA256SUMS has no entry for (.+?)","errorType":"exception","errorClass":"ReleaseVerificationError","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/proxy/verify.ts","lineNumber":85,"sourceCode":"export interface VerifyReleaseResult {\n  sha256: string;\n}\n\n/**\n * Full verification: signature over SHA256SUMS, then the asset's own hash\n * against the matching line. Throws `ReleaseVerificationError` on ANY\n * failure — there is no partial-trust outcome, matching ADR-307's \"refuses\n * on any mismatch\" requirement.\n */\nexport function verifyRelease(input: VerifyReleaseInput): VerifyReleaseResult {\n  if (!verifySha256SumsSignature(input.sumsBytes, input.sigBase64, input.pubkeyPem)) {\n    throw new ReleaseVerificationError('SHA256SUMS.sig failed Ed25519 verification — refusing to install');\n  }\n\n  const sums = parseSha256Sums(input.sumsBytes.toString('utf-8'));\n  const expected = sums[input.assetFilename];\n  if (!expected) {\n    throw new ReleaseVerificationError(`SHA256SUMS has no entry for ${input.assetFilename}`);\n  }\n\n  const actual = sha256Hex(input.assetBytes);\n  if (actual !== expected) {\n    throw new ReleaseVerificationError(\n      `sha256 mismatch for ${input.assetFilename}: expected ${expected.slice(0, 12)}…, got ${actual.slice(0, 12)}…`,\n    );\n  }\n\n  return { sha256: actual };\n}\n","sourceCodeStart":67,"sourceCodeEnd":97,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/proxy/verify.ts#L67-L97","documentation":"After the manifest signature verifies, verifyRelease() looks up the exact asset filename (built by releaseAssetFilename, e.g. meta-proxy-1.2.3-x86_64-unknown-linux-gnu.tar.gz) in the parsed SHA256SUMS. If the release was published without an entry for that file, there is no hash to compare against, and the install is refused — a missing entry counts as a verification failure, not a skip.","triggerScenarios":"A release that publishes an archive for a platform but omits that file from SHA256SUMS; or a filename-scheme drift between what this CLI version constructs (version prefix, triple naming) and how the release assets were actually named.","commonSituations":"Partially-published releases (assets uploaded before the manifest was regenerated); version-scheme changes (v-prefix, build metadata) mismatching filename construction; new triples added to assets but not to the signing job.","solutions":["Open the release page for your version and confirm SHA256SUMS actually lists your platform's archive","Update the ruflo CLI — filename construction mismatches are fixed alongside release tooling changes","Install on a triple that is listed in the manifest, or wait for maintainers to republish a complete one","Report the release version plus the missing filename upstream"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"import { parseSha256Sums, releaseAssetFilename, detectTargetTriple } from '@claude-flow/cli/.../proxy/index.js';\nconst sums = parseSha256Sums(sumsBytes.toString('utf8'));\nif (!sums[releaseAssetFilename(version, detectTargetTriple())]) {\n  throw new Error('release manifest lacks an entry for this platform — update ruflo or pick a listed triple');\n}","typeGuard":"const isReleaseVerification = (e: unknown): e is Error & { name: 'ReleaseVerificationError' } =>\n  e instanceof Error && e.name === 'ReleaseVerificationError';","tryCatchPattern":"try {\n  verifyRelease(input);\n} catch (e) {\n  if (isReleaseVerification(e) && /has no entry for/.test(e.message)) {\n    // manifest drift: choose a listed triple or upgrade CLI — never skip verification\n    throw new Error(`release incomplete for this platform: ${e.message}`);\n  }\n  throw e;\n}","preventionTips":["Smoke-test installs on all five triples in release CI","Upgrade CLI and proxy releases together","Treat missing manifest entries as release-tooling bugs, not user error"],"tags":["security","checksums","release-manifest","proxy-install"],"backgroundTag":"checksum-manifest-missing-entry","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}