{"record":{"id":"edb7f1dc652f68e8","repo":"hashicorp/terraform","slug":"archive-has-incorrect-checksum-s-expected-s","errorCode":null,"errorMessage":"archive has incorrect checksum %s (expected %s)","messagePattern":"archive has incorrect checksum (.+?) \\(expected (.+?)\\)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":315,"sourceCode":"func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {\n\treturn archiveHashAuthentication{platform, wantSHA256Sum}\n}\n\nfunc (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {\n\tarchiveLocation, ok := localLocation.(PackageLocalArchive)\n\tif !ok {\n\t\t// A source should not use this authentication type for non-archive\n\t\t// locations.\n\t\treturn nil, fmt.Errorf(\"cannot check archive hash for non-archive location %s\", localLocation)\n\t}\n\n\tgotHash, err := PackageHashLegacyZipSHA(archiveLocation)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to compute checksum for %s: %s\", archiveLocation, err)\n\t}\n\twantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)\n\tif gotHash != wantHash {\n\t\treturn nil, fmt.Errorf(\"archive has incorrect checksum %s (expected %s)\", gotHash, wantHash)\n\t}\n\treturn &PackageAuthenticationResult{result: verifiedChecksum}, nil\n}\n\nfunc (a archiveHashAuthentication) AcceptableHashes() []Hash {\n\treturn []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}\n}\n\ntype matchingChecksumAuthentication struct {\n\tDocument      []byte\n\tFilename      string\n\tWantSHA256Sum [sha256.Size]byte\n}\n\n// NewMatchingChecksumAuthentication returns a PackageAuthentication\n// implementation that scans a registry-provided SHA256SUMS document for a\n// specified filename, and compares the SHA256 hash against the expected hash.\n// This is necessary to ensure that the signed SHA256SUMS document matches the","sourceCodeStart":297,"sourceCodeEnd":333,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L297-L333","documentation":"Thrown by archiveHashAuthentication.AuthenticatePackage when the legacy zip SHA-256 computed over the archive (gotHash) does not equal the expected HashLegacyZipSHAFromSHA(a.WantSHA256Sum). This is a positive mismatch verdict: the archive bytes differ from the expected checksum. Computed via PackageHashLegacyZipSHA at package_authentication.go:309-315.","triggerScenarios":"AuthenticatePackage succeeds in reading the archive but the computed zh: hash differs from the wantSHA256Sum passed to NewArchiveChecksumAuthentication. Happens when the registry-provided expected sum is for different bytes than what was downloaded.","commonSituations":"Provider re-packed upstream so the zip layout/bytes changed while the expected sum is stale; a mirror serving a repacked zip with different compression/metadata; download corruption that still yields a valid zip; wrong platform archive fetched; a man-in-the-middle or tampered artifact.","solutions":["Re-download the archive from the origin registry and recompute — if it then matches, the prior artifact was stale/corrupt.","Confirm the expected SHA256 sum passed to NewArchiveChecksumAuthentication matches the current registry entry for that exact version+platform.","If both come from the same registry and still differ, report a registry/packaging issue (possible republish) — do not disable the check.","Treat a persistent mismatch on an official provider as possible tampering and stop using the artifact."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"archive has incorrect checksum\") {\n    return result, fmt.Errorf(\"archive checksum mismatch (possible tampering/stale republish): %w\", err)\n}","preventionTips":["Pin provider versions whose archives are stable; re-derive expected sums after any republish.","Treat persistent mismatches as possible tampering.","Keep the expected SHA256Sum consistent with the current registry entry."],"tags":["authentication","archive","checksum","tampering","hash"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}