{"record":{"id":"c1663d8e83e0c36e","repo":"hashicorp/terraform","slug":"failed-to-compute-checksum-for-s-s","errorCode":null,"errorMessage":"failed to compute checksum for %s: %s","messagePattern":"failed to compute checksum for (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":311,"sourceCode":"//\n// NewPackageHashAuthentication is preferable to use when possible because\n// it uses the newer hashing scheme (implemented by function PackageHash) that\n// can work with both packed and unpacked provider packages.\nfunc NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {\n\treturn archiveHashAuthentication{platform, wantSHA256Sum}\n}\n\nfunc (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tarchiveLocation, ok := localLocation.(PackageLocalArchive)\n\tif !ok {\n\t\t// A source should not use this authentication type for non-archive\n\t\t// locations.\n\t\treturn nil, fmt.Errorf(\"cannot check archive hash for non-archive location %s\", localLocation)\n\t}\n\n\tgotHash, err := PackageHashLegacyZipSHA(archiveLocation)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to compute checksum for %s: %s\", archiveLocation, err)\n\t}\n\twantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)\n\tif gotHash != wantHash {\n\t\treturn nil, fmt.Errorf(\"archive has incorrect checksum %s (expected %s)\", gotHash, wantHash)\n\t}\n\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n}\n\nfunc (a archiveHashAuthentication) AcceptableHashes() []Hash {\n\treturn []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}\n}\n\ntype matchingChecksumAuthentication struct {\n\tDocument      []byte\n\tFilename      string\n\tWantSHA256Sum [sha256.Size]byte\n}\n","sourceCodeStart":293,"sourceCodeEnd":329,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L293-L329","documentation":"Thrown by archiveHashAuthentication.AuthenticatePackage when PackageHashLegacyZipSHA(archiveLocation) returns an error reading or hashing the archive. The wrapped %s is the underlying error — usually an I/O failure opening/reading the archive or a zip-struct read error. The location did type-assert to PackageLocalArchive, so the file exists as an archive but its contents cannot be hashed.","triggerScenarios":"AuthenticatePackage on a PackageLocalArchive whose file is unreadable (permission denied, removed mid-operation, locked by another process) or whose zip structure is unreadable by the legacy-zip hasher. Triggered at package_authentication.go:309-311.","commonSituations":"The downloaded .zip is truncated (interrupted download); AV/EDR on Windows locks the file; permissions changed after staging; the archive is corrupt or zero-length; concurrent processes reading/deleting the cache.","solutions":["Delete the cached archive file and re-run init to re-download a complete package.","Check read permissions and that no other process (AV, backup, another terraform run) holds the file.","Verify the archive is a valid zip (unzip -t or equivalent) and non-empty; if not, re-fetch.","Confirm the download path has enough disk space to write the full archive."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"failed to compute checksum\") {\n    // archive unreadable: re-download\n    _ = os.Remove(archivePath)\n}\nreturn result, err","preventionTips":["Verify downloads complete (non-empty, valid zip) before staging.","Keep the cache on a writable, unlocked path with enough disk.","Re-fetch on any archive read error rather than retrying the same bytes."],"tags":["authentication","archive","checksum","io","filesystem"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}