{"record":{"id":"9216ec851abfc726","repo":"hashicorp/terraform","slug":"provider-package-doesn-t-match-the-any-of-the-expe","errorCode":null,"errorMessage":"provider package doesn't match the any of the expected checksums","messagePattern":"provider package doesn't match the any of the expected checksums","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":268,"sourceCode":"\tmatches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to verify provider package checksums: %s\", err)\n\t}\n\n\tif matches {\n\t\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n\t}\n\tif len(a.RequiredHashes) == 1 {\n\t\treturn nil, fmt.Errorf(\"provider package doesn't match the expected checksum %q\", a.RequiredHashes[0].String())\n\t}\n\t// It's non-ideal that this doesn't actually list the expected checksums,\n\t// but in the many-checksum case the message would get pretty unweildy.\n\t// In practice today we typically use this authenticator only with a\n\t// single hash returned from a network mirror, so the better message\n\t// above will prevail in that case. Maybe we'll improve on this somehow\n\t// if the future introduction of a new hash scheme causes there to more\n\t// commonly be multiple hashes.\n\treturn nil, fmt.Errorf(\"provider package doesn't match the any of the expected checksums\")\n}\n\nfunc (a packageHashAuthentication) AcceptableHashes() []Hash {\n\t// In this case we include even hashes the current version of Terraform\n\t// doesn't prefer, because this result is used for building a lock file\n\t// and so it's helpful to include older hash formats that other Terraform\n\t// versions might need in order to do authentication successfully.\n\treturn a.AllHashes\n}\n\ntype archiveHashAuthentication struct {\n\tPlatform      Platform\n\tWantSHA256Sum [sha256.Size]byte\n}\n\n// NewArchiveChecksumAuthentication returns a PackageAuthentication\n// implementation that checks that the original distribution archive matches\n// the given hash.","sourceCodeStart":250,"sourceCodeEnd":286,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L250-L286","documentation":"Thrown by packageHashAuthentication.AuthenticatePackage when there are two or more RequiredHashes and the package matched none of them. This is the multi-hash mismatch path at package_authentication.go:261-268 (note the message typo 'match the any of the expected'). The error does not enumerate the expected hashes, so diagnosis requires inspecting the lock file / AllHashes directly.","triggerScenarios":"AuthenticatePackage with len(RequiredHashes) > 1 where PackageMatchesAnyHash returned false. Typical with the standard registry flow where multiple zh:/h1: hashes are acceptable but the local package matches none.","commonSituations":"Package repackaged upstream while the lock file still lists old hashes; cross-platform lock file used on a platform whose cached package was built differently; a stale CI cache; tampered or partially overwritten package files.","solutions":["Remove the cached package directory and re-run init to re-download against the current registry hashes.","Regenerate the lock file (terraform init -upgrade) so hashes match the currently published package bytes.","Compare the actual package hash (compute it locally) against each entry in the lock file to identify which scheme/version drifted.","If running across platforms, ensure the lock file has hashes for the target platform's package, not just one platform."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"doesn't match the any of the expected checksums\") {\n    // multi-hash mismatch: log AllHashes for diagnosis, then re-fetch\n    return result, err\n}","preventionTips":["Keep the lock file's hashes in sync with the published package bytes.","Include hashes for the target platform in cross-platform lock files.","Clear stale CI caches when providers are republished."],"tags":["authentication","checksum","tampering","lock-file","hash"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}