{"record":{"id":"da1bce115ca6e0f8","repo":"hashicorp/terraform","slug":"the-cached-package-for-s-s-in-s-does-not-matc","errorCode":null,"errorMessage":"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file","messagePattern":"the cached package for (.+?) (.+?) \\(in (.+?)\\) does not match any of the checksums recorded in the dependency lock file","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/meta_providers.go","lineNumber":420,"sourceCode":"\t\t\treportError(fmt.Errorf(\n\t\t\t\t\"there is no package for %s %s cached in %s\",\n\t\t\t\tprovider, version, cacheDir.BasePath(),\n\t\t\t))\n\t\t\tcontinue\n\t\t}\n\t\t// The cached package must match one of the checksums recorded in\n\t\t// the lock file, if any.\n\t\tif allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {\n\t\t\tmatched, err := cached.MatchesAnyHash(allowedHashes)\n\t\t\tif err != nil {\n\t\t\t\treportError(fmt.Errorf(\n\t\t\t\t\t\"failed to verify checksum of %s %s package cached in in %s: %s\",\n\t\t\t\t\tprovider, version, cacheDir.BasePath(), err,\n\t\t\t\t))\n\t\t\t\tcontinue\n\t\t\t}\n\t\t\tif !matched {\n\t\t\t\treportError(fmt.Errorf(\n\t\t\t\t\t\"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file\",\n\t\t\t\t\tprovider, version, cacheDir.BasePath(),\n\t\t\t\t))\n\t\t\t\tcontinue\n\t\t\t}\n\t\t}\n\t\tfactories[provider] = providerFactory(cached)\n\t}\n\tfor provider, localDir := range devOverrideProviders {\n\t\tfactories[provider] = devOverrideProviderFactory(provider, localDir)\n\t}\n\tfor provider, reattach := range unmanagedProviders {\n\t\tfactories[provider] = unmanagedProviderFactory(provider, reattach)\n\t}\n\tif m.testingOverrides != nil {\n\t\t// Allow tests, where testingOverrides is set, to see test providers in locks\n\t\tfor provider, factory := range m.testingOverrides.Providers {\n\t\t\tfactories[provider] = factory","sourceCodeStart":402,"sourceCodeEnd":438,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/meta_providers.go#L402-L438","documentation":"When MatchesAnyHash completes successfully but returns matched == false, the cached provider package hashes do not match any checksum recorded in the dependency lock file. This is a deliberate integrity failure: Terraform treats the package as untrusted because it differs from what was locked. reportError installs a stub factory so the error surfaces again if the provider is actually used.","triggerScenarios":"lock.PreferredHashes() is non-empty, cached.MatchesAnyHash returns (false, nil). The package bytes differ from every h1:/zh: hash in the lock file — e.g. the archive was replaced, re-packed, or comes from an unverified mirror.","commonSituations":"Manually replacing a provider binary for debugging and forgetting to update the lock; pulling a different build of the same version from a mirror; lock file generated on a different platform with only zh: hashes and the local package yields h1: only; supply-chain tampering or a corrupted download.","solutions":["If the package was intentionally replaced, run terraform init -upgrade (or terraform providers lock) to regenerate the lock hashes for the current package.","If the package is suspect, delete .terraform/providers/<provider>/<version> and re-run terraform init to fetch the original.","Ensure all platforms needed are represented in the lock file: terraform providers lock -platform=linux_amd64 -platform=darwin_arm64 ...","Verify the registry/mirror URL is the trusted origin configured when the lock was first generated."],"exampleFix":"# before: checksum mismatch after replacing provider\n# after: regenerate lock hashes\nterraform providers lock -platform=$(go env GOOS)_$(go env GOARCH)\ngit add .terraform.lock.hcl","handlingStrategy":"validation","validationCode":"// Verify package hashes match the lock before delegating to Terraform.\nmatched, err := cached.MatchesAnyHash(lock.PreferredHashes())\nif err == nil && !matched {\n    return fmt.Errorf(\"integrity check failed for %s; regenerate lock or re-fetch\", provider)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Generate lock hashes for all target platforms with terraform providers lock.","Never replace provider binaries under the cache without updating the lock file.","Treat a sudden checksum mismatch as a possible supply-chain incident and investigate before re-locking."],"tags":["terraform","provider","checksum","integrity","security","lock-file"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}