{"record":{"id":"e5618d09ab616c1a","repo":"hashicorp/terraform","slug":"provider-package-doesn-t-match-the-expected-checks","errorCode":null,"errorMessage":"provider package doesn't match the expected checksum %q","messagePattern":"provider package doesn't match the expected checksum %q","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":259,"sourceCode":"\nfunc (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tif len(a.RequiredHashes) == 0 {\n\t\t// Indicates that none of the hashes given to\n\t\t// NewPackageHashAuthentication were considered to be usable by this\n\t\t// version of Terraform.\n\t\treturn nil, fmt.Errorf(\"this version of Terraform does not support any of the checksum formats given for this provider\")\n\t}\n\n\tmatches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to verify provider package checksums: %s\", err)\n\t}\n\n\tif matches {\n\t\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n\t}\n\tif len(a.RequiredHashes) == 1 {\n\t\treturn nil, fmt.Errorf(\"provider package doesn't match the expected checksum %q\", a.RequiredHashes[0].String())\n\t}\n\t// It's non-ideal that this doesn't actually list the expected checksums,\n\t// but in the many-checksum case the message would get pretty unweildy.\n\t// In practice today we typically use this authenticator only with a\n\t// single hash returned from a network mirror, so the better message\n\t// above will prevail in that case. Maybe we'll improve on this somehow\n\t// if the future introduction of a new hash scheme causes there to more\n\t// commonly be multiple hashes.\n\treturn nil, fmt.Errorf(\"provider package doesn't match the any of the expected checksums\")\n}\n\nfunc (a packageHashAuthentication) AcceptableHashes() []Hash {\n\t// In this case we include even hashes the current version of Terraform\n\t// doesn't prefer, because this result is used for building a lock file\n\t// and so it's helpful to include older hash formats that other Terraform\n\t// versions might need in order to do authentication successfully.\n\treturn a.AllHashes\n}","sourceCodeStart":241,"sourceCodeEnd":277,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L241-L277","documentation":"Thrown by packageHashAuthentication.AuthenticatePackage when there is exactly one RequiredHash and the computed package hash does not match it. This is the single-hash mismatch path at package_authentication.go:258-259; the printed %q is the expected hash string. A mismatch means the staged package bytes differ from what the lock file/registry declared — corruption, tampering, or a wrong/mismatched package.","triggerScenarios":"AuthenticatePackage with len(RequiredHashes)==1 where PackageMatchesAnyHash returned false. Typical with a network mirror returning a single hash; a manually replaced plugin binary; a lock file hash from a different provider version.","commonSituations":"A provider version was re-published/repacked so the bytes changed but the lock file pins the old hash; someone copied a different provider binary into the cache; a CI cache of .terraform/providers holds a stale package from a prior version; a network mirror served a wrong hash.","solutions":["Delete the cached package and the affected lock-file hashes, then re-run init -upgrade to fetch a fresh, matching package and hash.","Confirm the lock file's version constraint and hashes correspond to the same provider release (mismatched version+hash is a common cause).","Verify the registry/mirror is serving the correct, current checksum for that version+platform.","If the mismatch is unexpected on an official provider, treat it as possible tampering — re-download from the origin registry over a trusted network."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"doesn't match the expected checksum\") {\n    // single-hash mismatch: do not weaken verification; re-download fresh\n    return result, fmt.Errorf(\"checksum mismatch (possible tampering or stale cache): %w\", err)\n}","preventionTips":["Never disable checksum verification to work around a mismatch.","Regenerate the lock file after provider upgrades.","Investigate persistent mismatches as possible tampering."],"tags":["authentication","checksum","tampering","lock-file","hash"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}