{"record":{"id":"d13c50f1a2dd4e2c","repo":"hashicorp/terraform","slug":"failed-to-retrieve-authentication-checksums-for-pr","errorCode":null,"errorMessage":"failed to retrieve authentication checksums for provider: %s","messagePattern":"failed to retrieve authentication checksums for provider: (.+?)","errorType":"exception","errorClass":"ErrQueryFailed","httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":333,"sourceCode":"\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tshasumsURL, err := url.Parse(body.SHA256SumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: %s\", err)\n\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: must use http or https scheme\")\n\t}\n\tdocument, err := c.getFile(shasumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve authentication checksums for provider: %s\", err),\n\t\t)\n\t}\n\tsignatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: %s\", err)\n\t}\n\tsignatureURL = resp.Request.URL.ResolveReference(signatureURL)\n\tif signatureURL.Scheme != \"http\" && signatureURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: must use http or https scheme\")\n\t}\n\tsignature, err := c.getFile(signatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve cryptographic signature for provider: %s\", err),\n\t\t)\n\t}\n","sourceCodeStart":315,"sourceCodeEnd":351,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L315-L351","documentation":"Thrown when fetching the SHA256SUMS document from the resolved shasums_url fails. Unlike the URL parse/scheme errors this is a transport/HTTP failure and is wrapped by errQueryFailed, so it commonly reflects a network or server problem rather than a malformed response.","triggerScenarios":"c.getFile(shasumsURL) returned a non-nil error — HTTP 4xx/5xx, DNS failure, connection refused, TLS error, timeout, or a truncated body.","commonSituations":"Registry/mirror outage; 404 for the SHA256SUMS file for this version; transient network failure; TLS certificate problem; an airgapped environment where the shasums host is unreachable.","solutions":["Retry the operation after a short delay for transient network/5xx failures","Verify the shasums_url is reachable and returns 200 (curl it from the same host)","Check DNS/TLS connectivity to the registry and any redirect target","If airgapped, mirror the SHA256SUMS artifact locally and point the registry at it"],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Not a validation error; pre-flight reachability can reduce surprises.\nresp, err := http.Head(shasumsURL.String())\nif err != nil || resp.StatusCode >= 400 {\n    log.Printf(\"SHASUMS endpoint unreachable: %v status=%v\", err, respStatus(resp))\n}","typeGuard":null,"tryCatchPattern":"var doc []byte\nerr := retry.Do(func() error {\n    var err error\n    doc, err = c.getFile(shasumsURL)\n    return err\n}, retry.Attempts(3), retry.LastErrorOnly(true))\nif err != nil {\n    return fmt.Errorf(\"failed to retrieve SHASUMS after retries: %w\", err)\n}","preventionTips":["Add bounded retry with backoff for SHASUMS fetches to absorb transient registry errors","Verify registry/mirror connectivity and TLS from the host before a run","Mirror the SHA256SUMS artifact locally for airgapped environments"],"tags":["registry","network","shasums","http","provider","transient"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}