{"record":{"id":"c2cd4d3b4d27ca1a","repo":"jdx/mise","slug":"packslip-project-manifest-digest-differs-from-signed-list","errorCode":null,"errorMessage":"packslip:{project}@{}: manifest digest differs from signed list","messagePattern":"packslip:(.+?)@(.+?): manifest digest differs from signed list","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/backend/packslip.rs","lineNumber":922,"sourceCode":"                    stamp.entry.packslip.clone(),\n                    self.vendor_entry(project, tv, pin, opts)\n                        .await?\n                        .and_then(|vendor| vendor.digest),\n                )\n            }\n            None => {\n                let vendor = self.locate_bundle(project, tv, pin, opts).await?;\n                (vendor.url, vendor.digest)\n            }\n        };\n        let text = crate::packslip::fetch_text(&url).await?;\n        let actual = hex::encode(Sha256::digest(text.as_bytes()));\n        for expected in vendor_digest\n            .iter()\n            .chain(stamp.and_then(|stamp| stamp.digest.as_ref()))\n        {\n            if &actual != expected {\n                bail!(\n                    \"packslip:{project}@{}: manifest digest differs from signed list\",\n                    tv.version\n                );\n            }\n        }\n        let verified = verify_bundle(&text, pin, !opts.allow_unlogged(), &[])?;\n        if verified.project != project || verified.version != tv.version {\n            bail!(\n                \"packslip:{project}@{}: verified manifest project/version differs from discovery\",\n                tv.version\n            );\n        }\n        let scheme = verified.scheme.to_string();\n        let attested_by = verified.attested_by.to_string();\n        packslip_pins::check(\n            project,\n            Observed {\n                scheme: &scheme,","sourceCodeStart":904,"sourceCodeEnd":940,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/backend/packslip.rs#L904-L940","documentation":"mise downloaded a packslip manifest and computed its sha256, but it does not match a digest declared by the signed vendor list (or the stamp). The manifest on the wire is not the one the vendor signed, so mise rejects it.","triggerScenarios":"verified_release hashing the fetched text (Sha256::digest) and comparing against each entry of vendor_digest and stamp.digest; any single mismatch bails — vendor republished content without updating the signed list, or the file was tampered with/corrupted in transit.","commonSituations":"A mirror serving a modified manifest; the vendor re-signed a new manifest but the release list still pins the old digest (or vice versa); CDN/cache serving a stale manifest; MITM or supply-chain attack attempt.","solutions":["Wait for / ask the vendor to republish the signed release list so its digest matches the current manifest","Clear any mirror/CDN cache so the digest-matching manifest is served","If you control the manifest, re-sign the release list to include the manifest's current sha256"],"exampleFix":"null","handlingStrategy":"retry","validationCode":"sha256sum <manifest>  # compare with the digest pinned in the signed release list before distributing","typeGuard":"null","tryCatchPattern":"// retry from a different source; a persistent mismatch means upstream desync\nfor attempt in 0..2 {\n    match install() {\n        Err(e) if e.to_string().contains(\"digest differs\") && attempt == 0 => { clear_mirror_cache(); continue; }\n        r => { r?; break; }\n    }\n}","preventionTips":["Vendors: update the signed release list and manifest atomically","Watch for CDN/cache staleness after republishing manifests","Never edit a manifest in place without re-signing the release list"],"tags":["packslip","sha256","integrity","supply-chain"],"backgroundTag":"checksum-mismatch","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}