hashicorp/terraform · error

archive has incorrect checksum

Error message

archive has incorrect checksum %s (expected %s)

What it means

Thrown by archiveHashAuthentication.AuthenticatePackage when the legacy zip SHA-256 computed over the archive (gotHash) does not equal the expected HashLegacyZipSHAFromSHA(a.WantSHA256Sum). This is a positive mismatch verdict: the archive bytes differ from the expected checksum. Computed via PackageHashLegacyZipSHA at package_authentication.go:309-315.

Solutions

  1. Re-download the archive from the origin registry and recompute — if it then matches, the prior artifact was stale/corrupt.
  2. Confirm the expected SHA256 sum passed to NewArchiveChecksumAuthentication matches the current registry entry for that exact version+platform.
  3. If both come from the same registry and still differ, report a registry/packaging issue (possible republish) — do not disable the check.
  4. Treat a persistent mismatch on an official provider as possible tampering and stop using the artifact.
Defensive patterns

Strategy: try-catch

Try / catch

result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "archive has incorrect checksum") {
    return result, fmt.Errorf("archive checksum mismatch (possible tampering/stale republish): %w", err)
}

Prevention

When it happens

Trigger: AuthenticatePackage succeeds in reading the archive but the computed zh: hash differs from the wantSHA256Sum passed to NewArchiveChecksumAuthentication. Happens when the registry-provided expected sum is for different bytes than what was downloaded.

Common situations: Provider re-packed upstream so the zip layout/bytes changed while the expected sum is stale; a mirror serving a repacked zip with different compression/metadata; download corruption that still yields a valid zip; wrong platform archive fetched; a man-in-the-middle or tampered artifact.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/edb7f1dc652f68e8. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:315

func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
	return archiveHashAuthentication{platform, wantSHA256Sum}
}

func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
	archiveLocation, ok := localLocation.(PackageLocalArchive)
	if !ok {
		// A source should not use this authentication type for non-archive
		// locations.
		return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
	}

	gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
	if err != nil {
		return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
	}
	wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
	if gotHash != wantHash {
		return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
	}
	return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}

func (a archiveHashAuthentication) AcceptableHashes() []Hash {
	return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}

type matchingChecksumAuthentication struct {
	Document      []byte
	Filename      string
	WantSHA256Sum [sha256.Size]byte
}

// NewMatchingChecksumAuthentication returns a PackageAuthentication
// implementation that scans a registry-provided SHA256SUMS document for a
// specified filename, and compares the SHA256 hash against the expected hash.
// This is necessary to ensure that the signed SHA256SUMS document matches the

View on GitHub (pinned to d32a084675)