hashicorp/terraform · error
archive has incorrect checksum
Error message
archive has incorrect checksum %s (expected %s)
What it means
Thrown by archiveHashAuthentication.AuthenticatePackage when the legacy zip SHA-256 computed over the archive (gotHash) does not equal the expected HashLegacyZipSHAFromSHA(a.WantSHA256Sum). This is a positive mismatch verdict: the archive bytes differ from the expected checksum. Computed via PackageHashLegacyZipSHA at package_authentication.go:309-315.
Solutions
- Re-download the archive from the origin registry and recompute — if it then matches, the prior artifact was stale/corrupt.
- Confirm the expected SHA256 sum passed to NewArchiveChecksumAuthentication matches the current registry entry for that exact version+platform.
- If both come from the same registry and still differ, report a registry/packaging issue (possible republish) — do not disable the check.
- Treat a persistent mismatch on an official provider as possible tampering and stop using the artifact.
Defensive patterns
Strategy: try-catch
Try / catch
result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "archive has incorrect checksum") {
return result, fmt.Errorf("archive checksum mismatch (possible tampering/stale republish): %w", err)
} Prevention
- Pin provider versions whose archives are stable; re-derive expected sums after any republish.
- Treat persistent mismatches as possible tampering.
- Keep the expected SHA256Sum consistent with the current registry entry.
When it happens
Trigger: AuthenticatePackage succeeds in reading the archive but the computed zh: hash differs from the wantSHA256Sum passed to NewArchiveChecksumAuthentication. Happens when the registry-provided expected sum is for different bytes than what was downloaded.
Common situations: Provider re-packed upstream so the zip layout/bytes changed while the expected sum is stale; a mirror serving a repacked zip with different compression/metadata; download corruption that still yields a valid zip; wrong platform archive fetched; a man-in-the-middle or tampered artifact.
Related errors
- provider package doesn't match the any of the expected…
- provider package doesn't match the expected checksum
- cannot check archive hash for non-archive location
- checksum list has unexpected SHA-256 hash
- failed to compute checksum for
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/edb7f1dc652f68e8.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:315
func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
return archiveHashAuthentication{platform, wantSHA256Sum}
}
func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
archiveLocation, ok := localLocation.(PackageLocalArchive)
if !ok {
// A source should not use this authentication type for non-archive
// locations.
return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
}
gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
if err != nil {
return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
}
wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
if gotHash != wantHash {
return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
}
return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}
func (a archiveHashAuthentication) AcceptableHashes() []Hash {
return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}
type matchingChecksumAuthentication struct {
Document []byte
Filename string
WantSHA256Sum [sha256.Size]byte
}
// NewMatchingChecksumAuthentication returns a PackageAuthentication
// implementation that scans a registry-provided SHA256SUMS document for a
// specified filename, and compares the SHA256 hash against the expected hash.
// This is necessary to ensure that the signed SHA256SUMS document matches theView on GitHub (pinned to d32a084675)