{"record":{"id":"ff007913ee75892c","repo":"hashicorp/terraform","slug":"registry-response-includes-invalid-sha256-hash-q","errorCode":null,"errorMessage":"registry response includes invalid SHA256 hash %q: %s","messagePattern":"registry response includes invalid SHA256 hash %q: (.+?)","errorType":"exception","errorClass":"ErrQueryFailed","httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":308,"sourceCode":"\t}\n\n\tret := PackageMeta{\n\t\tProvider:         provider,\n\t\tVersion:          version,\n\t\tProtocolVersions: protoVersions,\n\t\tTargetPlatform: Platform{\n\t\t\tOS:   body.OS,\n\t\t\tArch: body.Arch,\n\t\t},\n\t\tFilename: body.Filename,\n\t\tLocation: PackageHTTPURL(downloadURL.String()),\n\t\t// \"Authentication\" is populated below\n\t}\n\n\tif len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tvar checksum [sha256.Size]byte\n\t_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tshasumsURL, err := url.Parse(body.SHA256SumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: %s\", err)\n\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {","sourceCodeStart":290,"sourceCodeEnd":326,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L290-L326","documentation":"Thrown when the registry's shasum field is not exactly sha256.Size*2 (64) hex characters long. Note: the error formats the nil err variable (a latent bug — the message prints '%!s(<nil>)'), so the real diagnostic is the length mismatch, not the appended err.","triggerScenarios":"len(body.SHA256Sum) != 64 — empty, too short, too long, or a non-hex-padded value.","commonSituations":"Registry omits the shasum field (empty string); returns a base64-encoded digest instead of hex; truncates the digest; schema regression returning the full checksums document instead of a single hash.","solutions":["Report the malformed shasum field to the registry operator","If self-hosting, return the provider archive's SHA256 as a 64-char lowercase hex string","Verify the registry endpoint returns the documented single-hash shasum (not the SHA256SUMS file body)"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Confirm the shasum is exactly 64 hex characters.\nif len(body.SHA256Sum) != sha256.Size*2 {\n    return fmt.Errorf(\"registry shasum has wrong length %d (want %d): %q\",\n        len(body.SHA256Sum), sha256.Size*2, body.SHA256Sum)\n}","typeGuard":"func IsSHA256HexLength(s string) bool {\n    return len(s) == sha256.Size*2\n}","tryCatchPattern":"if len(body.SHA256Sum) != sha256.Size*2 {\n    return fmt.Errorf(\"registry returned a malformed shasum (length): %q\", body.SHA256Sum)\n}","preventionTips":["Registries must return shasum as a 64-char lowercase hex digest","Do not return base64 or the full SHA256SUMS file body in the shasum field"],"tags":["registry","sha256","checksum","provider","validation","bug"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}