hashicorp/terraform · error
checksum list has no SHA-256 hash for
Error message
checksum list has no SHA-256 hash for %q
What it means
Thrown by matchingChecksumAuthentication.AuthenticatePackage when the SHA256SUMS document (m.Document) contains no line whose second field equals m.Filename. The document is parsed as '<hexhash> <filename>' lines split on newlines and whitespace (bytes.Fields); if no line's filename field matches, checksum stays nil and the error fires at package_authentication.go:360-361.
Solutions
- Ensure m.Filename exactly matches an entry in the SHA256SUMS document (same version, platform, and naming including extension).
- Verify the sums document corresponds to the same provider version being installed; re-fetch the sums document for that version.
- If building a custom registry/mirror, include a line for every platform archive you serve in the sums document.
- Log/print m.Document lines to confirm which filenames are actually present and adjust the requested filename.
Defensive patterns
Strategy: validation
Validate before calling
// Before constructing NewMatchingChecksumAuthentication, confirm the
// requested filename appears in the sums document.
func filenameInSums(document []byte, filename string) error {
want := []byte(filename)
for _, line := range bytes.Split(document, []byte("\n")) {
parts := bytes.Fields(line)
if len(parts) > 1 && bytes.Equal(parts[1], want) {
return nil
}
}
return fmt.Errorf("filename %q not present in SHA256SUMS document", filename)
} Prevention
- Ensure the sums document covers the exact platform archive being installed.
- Keep the requested filename's version aligned with the sums document's version.
- Custom mirrors must list every served platform archive in the sums document.
When it happens
Trigger: NewMatchingChecksumAuthentication(document, filename, wantSHA256Sum) where filename is not present in the sums document — e.g. the document is for a different provider version, a different platform archive name, or the filename string does not exactly match (case, path prefix, .zip vs other extension).
Common situations: Platform mismatch — the sums file lists terraform-provider-aws_5.0.0_linux_amd64.zip but you asked for darwin_arm64; version mismatch — sums file from 5.0.0 queried with the 5.1.0 filename; a custom registry returning a sums document without the requested artifact; filename formatting drift (extra path component, different naming convention).
Related errors
- checksum list has invalid SHA256 hash
- checksum list has unexpected SHA-256 hash
- archive has incorrect checksum
- cannot check archive hash for non-archive location
- error checking signature
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/6a633d49206762bf.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:361
Filename: filename,
WantSHA256Sum: wantSHA256Sum,
}
}
func (m matchingChecksumAuthentication) AuthenticatePackage(location PackageLocation) (*PackageAuthenticationResult, error) {
// Find the checksum in the list with matching filename. The document is
// in the form "0123456789abcdef filename.zip".
filename := []byte(m.Filename)
var checksum []byte
for _, line := range bytes.Split(m.Document, []byte("\n")) {
parts := bytes.Fields(line)
if len(parts) > 1 && bytes.Equal(parts[1], filename) {
checksum = parts[0]
break
}
}
if checksum == nil {
return nil, fmt.Errorf("checksum list has no SHA-256 hash for %q", m.Filename)
}
// Decode the ASCII checksum into a byte array for comparison.
var gotSHA256Sum [sha256.Size]byte
if _, err := hex.Decode(gotSHA256Sum[:], checksum); err != nil {
return nil, fmt.Errorf("checksum list has invalid SHA256 hash %q: %s", string(checksum), err)
}
// If the checksums don't match, authentication fails.
if !bytes.Equal(gotSHA256Sum[:], m.WantSHA256Sum[:]) {
return nil, fmt.Errorf("checksum list has unexpected SHA-256 hash %x (expected %x)", gotSHA256Sum, m.WantSHA256Sum[:])
}
// Success! But this doesn't result in any real authentication, only a
// lack of authentication errors, so we return a nil result.
return nil, nil
}
View on GitHub (pinned to d32a084675)