hashicorp/terraform · error

cannot check archive hash for non-archive location

Error message

cannot check archive hash for non-archive location %s

What it means

Thrown by archiveHashAuthentication.AuthenticatePackage when the supplied localLocation is not a PackageLocalArchive. This authenticator (NewArchiveChecksumAuthentication) only works on a packaged archive file because it computes the legacy zip SHA-256 over the archive bytes; an unpacked directory (PackageLocalDir) or any other location type is rejected at package_authentication.go:302-306. The doc on the constructor explicitly states this authenticator is unsuitable for unpacked layouts.

Solutions

  1. Use NewPackageHashAuthentication instead — it works on both packed archives and unpacked directories via the newer PackageHash scheme.
  2. Ensure the source stages the provider as a PackageLocalArchive (keeps the original .zip) before applying archive auth.
  3. Drop archiveHashAuthentication from the auth chain when the location is an unpacked dir.

Example fix

// before
auth := NewArchiveChecksumAuthentication(platform, wantSHA256Sum)
// applied to an unpacked PackageLocalDir -> error

// after
auth := NewPackageHashAuthentication(platform, validHashes)
// works for PackageLocalArchive and PackageLocalDir
Defensive patterns

Strategy: type-guard

Type guard

// Guard the location type before applying archive auth.
func isArchiveLocation(loc getproviders.PackageLocation) bool {
    _, ok := loc.(getproviders.PackageLocalArchive)
    return ok
}

// usage:
// if !isArchiveLocation(loc) {
//     auth = getproviders.NewPackageHashAuthentication(platform, hashes)
// }

Prevention

When it happens

Trigger: Constructing NewArchiveChecksumAuthentication and calling AuthenticatePackage on a PackageLocalDir (unpacked provider), a PackageHTTPURL, or any location that does not type-assert to PackageLocalArchive. Happens when a source stages providers unpacked but the auth chain still includes the archive authenticator.

Common situations: Switching a source from archive-based to unpacked-dir staging without updating the authenticator; building a custom source/mirror that unpacks for inspection then tries archive auth; mixing NewArchiveChecksumAuthentication with NewPackageHashAuthentication and applying it to a dir.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/580a8393dd238b75. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:306

// This authentication is suitable only for PackageHTTPURL and
// PackageLocalArchive source locations, because the unpacked layout
// (represented by PackageLocalDir) does not retain access to the original
// source archive. Therefore this authenticator will return an error if its
// given localLocation is not PackageLocalArchive.
//
// NewPackageHashAuthentication is preferable to use when possible because
// it uses the newer hashing scheme (implemented by function PackageHash) that
// can work with both packed and unpacked provider packages.
func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
	return archiveHashAuthentication{platform, wantSHA256Sum}
}

func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
	archiveLocation, ok := localLocation.(PackageLocalArchive)
	if !ok {
		// A source should not use this authentication type for non-archive
		// locations.
		return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
	}

	gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
	if err != nil {
		return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
	}
	wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
	if gotHash != wantHash {
		return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
	}
	return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}

func (a archiveHashAuthentication) AcceptableHashes() []Hash {
	return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}

type matchingChecksumAuthentication struct {

View on GitHub (pinned to d32a084675)