hashicorp/terraform · error
cannot check archive hash for non-archive location
Error message
cannot check archive hash for non-archive location %s
What it means
Thrown by archiveHashAuthentication.AuthenticatePackage when the supplied localLocation is not a PackageLocalArchive. This authenticator (NewArchiveChecksumAuthentication) only works on a packaged archive file because it computes the legacy zip SHA-256 over the archive bytes; an unpacked directory (PackageLocalDir) or any other location type is rejected at package_authentication.go:302-306. The doc on the constructor explicitly states this authenticator is unsuitable for unpacked layouts.
Solutions
- Use NewPackageHashAuthentication instead — it works on both packed archives and unpacked directories via the newer PackageHash scheme.
- Ensure the source stages the provider as a PackageLocalArchive (keeps the original .zip) before applying archive auth.
- Drop archiveHashAuthentication from the auth chain when the location is an unpacked dir.
Example fix
// before auth := NewArchiveChecksumAuthentication(platform, wantSHA256Sum) // applied to an unpacked PackageLocalDir -> error // after auth := NewPackageHashAuthentication(platform, validHashes) // works for PackageLocalArchive and PackageLocalDir
Defensive patterns
Strategy: type-guard
Type guard
// Guard the location type before applying archive auth.
func isArchiveLocation(loc getproviders.PackageLocation) bool {
_, ok := loc.(getproviders.PackageLocalArchive)
return ok
}
// usage:
// if !isArchiveLocation(loc) {
// auth = getproviders.NewPackageHashAuthentication(platform, hashes)
// } Prevention
- Prefer NewPackageHashAuthentication — it works on archives and unpacked dirs.
- Only attach NewArchiveChecksumAuthentication when the source keeps the original archive.
- Type-assert the location before choosing an authenticator.
When it happens
Trigger: Constructing NewArchiveChecksumAuthentication and calling AuthenticatePackage on a PackageLocalDir (unpacked provider), a PackageHTTPURL, or any location that does not type-assert to PackageLocalArchive. Happens when a source stages providers unpacked but the auth chain still includes the archive authenticator.
Common situations: Switching a source from archive-based to unpacked-dir staging without updating the authenticator; building a custom source/mirror that unpacks for inspection then tries archive auth; mixing NewArchiveChecksumAuthentication with NewPackageHashAuthentication and applying it to a dir.
Related errors
- archive has incorrect checksum
- failed to compute checksum for
- checksum list has invalid SHA256 hash
- checksum list has no SHA-256 hash for
- checksum list has unexpected SHA-256 hash
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/580a8393dd238b75.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:306
// This authentication is suitable only for PackageHTTPURL and
// PackageLocalArchive source locations, because the unpacked layout
// (represented by PackageLocalDir) does not retain access to the original
// source archive. Therefore this authenticator will return an error if its
// given localLocation is not PackageLocalArchive.
//
// NewPackageHashAuthentication is preferable to use when possible because
// it uses the newer hashing scheme (implemented by function PackageHash) that
// can work with both packed and unpacked provider packages.
func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
return archiveHashAuthentication{platform, wantSHA256Sum}
}
func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
archiveLocation, ok := localLocation.(PackageLocalArchive)
if !ok {
// A source should not use this authentication type for non-archive
// locations.
return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
}
gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
if err != nil {
return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
}
wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
if gotHash != wantHash {
return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
}
return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}
func (a archiveHashAuthentication) AcceptableHashes() []Hash {
return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}
type matchingChecksumAuthentication struct {View on GitHub (pinned to d32a084675)