{"record":{"id":"9bb36b5fd2145d5a","repo":"hashicorp/terraform","slug":"failed-to-verify-provider-package-checksums-s","errorCode":null,"errorMessage":"failed to verify provider package checksums: %s","messagePattern":"failed to verify provider package checksums: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":252,"sourceCode":"\trequiredHashes := PreferredHashes(validHashes)\n\treturn packageHashAuthentication{\n\t\tRequiredHashes: requiredHashes,\n\t\tAllHashes:      validHashes,\n\t\tPlatform:       platform,\n\t}\n}\n\nfunc (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tif len(a.RequiredHashes) == 0 {\n\t\t// Indicates that none of the hashes given to\n\t\t// NewPackageHashAuthentication were considered to be usable by this\n\t\t// version of Terraform.\n\t\treturn nil, fmt.Errorf(\"this version of Terraform does not support any of the checksum formats given for this provider\")\n\t}\n\n\tmatches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to verify provider package checksums: %s\", err)\n\t}\n\n\tif matches {\n\t\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n\t}\n\tif len(a.RequiredHashes) == 1 {\n\t\treturn nil, fmt.Errorf(\"provider package doesn't match the expected checksum %q\", a.RequiredHashes[0].String())\n\t}\n\t// It's non-ideal that this doesn't actually list the expected checksums,\n\t// but in the many-checksum case the message would get pretty unweildy.\n\t// In practice today we typically use this authenticator only with a\n\t// single hash returned from a network mirror, so the better message\n\t// above will prevail in that case. Maybe we'll improve on this somehow\n\t// if the future introduction of a new hash scheme causes there to more\n\t// commonly be multiple hashes.\n\treturn nil, fmt.Errorf(\"provider package doesn't match the any of the expected checksums\")\n}\n","sourceCodeStart":234,"sourceCodeEnd":270,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L234-L270","documentation":"Thrown by packageHashAuthentication.AuthenticatePackage when PackageMatchesAnyHash returns a non-nil error while trying to compute/compare the package's hash against RequiredHashes. The wrapped %s is the underlying error — typically an I/O failure reading the staged package, a corrupt zip, or a hashing computation error. This is an infrastructure/read failure, not a mismatch verdict.","triggerScenarios":"AuthenticatePackage is called on a local package whose files cannot be read (permission denied, missing file, broken symlink), or whose zip/archive cannot be walked during hash computation. PackageMatchesAnyHash localLocation read returns err at multi_source.go... package_authentication.go:250-252.","commonSituations":"The provider cache dir got partially deleted or had permissions changed; antivirus/EDR locking the unzipped plugin files on Windows; a truncated download left in the cache; a manually placed provider dir missing files; out-of-disk during extraction.","solutions":["Clear the provider plugin cache (remove .terraform/providers/<host>/<ns>/<type>/<version>/) and re-run init to re-download cleanly.","Check read permissions and file ownership on the plugin directory, especially after running as a different user or root.","On Windows, exclude the cache path from AV/EDR on-access scanning, or stop the process holding the file.","Verify disk space and that the download completed (re-run with a fresh download)."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil {\n    if strings.Contains(err.Error(), \"failed to verify provider package checksums\") {\n        // underlying I/O / hashing failure: clear the cache and retry once\n        _ = os.RemoveAll(providerCacheDir)\n    }\n    return result, err\n}","preventionTips":["Treat the provider cache as disposable; delete and re-download on I/O errors.","Run init in a clean CI workspace to avoid stale/locked caches.","On Windows, exclude the plugin cache from on-access AV scanning."],"tags":["authentication","checksum","io","filesystem","hash"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}