{"record":{"id":"a714188cf71665f2","repo":"siyuan-note/siyuan","slug":"update-package-url-or-checksum-is-empty","errorCode":null,"errorMessage":"update package URL or checksum is empty","messagePattern":"update package URL or checksum is empty","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/updater.go","lineNumber":138,"sourceCode":"\t\treturn\n\t}\n\tpkg := release.Packages[pkgName]\n\tif nil == pkg || 0 == len(pkg.URLs) {\n\t\terr = fmt.Errorf(\"%w: [%s]\", errUpdatePackageUnavailable, pkgName)\n\t\treturn\n\t}\n\tif \"\" == pkg.Checksum {\n\t\terr = fmt.Errorf(\"%w: [%s] checksum is unavailable\", errUpdatePackageUnavailable, pkgName)\n\t\treturn\n\t}\n\tdownloadPkgURLs = append(downloadPkgURLs, pkg.URLs...)\n\tchecksum = pkg.Checksum\n\treturn\n}\n\nfunc downloadInstallPkg(pkgURL, checksum string) (err error) {\n\tif \"\" == pkgURL || \"\" == checksum {\n\t\terr = errors.New(\"update package URL or checksum is empty\")\n\t\treturn\n\t}\n\n\tpkg := path.Base(pkgURL)\n\tsavePath := filepath.Join(util.TempDir, \"install\", pkg)\n\tif gulu.File.IsExist(savePath) {\n\t\tlocalChecksum, _ := sha256Hash(savePath)\n\t\tif localChecksum == checksum {\n\t\t\treturn\n\t\t}\n\t}\n\n\terr = os.MkdirAll(filepath.Join(util.TempDir, \"install\"), 0755)\n\tif err != nil {\n\t\tlogging.LogErrorf(\"create temp install dir failed: %s\", err)\n\t\treturn\n\t}\n","sourceCodeStart":120,"sourceCodeEnd":156,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/updater.go#L120-L156","documentation":"downloadInstallPkg validates its inputs before doing any I/O: if the package URL or the expected checksum is an empty string it returns errors.New(\"update package URL or checksum is empty\"). This is an internal pre-condition check ensuring a download is never attempted without the data needed to fetch and verify the package.","triggerScenarios":"checkDownloadInstallPkg proceeds to downloadInstallPkg while the download URL list or checksum produced by getUpdatePkg is empty — i.e. an upstream guard was bypassed or a URL from pkg.URLs was blank.","commonSituations":"A malformed release whose URL entries are empty strings; a code path that skips the getUpdatePkg validation; custom update-server metadata missing URL or checksum fields.","solutions":["Ensure getUpdatePkg succeeded and returned non-empty URL/checksum before calling downloadInstallPkg","Fix the update-server/release metadata so URLs and checksum are populated","Add the same empty-string guard at your call site if you call downloadInstallPkg directly","Log the release metadata when this fires to identify which field is missing"],"exampleFix":"// before\ndownloadInstallPkg(pkgURL, checksum)\n// after\nif \"\" == pkgURL || \"\" == checksum {\n    return errors.New(\"skip download: missing url or checksum\")\n}\ndownloadInstallPkg(pkgURL, checksum)","handlingStrategy":"validation","validationCode":"if \"\" == pkgURL || \"\" == checksum { return errors.New(\"skip download: missing url or checksum\") }","typeGuard":null,"tryCatchPattern":"if err := downloadInstallPkg(url, sum); err != nil {\n    logging.LogErrorf(\"download aborted: %s\", err)\n    return err\n}","preventionTips":["Always obtain URL and checksum from a successful getUpdatePkg call","Validate release metadata (non-empty URLs and checksum) upstream","Log metadata on failure to identify the missing field"],"tags":["go","updater","validation"],"backgroundTag":"empty-required-field","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}